NAVANEM

Security news & tech updates for sysadmins and IT pros

Cybersecurity advisories, CVE watch and the tech worth sharing, scored by trend and updated regularly, written for people who actually run infrastructure.

71stories
hourlyupdated
8sources

71 results

Exchange security themed image showing a critical CVE tile, an OWA browser window with injected script and a PATCH NOW shield icon representing urgent updates for thousands of vulnerable servers
[Vulnerabilities] · Jun 12, 2026 · 15:45 UTC

Exchange Server Zero-Day CVE-2024-21413 Patched

Microsoft patches CVE-2024-21413 Exchange Server zero-day exploited against OWA users. Over 97,000 servers vulnerable. XSS flaw allows JavaScript injection. Patch now.

emanuel de almeida · read →
Windows Server security update themed image showing encrypted DNS traffic, a corrected BitLocker recovery workflow and firmware Secure Boot certificate toggles linked to KB5094125
[Tech] · Jun 12, 2026 · 12:00 UTC

Windows Server 2025 June Update KB5094125: DoH, BitLocker Fix

KB5094125 adds DNS over HTTPS support, fixes April's BitLocker recovery bug, and includes Secure Boot certificate controls for Windows Server 2025.

emanuel de almeida · read →
Windows security update themed image showing a long Patch Tuesday bulletin with one MSMQ CVE tile highlighted in red as a critical 9.8 CVSS RCE that requires urgent patching
[Vulnerabilities] · Jun 11, 2026 · 17:00 UTC

Patch Tuesday June 2024: Microsoft Fixes 51 Flaws, One Zero-Day

Microsoft's June 2024 Patch Tuesday addresses 51 vulnerabilities including 18 RCE flaws. CVE-2024-30080 MSMQ bug scores 9.8 CVSS and demands immediate patching.

emanuel de almeida · read →
Windows Server security update themed image showing Secure Boot certificate and telemetry settings, a corrected DFS namespace diagram and a protected desktop.ini file linked to KB5094122
[Security] · Jun 11, 2026 · 12:00 UTC

KB5094122: Windows Server 2016 Secure Boot Privacy Update

KB5094122 brings build 14393.9234 to Windows Server 2016 with Secure Boot telemetry controls, a DFS namespace fix, and desktop.ini hardening.

emanuel de almeida · read →
Visualization of a Defender remediation pipeline where an attacker-controlled junction redirects SYSTEM-level cleanup actions into a malicious folder, resulting in a SYSTEM shell inside the user session
[Vulnerabilities] · Jun 10, 2026 · 12:00 UTC

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Privileges on Patched Systems

New RoguePlanet exploit bypasses June 2026 patches to spawn SYSTEM-level prompts via Defender race condition. Seventh release from Nightmare Eclipse in ten weeks.

emanuel de almeida · read →
Chrome security themed image showing a cracked V8 engine icon representing CVE-2026-11645, a zero-day exploited against billions of users, and an emergency update plus CISA KEV entry requiring urgent patching
[Vulnerabilities] · Jun 10, 2026 · 06:00 UTC

Chrome Zero-Day CVE-2026-11645 Patched: Update Now

Google patches CVE-2026-11645, Chrome's fifth zero-day of 2026. With 3.83 billion users at risk, CISA mandates federal remediation by June 23.

emanuel de almeida · read →
VPN security themed image showing a compromised Check Point gateway, a Qilin ransomware icon moving through a red VPN tunnel, and a CISA shield with a 72-hour countdown indicating an urgent remediation mandate for CVE-2026-50751
[Security] · Jun 10, 2026 · 04:24 UTC

Check Point VPN Zero-Day Exploited by Qilin Ransomware

CVE-2026-50751 lets Qilin ransomware bypass Check Point VPN authentication. CISA mandates a 72-hour patch deadline. Learn detection steps and fixes.

emanuel de almeida · read →
Illustration of a June 2026 ServiceNow security incident where an unauthenticated REST API endpoint exposed customer data on June 2–3 before being patched on June 5, and a checklist of actions affected organisations must now take, including verifying the patch, reviewing logs, investigating suspicious API calls and rotating exposed credentials
[Security] · Jun 9, 2026 · 12:00 UTC

ServiceNow API Flaw Exposes Customer Data: Response Guide

A ServiceNow API flaw exposed customer data from June 2-3, 2026. ServiceNow patched the unauthenticated endpoint on June 5. Here's what 8,700+ customers must do now.

emanuel de almeida · read →
Windows Server patch management themed image showing June 2026 Patch Tuesday updates being rolled out across a datacenter
[Tech] · Jun 9, 2026 · 12:00 UTC

Windows Server June 2026 Patch Tuesday: KB5094125, KB5094128 and More

Windows Server June 2026 Patch Tuesday (KB5094125-KB5094122) fixes 200 vulns, adds DoH GA, resolves BitLocker PCR7 bugs, and rolls out Secure Boot certs.

emanuel de almeida · read →
Illustration of Google patching 124 Android vulnerabilities including an actively exploited zero-day
[Vulnerabilities] · Jun 2, 2026 · 12:00 UTC

CVE-2025-48595: Google Patches 124 Android Flaws Including Active Zero-Day

Google's June 2026 Android bulletin patches 124 vulnerabilities, including zero-day CVE-2025-48595 with a CVSS 8.4 score confirmed under active targeted exploitation.

emanuel de almeida · read →
Illustration of Windows Server 2016 servers failing domain controller discovery after installing KB5087537 when the hostname is exactly 15 characters
[Tech] · May 27, 2026 · 12:00 UTC

KB5087537 Bug Breaks DC Discovery on Windows Server 2016

The May 2026 Patch Tuesday update KB5087537 breaks domain controller discovery on Windows Server 2016 when the hostname is exactly 15 characters, returning ERROR_INVALID_PARAMETER.

emanuel de almeida · read →
show