cve-2026-11645
128 articles with this tag
✨
AI summary
Loading…
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
July 2026 Patch Tuesday
June 2026 CVE Landscape
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Dawn of the Apex Agentic Adversary
DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries
Stop Your Legacy Infrastructure from Hijacking Your AI Agents
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
From Assistive to Agentic: The AI Shift That's Redefining Threat Management
Forget Data Leakage: Shadow AI's Real Threat Is Access Control
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
The Scripts on Your Checkout Page Are Now a PCI DSS Problem
Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization
The Top 10 Attack Surface Exposures in 2026
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
144 Mastra npm Packages Compromised via Hijacked Contributor Account
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Multiples vulnérabilités dans Microsoft Edge (16 juin 2026)
Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
Chromium: CVE-2026-11645 Out of bounds memory access in V8
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
The Onboarding Password Mistake That Creates Unnecessary Risk
Bulletin d'actualité CERTFR-2026-ACT-026 (15 juin 2026)
152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories
OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack