ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59199
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.

Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.84%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
CVE-2026-0257
Authentication Bypass in Palo Alto Networks PAN-OS GlobalProtect Portal and Gateway

CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS that allows a remote, unauthenticated attacker to defeat security restrictions and establish an unauthorized VPN connection; incident reporting indicates it involves forged VPN cookies (CWE-565). An attacker who succeeds gains the network access of a legitimate remote-access user, and Qilin ransomware affiliates have been using this flaw as their initial access vector. Any organization running PAN-OS with the GlobalProtect portal or gateway enabled is in scope, including Siemens RUGGEDCOM APE1808 appliances that run PAN-OS, while Panorama and Cloud NGFW are explicitly not affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2026-05-29 with ransomware use known, EPSS assigns it a 93.9% probability of exploitation within 30 days (100th percentile), and Rapid7 has documented attacks against multiple customers.

Do: Upgrade PAN-OS to the fixed release specified in the Palo Alto Networks security advisory, and check Siemens' guidance if you operate RUGGEDCOM APE1808 appliances. Review GlobalProtect portal/gateway logs for forged VPN cookies and unauthorized VPN sessions, and hunt for Qilin ransomware indicators on hosts reachable through the VPN. If patching cannot happen immediately, restrict internet exposure of the GlobalProtect portal and gateway; federal agencies must apply mitigations per BOD 22-01 given the KEV listing.

7.895% KEV ransomware
  • Palo Alto Networks PAN-OS (GlobalProtect portal and gateway)
  • Palo Alto Networks Prisma Access Listed in CPE data; affected status not detailed in source description, confirm with vendor advisory
  • Siemens RUGGEDCOM APE1808 firmware
massOn the order of hundreds of thousands of internet-exposed GlobalProtect portals/devices (mid-six figures)
CVE-2026-4868
+2 in the same advisory: …1402 …6713
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain co

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners.

NVD description · AI analysis pending
8.2
group max
<1%
  • gitlab gitlab
CVE-2026-2332
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.

NVD description · AI analysis pending
9.11% PoC
  • eclipse jetty
CVE-2026-27771
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package so

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

NVD description · AI analysis pending
8.21%
CVE-2026-32996
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

NVD description · AI analysis pending
7.3<1% PoC
CVE-2026-32997
A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

NVD description · AI analysis pending
8.6<1%
CVE-2026-3593
+2 in the same advisory: …5946 …5947
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.

NVD description · AI analysis pending
9.8
group max
2%
  • isc bind
CVE-2026-40933
Flowise is a drag & drop user interface to build a customized large language model flow.

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerability lies in a bug in the input sanitization from the “Custom MCP” configuration in http://localhost:3000/canvas - where any user can add a new MCP, when doing so - adding a new MCP using stdio, the user can add any command, even though your code have input sanitization checks such as validateCommandInjection and validateArgsForLocalFileAccess, and a list of predefined specific safe commands - these commands, for example "npx" can be combined with code execution arguments ("-c touch /tmp/pwn") that enable direct code execution on the underlying OS. This vulnerability is fixed in 3.1.0.

NVD description · AI analysis pending
9.912% PoC
  • flowiseai flowise
CVE-2026-4115
A vulnerability was detected in PuTTY 0.83.

A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic signature. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The real existence of this vulnerability is still doubted at the moment. The patch is identified as af996b5ec27ab79bae3882071b9d6acf16044549. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a patch for the affected product. However, at the moment there is no proof that this flaw might have any real-world impact.

NVD description · AI analysis pending
2.9<1% PoC
  • putty putty
CVE-2026-4480
A flaw was found in the Samba printing subsystem.

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

NVD description · AI analysis pending
9.014%
  • redhat openshift container platform
  • redhat samba
  • redhat enterprise linux
CVE-2026-44930
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates fro

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

NVD description · AI analysis pending
9.8<1%
  • apache cxf
CVE-2026-44962
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath querie

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.

