Proto6: Six protobuf.js Vulnerabilities Expose Node.js Apps to RCE and DoS
June 10, 2026 Cybersecurity researchers at Cyera have disclosed six vulnerabilities — collectively codenamed Proto6 — in protobuf.js, a widely deployed JavaScript and TypeScript implementation of Google’s Protocol Buffers data serialization format.…
LiteLLM CVE-2026-42271: CISA KEV Alert for Active Command Injection Exploit
June 9, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity command injection flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog on Monday. The vulnerability, tracked as CVE-2026-42271,…
Google Chrome Zero-Day CVE-2026-11645: Fifth 2026 Exploit
June 9, 2026 Google has released an emergency security update for Chrome to fix CVE-2026-11645, a high-severity zero-day vulnerability in the V8 JavaScript engine that is already being exploited in the wild. Consequently, this marks the fifth actively…
AI Agent Discovers 21 FFmpeg Zero-Days: CVE-2026-39210-39218
June 6, 2026 An autonomous AI security agent has uncovered 21 zero-day vulnerabilities in FFmpeg, the ubiquitous media processing library that powers browsers, streaming platforms, and countless applications worldwide. The findings mark a significant…
Cisco Unified CM CVE-2026-20230: Critical SSRF Flaw With Public PoC
June 04, 2026 Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager platform. The flaw, tracked as CVE-2026-20230, could allow unauthenticated remote attackers to gain root privileges on…
CVE-2026-23479: AI Discovers 2-Year-Old Redis RCE Vulnerability
June 3, 2026 Redis has patched a critical use-after-free vulnerability that allows authenticated attackers to execute arbitrary operating system commands on the database server. The flaw, tracked as CVE-2026-23479, was discovered by an autonomous AI…
CVE-2025-48595 Android Zero-Day Under Active Exploit
June 02, 2026 Google has released the June 2026 Android security update, patching 124 vulnerabilities across the mobile operating system. One high-severity flaw in the Android Framework component, tracked as CVE-2025-48595, is already under active…
CVE-2026-41089: Critical Windows Netlogon RCE Under Active Exploit
June 2, 2026 A critical remote code execution vulnerability in Windows Netlogon is now under active exploitation in the wild. The flaw, tracked as CVE-2026-41089, carries a CVSS score of 9.8 and allows unauthenticated attackers to execute code on Windows…
Miasma Supply Chain Attack: Red Hat npm Packages Compromised
June 01, 2026 A new supply chain attack campaign codenamed Miasma has compromised multiple @redhat-cloud-services npm packages. The attack steals developer credentials and CI/CD secrets through install-time malware. It also delivers a self-propagating…
ChatGPT LLMShare Malware Campaign Abuses Share Links to Deliver Fake Outage Pages
June 1, 2026 Threat actors have launched a novel malware campaign dubbed LLMShare that abuses legitimate ChatGPT share links to deliver malicious payloads. The campaign uses ChatGPT’s own code-rendering feature to host fake outage pages on trusted…