F5 Critical NGINX RCE CVE-2026-42530 and CVE-2026-42055 Patched
June 18, 2026 Cybersecurity company F5 has released out-of-band security updates for multiple critical NGINX vulnerabilities. Consequently, organizations running NGINX Plus, NGINX Open Source, or NGINX Gateway Fabric should prioritize patching…
CISA Orders Federal Patch for Joomla JCE CVE-2026-48907 by Friday
June 18, 2026 CISA has added a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-48907, allows unauthenticated attackers to upload and execute…
Mastra npm Supply Chain Attack: 144 Packages Compromised
June 17, 2026 On June 17, 2026, a software supply chain attack codenamed “easy-day-js” compromised 144 npm packages associated with the Mastra AI framework. Attackers hijacked a former contributor’s account to publish malicious versions…
Three FortiSandbox CVEs Under Active Exploit: Unauthenticated RCE
June 16, 2026 Threat actors are actively exploiting three critical vulnerabilities in Fortinet’s FortiSandbox threat detection platform. The flaws, tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, allow unauthenticated remote…
Cisco SD-WAN Zero-Day CVE-2026-20262: Active Root Exploit
June 15, 2026 Cisco has patched a critical zero-day vulnerability in its Catalyst SD-WAN Manager platform. The flaw, tracked as CVE-2026-20262, allows authenticated remote attackers to overwrite files and escalate to root privileges. CISA added the…
US Government Orders Anthropic Fable 5 Suspension Over Jailbreak
June 13, 2026 The US government issued an export control directive ordering Anthropic to suspend access to Fable 5 and Mythos 5 for all users worldwide. The order, issued on June 12, 2026, cites national security concerns over a reported jailbreak of the…
Arch Linux AUR Supply Chain Attack: 400+ Packages Hijacked with Rootkit and Infostealer
June 12, 2026 Attackers hijacked more than 400 packages in the Arch Linux community repository this week. Furthermore, the malicious build scripts installed a Rust credential stealer and an optional eBPF rootkit on developer workstations. This Arch Linux…
French Government Tchap Messenger Breach Exposes 73,000 Public Sector Accounts
June 12, 2026 The French government disclosed a breach of its Tchap encrypted messaging platform that affects over 73,000 public sector employees. Attackers compromised a user account and scraped data from public chat rooms, exposing names, email…
Oracle PeopleSoft CVE-2026-35273: ShinyHunters Zero-Day RCE Under Active Exploit | June 2026
June 11, 2026 Oracle has issued an emergency security alert for CVE-2026-35273, a critical zero-day vulnerability in PeopleSoft Enterprise PeopleTools that enables unauthenticated remote code execution. The ShinyHunters extortion gang is actively…
Ivanti Sentry CVE Root RCE Under Active Exploit
June 11, 2026 Attackers are actively exploiting CVE-2026-10520, a maximum-severity vulnerability in Ivanti Sentry that allows unauthenticated root remote code execution on exposed secure mobile gateways. The flaw was patched on June 9, 2026, but threat…