NVD description · AI analysis pending
9.9<1%
CVE-2026-45659
Authenticated Deserialization RCE in Microsoft SharePoint Server (Actively Exploited)

CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft SharePoint Server in which an authorized (authenticated, low-privilege) attacker can submit crafted serialized data over the network, with no user interaction required, to execute code on the server. Successful exploitation carries high impact on confidentiality, integrity, and availability within the SharePoint service context, giving attackers a foothold for follow-on activity, and CISA notes that ransomware use is known. Organizations running on-premises Microsoft SharePoint Server are affected; the source data lists no specific version ranges, and the CPE scope (sharepoint server) points to the on-premises product rather than the Microsoft-managed SharePoint Online service. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-01 after active exploitation, and its EPSS score of 76.1% (100th percentile) indicates a high probability of near-term exploitation. The CVE record lists no public proof-of-concept, though related reporting describes exploitation activity following a public PoC release for a SharePoint authentication bypass.

Do: Apply Microsoft's current security updates for SharePoint Server following vendor instructions, prioritizing internet-facing servers, and comply with CISA BOD 26-04, which requires applying mitigations per vendor guidance (including the cited Forensics Triage Requirements) or discontinuing use of the product if mitigations are unavailable. Because in-the-wild exploitation and ransomware use are confirmed, triage exposed servers for compromise: review IIS/SharePoint logs for unexpected authenticated requests, look for webshells or newly modified files in SharePoint web roots, and check for unusual child processes spawned by the SharePoint application pool. Given related reporting on an authentication-bypass PoC, also verify that any related SharePoint authentication-bypass patches are…

8.876% KEV ransomware
  • Microsoft SharePoint Server
mass≈100,000 internet-exposed SharePoint Server deployments (order-of-magnitude estimate), with total users across on-premises deployments likely in the millions
CVE-2026-46840
+2 in the same advisory: …46775 …46839
Vulnerability in Oracle REST Data Services (component:

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
10.0
group max
<1%
  • oracle rest data services
CVE-2026-47783
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username i

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

NVD description · AI analysis pending
8.11%
  • memcached memcached
CVE-2026-48095
7-Zip is a file archiver with a high compression ratio.

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)1 = 28 and CompressionUnit == 4 drives the exponent to 32, which is undefined behavior and collapses on x86/x64 so _inBuf is allocated as 1 byte. ReadStream_FALSE then writes up to 256 MB of attacker-controlled data into that 1-byte buffer in 64 KB iterations, and because the CInStream object sits only 304 bytes after _inBuf, its vtable pointer is overwritten and the next dispatched call achieves a vtable hijack. On 32-bit builds the overflow is unconditionally reached; on 64-bit it requires the parallel 8 GB _outBuf allocation to succeed, otherwise failing closed to denial of service. The NTFS handler is enabled by default in stock 7z.dll and, via signature-based fallback matching "NTFS " at offset 3, will open a crafted image regardless of file extension during extraction or testing. Version 26.01 fixes the issue.

NVD description · AI analysis pending
8.81% PoC
  • 7-zip 7-zip
CVE-2026-48778
+2 in the same advisory: …48800 …48770
Notepad++ is a free and open-source source code editor.

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any validation, whitelist, or digital signature check. When the user triggers IDM_FILE_OPEN_CMD (File → Open Containing Folder → cmd), NppCommands.cpp:228 creates a Command object with this value and calls run(), which invokes ShellExecute (RunDlg.cpp:221) with the attacker-controlled string as the executable path. This vulnerability is fixed in 8.9.6.1.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • notepad-plus-plus notepad\+\+
CVE-2026-8732
Unauthenticated Privilege Escalation (Admin Account Creation) in WP Maps Pro Plugin

CVE-2026-8732 is a critical (CVSS 9.8) unauthenticated privilege escalation flaw in the WP Maps Pro plugin for WordPress, affecting every version up to and including 6.1.0, so any site running one of these versions is exposed. The plugin registers its wpgmp_temp_access_ajax AJAX action for unauthenticated users but protects it only with the fc-call-nonce nonce, which is publicly embedded in every frontend page via the wpgmp_local JavaScript object, making the check ineffective as an access control mechanism (CWE-306, missing authentication). An unauthenticated attacker can invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded administrator role via wp_insert_user() and returns a magic login URL that fully authenticates the attacker via wp_set_auth_cookie(). The result is complete site takeover without any credentials. The flaw is already being actively exploited in the wild to create rogue admin accounts according to current security reporting, a public proof-of-concept exists, and EPSS assigns a 21.5% probability of exploitation within 30 days (97th percentile).

