AryStinger Botnet Hijacks 4,300 D-Link Routers for Global Proxy Network
June 22, 2026 A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide. Unlike typical IoT botnets built for DDoS or cryptocurrency mining, this threat converts infected devices into distributed…
Icarus Extortion Group Steals Salesforce CRM Data
June 20, 2026 Market intelligence platform Klue disclosed a critical security incident on June 19, 2026. Threat actors compromised legacy integration credentials to steal OAuth tokens used to connect Klue with customer Salesforce environments.…
Unpatchable Exploit for Apple A12 and A13 SecureROM
June 21, 2026 Security researchers at Paradigm Shift have disclosed usbliter8. It is an unpatchable exploit that achieves arbitrary code execution inside Apple’s A12 and A13 SecureROM. This vulnerability was published on June 18, 2026, following…
Gravity SMTP CVE-2026-4020: WordPress Plugin Actively Exploited
June 20, 2026 Threat actors are actively exploiting CVE-2026-4020, an unauthenticated information disclosure vulnerability in the popular Gravity SMTP WordPress plugin. This flaw exposes sensitive credentials and system configuration data on over 100,000…
Splunk Enterprise CVE-2026-20253: CISA KEV Alert Orders Federal Patch by Sunday
June 19, 2026 CISA has added a critical Splunk Enterprise vulnerability to its Known Exploited Vulnerabilities catalog after threat actors began actively exploiting it in the wild. Tracked as CVE-2026-20253, the flaw allows unauthenticated remote…
F5 Critical NGINX RCE CVE-2026-42530 and CVE-2026-42055 Patched
June 18, 2026 Cybersecurity company F5 has released out-of-band security updates for multiple critical NGINX vulnerabilities. Consequently, organizations running NGINX Plus, NGINX Open Source, or NGINX Gateway Fabric should prioritize patching…
CISA Orders Federal Patch for Joomla JCE CVE-2026-48907 by Friday
June 18, 2026 CISA has added a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-48907, allows unauthenticated attackers to upload and execute…
FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices
June 17, 2026 A newly discovered data leak dubbed FortiBleed has exposed Fortinet VPN credentials for 73,932 firewall URLs at organizations worldwide. Consequently, security researchers warn that the leaked data could enable direct access to enterprise…
Mastra npm Supply Chain Attack: 144 Packages Compromised
June 17, 2026 On June 17, 2026, a software supply chain attack codenamed “easy-day-js” compromised 144 npm packages associated with the Mastra AI framework. Attackers hijacked a former contributor’s account to publish malicious versions…
Three FortiSandbox CVEs Under Active Exploit: Unauthenticated RCE
June 16, 2026 Threat actors are actively exploiting three critical vulnerabilities in Fortinet’s FortiSandbox threat detection platform. The flaws, tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, allow unauthenticated remote…