CVE-2026-23479: AI Discovers 2-Year-Old Redis RCE Vulnerability
June 3, 2026 Redis has patched a critical use-after-free vulnerability that allows authenticated attackers to execute arbitrary operating system commands on the database server. The flaw, tracked as CVE-2026-23479, was discovered by an autonomous AI…
CVE-2025-48595 Android Zero-Day Under Active Exploit
June 02, 2026 Google has released the June 2026 Android security update, patching 124 vulnerabilities across the mobile operating system. One high-severity flaw in the Android Framework component, tracked as CVE-2025-48595, is already under active…
Iranian State-Sponsored Hacking Group Handala Breaches Holocaust Victim Support Centre: 2M Documents Leaked
June 2, 2026 Iranian state-sponsored hacking group Handala breached the Holocaust Victim Support Centre in Israel on May 31, 2026. The group claimed responsibility for the attack and leaked over two million documents totaling more than one terabyte of…
CVE-2026-41089: Critical Windows Netlogon RCE Under Active Exploit
June 2, 2026 A critical remote code execution vulnerability in Windows Netlogon is now under active exploitation in the wild. The flaw, tracked as CVE-2026-41089, carries a CVSS score of 9.8 and allows unauthenticated attackers to execute code on Windows…
Miasma Supply Chain Attack: Red Hat npm Packages Compromised
June 01, 2026 A new supply chain attack campaign codenamed Miasma has compromised multiple @redhat-cloud-services npm packages. The attack steals developer credentials and CI/CD secrets through install-time malware. It also delivers a self-propagating…
ChatGPT LLMShare Malware Campaign Abuses Share Links to Deliver Fake Outage Pages
June 1, 2026 Threat actors have launched a novel malware campaign dubbed LLMShare that abuses legitimate ChatGPT share links to deliver malicious payloads. The campaign uses ChatGPT’s own code-rendering feature to host fake outage pages on trusted…
WP Maps Pro CVE-2026-8732: Critical WordPress Admin Bypass Under Active Exploit
May 31, 2026 A critical vulnerability in the WP Maps Pro WordPress plugin is now under active exploitation. Threat actors are abusing CVE-2026-8732 to create rogue administrator accounts on compromised websites without any authentication. WP Maps Pro is…
ShinyHunters Breach Charter Communications: 4.9M Accounts Exposed
May 29, 2026 The ShinyHunters extortion gang has breached Charter Communications, exposing 4.9 million customer and business accounts. Consequently, the telecom giant confirmed the incident while disputing the severity of the stolen data. Charter…
CIFSwitch Linux Flaw Grants Root Access on Major Distros
May 30, 2026 A newly discovered Linux kernel privilege escalation vulnerability named CIFSwitch allows local attackers to forge CIFS authentication key descriptions, abuse the kernel’s key request mechanism, and gain root privileges on multiple…
Palo Alto PAN-OS CVE-2026-0257: GlobalProtect Authentication Bypass Under Active Exploit
May 30, 2026 CISA has added a critical Palo Alto Networks PAN-OS authentication bypass vulnerability to its Known Exploited Vulnerabilities catalog. CVE-2026-0257 affects GlobalProtect portal and gateway configurations, and it is already being exploited…