Do: Update WP Maps Pro to a release newer than 6.1.0 as soon as a patched version is published (the advisory lists all versions through 6.1.0 as vulnerable and names no fixed version); until then, deactivate the plugin or block unauthenticated requests to the wpgmp_temp_access_ajax action via a WAF. Audit the WordPress users list for administrator accounts you did not create, delete any rogue accounts, and expire active sessions and rotate admin credentials on sites where takeover is suspected.

9.823% PoC
  • WP Maps Pro plugin for WordPress All versions up to and including 6.1.0 (no fixed version stated in the data)
moderatelikely on the order of tens of thousands of WordPress sites (rough estimate; no active-install statistics were provided)
CVE-2026-9089
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations.

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.

NVD description · AI analysis pending
8.8<1%
  • connectwise automate
CVE-2026-9090
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate.

Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-configured Identity Provider certificate, allowing an attacker to forge assertions signed with an attacker-controlled key.

NVD description · AI analysis pending
9.1<1%
CVE-2026-9098
In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifyin

In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identity Provider) after a SAML flow has started, the handler still processes the response using the provider snapshot loaded at the start of the request. As a result, an attacker controlling a registered upstream IdP can send unsolicited SAML responses, or replay a legitimately captured response in a different session or after the original flow has ended. In both cases, Casdoor accepts the response and issues a session, enabling persistent unauthorized access.

NVD description · AI analysis pending
9.1<1%
CVE-2026-9312
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.2. This vulnerability was reported via the GitHub Bug Bounty program.

NVD description · AI analysis pending
9.27%
  • github enterprise server
CVE-2026-9560
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privile

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

NVD description · AI analysis pending
9.4<1%
  • openvpn connect
CVE-2026-9872
+1 in the same advisory: …9893
Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted H

Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

NVD description · AI analysis pending
9.6
group max
<1%
  • google chrome
Full article2,718 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 01, 2026Cybersecurity / Hacking

Monday hit like a cron job with anger issues.

A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality.

The vibe is simple: old bugs, new wrappers, faster abuse. Patch the obvious crap first. Then read the rest.

⚡ Threat of the Week

PAN-OS GlobalProtect Authentication Bypass Under Exploitation - Palo Alto Networks warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. The issue specifically affects firewalls with GlobalProtect portal or gateway configured when authentication override cookies are enabled and a specific certificate configuration exists, the network security company said.

🔔 Top News

  • Critical Unpatched Flaw in Gogs - The popular open-source self-hosted Git service Gogs is affected by a critical-severity zero-day vulnerability that exposes servers to remote code execution (RCE), per Rapid7. The injection flaw can be exploited by authenticated attackers via pull requests with malicious branch names. "Since Gogs ships with open registration enabled by default and no limit on repository creation, an unauthenticated attacker can simply create an account and repository on any default-configured instance," the cybersecurity firm says. Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly. "The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users' private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository's code," Rapid7 said. Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. No patch has been released as of the time of publishing.
  • GlassWorm C2 Taken Down - CrowdStrike, Google, and the Shadowserver Foundation dismantled the GlassWorm malware operation by taking down all four of GlassWorm's command-and-control (C2) channels simultaneously on May 26, 2026, at 2 p.m. UTC. GlassWorm, since its emergence last year, has conducted a "multi-pronged campaign" using trojanized VS Code extensions published on both the Microsoft VS Code Marketplace and Open VSX. The campaign is also known to have introduced malicious code through compromised npm and Python packages. By taking down all four channels at the same time, the action severed the operators' access to the infected hosts and their ability to deliver new commands. Evidence suggests that GlassWorm's operators are of Russian origin: the malware checks the system's locale and avoids infecting machines in CIS countries, and its code contains Russian-language comments. In addition to taking down the GlassWorm infrastructure, CrowdStrike has instructed the infected endpoints to beacon to the benign IP address 164.92.88[.]210. Organizations are advised to check for connections to this IP address to identify potential infections. Despite these efforts, the broader economics of repository abuse remain an ongoing issue. Open-source ecosystems continue to offer attackers low-cost distribution channels with a massive reach when compared to traditional software. This also means operators behind such campaigns can resurface under new accounts, domains, or package names. In other words, it's only a temporary disruption, not eradication.
  • CERT-In Urges Organizations to Patch Exploited Flaws Within 12 Hours - Organizations in India have been urged to patch actively exploited vulnerabilities impacting internet-facing or "crown jewel" systems within 12 hours, where feasible, so as to better respond to the speed artificial intelligence (AI) now brings to cyber attacks. CERT-In stopped short of framing the timelines as binding, describing them as indicative expectations to be applied according to operational criticality and threat exposure. The agency also warned that AI-assisted attacks are dramatically compressing the time between vulnerability disclosure and exploitation. The framework also recommends one-day remediation for critical externally exposed vulnerabilities, three days for critical internal vulnerabilities affecting high-value systems, and five days for high-severity flaws based on risk prioritization.
  • GREYVIBE Leans on AI for Ukraine Attacks - A previously undocumented Russian group codenamed GREYVIBE has been found to make extensive use of large language models (LLMs) in its attacks against private, government, and military organizations in Ukraine. The end goal is to gather intelligence for the ongoing war. "While the activities align with Russian state interests, several observed indicators suggest the group has ties to the broader cybercrime ecosystem, with the group potentially involving current or former cybercriminal actors," WithSecure said. The threat actor is believed to have been active since August 2025. What's notable is the extent to which AI appears to be enmeshed throughout the operation. The group's use of AI is believed to be "operationally integrated rather than isolated or experimental."
  • AI Chatbot Recommendations Redirect Users to Cryptojacking Malware - A new campaign is using searches for popular tools in AI chatbots to redirect users to sketchy sites that trick users into downloading booby-trapped executables that drop a cryptocurrency miner on compromised hosts. The goals of the campaign are not merely financially motivated. The threat actors have also been found to establish persistent remote access to compromised hosts through ScreenConnect deployments, which could then be leveraged for follow-on activity, such as data theft, lateral movement, or ransomware.

🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-8732 (WP Maps Pro plugin), CVE-2026-0257 (Palo Alto Networks PAN-OS and Prisma Access), CVE-2026-27771 (Gitea), CVE-2026-45659 (Microsoft SharePoint), from CVE-2026-9090 through CVE-2026-9098 (Casdoor), CVE-2026-48800, CVE-2026-48778, CVE-2026-48770 (Notepad++), CVE-2026-40933 (Flowise), from CVE-2026-9872 through CVE-2026-9893 (Google Chrome), CVE-2026-32996, CVE-2026-32997 (Veeam Backup & Replication), CVE-2026-44962 (Plesk), CVE-2026-4868, CVE-2026-1402, CVE-2026-6713 (GitLab), CVE-2026-46840, CVE-2026-46775, CVE-2026-46839, CVE-2026-2332 (Oracle), CVE-2026-4480 (Samba), CVE-2025-59199 aka Click Or Trick (Microsoft Windows 11), CVE-2026-9560 (OpenVPN Connect for macOS), CVE-2026-9312 (GitHub Enterprise Server), CVE-2026-3593, CVE-2026-5946, CVE-2026-5947 (BIND 9), CVE-2026-47783 (Memcached), CVE-2026-44930 (Apache CXF), CVE-2026-9089 (ConnectWise Automate), CVE-2026-4115 (PuTTY), CVE-2026-48095 (7-Zip), an argument injection vulnerability in Gogs, a remote code execution vulnerability in Microsoft Visual Studio Code Remote-SSH extension, and multiple vulnerabilities in Roundcube Webmail.

🎥 Cybersecurity Webinars

  • Beyond Zero-Day: How Attackers Actually See Your Network → Zero-days are inevitable. The real battle is what attackers see once they're inside. Join HD Moore (creator of Metasploit) in this webinar as he reveals how to map your network like an attacker - exposing hidden assets, forgotten bridges, and dangerous IT/IoT/OT connections most teams miss.
  • Why Automated Pentesting Falls Short - And How to Fix It → Automated pentesting tools promised comprehensive security validation, but in reality, they only scratch the surface. After a few runs, new findings drop sharply, leaving critical blind spots in detection, response, and control effectiveness. Join Autumn Stambaugh and Can Yüceel of Picus Security as they explain why automated pentesting alone isn't enough - and how to build a complete validation program that actually closes the gaps.

📰 Around the Cyber World

  • New Windows Flaw Under Attack - Belgium's Centre for Cybersecurity (CCB) has warned that a recently patched Windows flaw, CVE-2026-41089, has come under active exploitation in the wild. The vulnerability is a stack-based buffer overflow in Windows Netlogon that allows an unauthorized attacker to execute code over a network. There are currently no details on how the vulnerability is being exploited. The vulnerability was addressed by Microsoft as part of its May 2026 Patch Tuesday update.
  • Anthropic Confirms Mythos Release - Anthropic has confirmed it intends to bring Mythos-class models to "all our customers in the coming weeks" and said it's "making swift progress" on developing stronger cyber safeguards prior to their release.
  • New Linux Flaw CIFSwitch Uncovered - A newly disclosed Linux local privilege escalation (LPE) vulnerability dubbed CIFSwitch has been found to enable low-privileged users to gain root access by abusing a logic flaw between the Linux kernel Common Internet File System (CIFS) client and the userspace helper package, cifs-utils. According to SpaceX security engineer Asim Viladi Oglu Manizada, the kernel-side bug has been around since 2007. A patch for the flaw has been pushed to mainline Linux as of May 19, 2026.
  • Dashlane Warns of Brute-Force Attack - Dashlane said: "user accounts were targeted in a brute force attack by an external party, resulting in the suspension of those accounts as part of Dashlane's built-in security measures." The affected accounts have since been unsuspended. The password management company also noted that it's taking measures to address the issue, adding that there is no evidence of compromise of Dashlane's systems. It's not known who is behind the attack.
  • Global Smishing Operation Impacts 19 Countries - Hunt.io said it identified a coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus. "The same infrastructure hitting Romanian taxpayers was also targeting DPD delivery customers in the U.K. and Ireland, road police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the United States," the company said. "1,628 malicious URLs confirmed active across 19 countries and multiple sectors." The campaigns are designed to invoke a false sense of emergency using fabricated fines and trick users into making payments and entering their personal information.
  • Microsoft Teams and Google Drive Abused to Deliver Java RAT - An intrusion targeting a customer in the legal industry involved the use of Microsoft Teams voice phishing to deceive the victim into granting remote access via Quick Assist. It was followed by the deployment of a Java-based remote access trojan (RAT) named Nimbus RAT. "Nimbus RAT is a self-contained implant that uses Google Drive and Google Sheets for command-and-control (C2), helping its network traffic appear benign," eSentire said. "From initial Teams contact to RAT execution, the attack took less than 20 minutes." The activity overlaps with similar Teams-based social engineering attacks carried out by BlackSuit affiliates.
  • Tracking Site Visitors Via FROST - New research has shown that malicious websites can track visitors by measuring tiny changes in SSD access times as a side channel, turning normal browser activity into a privacy leak. The attack, named FROST (short for Fingerprinting Remotely using OPFS-based SSD Timing), is a "side-channel attack from JavaScript that exploits OPFS [Origin Private File System] to leak sensitive information from the browser without requiring any user interaction on both Linux and macOS." The attack "uses SSD contention measurements from within the browser to fingerprint user activity on a system," a group of academics from the Graz University of Technology and Liebherr-Transportation Systems GmbH said. "After tricking the victim into clicking a malicious link, an attacker can monitor the victim's activity on the host system, such as website visits and application usage, without further user interaction." The impact of the attack goes beyond website tracking. The study also demonstrated that it's possible to fingerprint application usage, allowing attackers to potentially infer where specific apps were opened.
  • Instagram Exploit Allegedly Enabled Account Takeover - According to Dark Web Informer and ZachXBT, Instagram is said to have suffered from an exploit that made it possible to use Meta AI to reset passwords to accounts with no multi-factor authentication (MFA) enabled. To pull off the attack, bad actors simply had to use a VPN to approximately match their location to the target Instagram account's region, begin the password reset process, and then prompt Meta's AI support chatbot to change the email address associated with the account. The end goal of the attack appears to link the target account with a new email address using the Meta AI chatbot, seize control of high-profile Instagram profiles, and sell them on the gray market for thousands of dollars. According to a report from 404 Media, bad actors have been aware of the loophole since March 2026. The exploit has since been patched, though it's unclear how many accounts were impacted by the exploit. The incident highlights the dangers of granting AI agents overly broad permissions that could be abused to trigger unintended actions without any human confirmation.
  • EvilTokens Abuses OAuth Flow, RatPressto Kit Surfaces - The phishing-as-a-service (PhaaS) platform known as EvilTokens is being used to carry out device code phishing attacks at scale. "These campaigns are notable for abusing the OAuth 2.0 device authorization flow, automating this sophisticated phishing at scale, and using AI to produce realistic, quickly deployable attack infrastructure," Netcraft said. The company said it has seen thousands of attacks using the EvilTokens phishing kit. The development coincides with the emergence of a new phishing toolkit dubbed RatPressto that's being used in an active campaign. The kit, hosted on legitimate-but-compromised WordPress sites, is used to serve ScreenConnect for establishing persistent remote access. "RatPressto has been observed targeting financial organizations, looking to silently exfiltrate credentials, secrets, and sensitive data that could be used to aid further compromise," Fortra said.
  • Solo Russian-Speaking Threat Actor Linked to Patriot Bait Campaign - A solo Russian-speaking threat actor tracked as "bandcampro" ran a 5-year MAGA-themed Telegram channel (@americanpatriotus, approximately 17,000 subscribers) and pivoted to AI-automated content, fraud, and credential theft starting September 2025. "A jailbroken Google Gemini served as the actor's co-worker, generating Q-styled posts, deploying infrastructure, rotating stolen API keys, modeling victim passwords, and running a QAnon-styled chatbot (QFS 2.0 Terminal)," Trend Micro said. "Safeguards were bypassed via jailbreaking and non-English prompting, allowing explicit pump-and-dump prompts and instructions to mutate victim passwords to be processed, showing how frontier-AI safety controls can be circumvented through jailbreaks and non-English prompting." The campaign once again highlights how AI has significantly cut down the resources needed to run influence operations.
  • SonicWall Scanning Spike Recorded - GreyNoise said it observed a "significant new spike in scanning of SonicWall SonicOS management interfaces" between May 9 and May 18, 2026. "Approximately 56% of sessions originate from networks announced in the Netherlands and 44% in Ukraine - together more than 99% of total volume," it said. "A single ASN (AS211736) carries roughly half of the total session volume."
  • New Payload Ransomware Emerges - Cybersecurity researchers have analyzed ransomware families like NightSpire and Payload, with the latter already racking up 50 victims on its leak site since emerging in February 2026. "Although the group initially claimed only a limited number of victims, its operations quickly showed a global footprint, with targets across Egypt, Mexico, and Poland," Dark Atlas said.

🔧 Cybersecurity Tools

  • EvidenceForge → It is an open-source tool from Cisco Talos that generates realistic, multi-format synthetic security logs - including Windows events, Sysmon, Zeek, and more - with strong consistency and causal relationships. It's particularly useful for threat hunting training, detection testing, and research where you need high-quality, non-obvious synthetic data.
  • MCPGuard-Dynamic → It is an open-source project from Facebook that provides kernel-level sandboxing for LLM agent tool calls using the Model Context Protocol (MCP). It combines policy enforcement, argument validation, and eBPF-based system call guards to restrict what potentially untrusted MCP servers can do - helping prevent file access, network exfiltration, and privilege escalation attempts.

Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law.

Conclusion

That's the week: too much speed, too many defaults, and not enough people treating "minor" exposed crap like it can become tomorrow's incident report. The pattern is boring until it's your box - attackers keep finding the cheap paths first, because cheap still works.

Patch the loud stuff, audit the weird stuff, and don't ignore the boring stuff. That's usually where the fire starts.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html