Monitoring 63 sources.
🚨 Active Exploits & Incidents
- Japan's largest taxi operator shuts systems after cyberattack — Nihon Kotsu, Japan's largest taxi operator, shut down part of its infrastructure after a confirmed cyberattack compromised its systems. Details on the attacker or malware used remain scarce but operational impact is significant.
- Active exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) — Multiple critical authentication bypass flaws in Cisco Catalyst SD-WAN Controller and Manager are actively exploited by sophisticated threat actors including UAT-8616. Patches exist; immediate remediation is mandated by CISA.
- Dirty Frag Linux kernel privilege escalation (CVE-2026-43284, CVE-2026-43500) — Public exploit code released for this chained local privilege escalation vulnerability in the Linux kernel. Affects multiple distros; patches pending but expected imminently. Exploit extends the "Copy Fail" bug class.
- Fragnesia Linux kernel privilege escalation (CVE-2026-46300) — New local privilege escalation with public PoC targeting the Linux kernel's XFRM ESP-in-TCP subsystem. Patch released May 13; existing mitigations for Dirty Frag do not cover this. Confirmed working on Ubuntu; no in-the-wild exploitation reported yet.
🔓 Vulnerabilities & CVEs
- Drupal Core SQL injection (CVE-2026-9082, CVSS 9.8) — Highly critical SQLi in Drupal's database abstraction layer affecting PostgreSQL sites. Unauthenticated remote exploitation possible. Detection PoC and patch diff publicly available; patches released across six supported branches.
- Lorex 2K Indoor Wi-Fi Camera remote code execution (CVE-2026-15680) — Format string RCE vulnerability exploitable by network-adjacent attackers. Immediate patching recommended.
- AnyDesk denial-of-service vulnerability (CVE-2026-15681) — Local attackers can cause DoS conditions on AnyDesk installations via screen recording link.
- 9Router unauthenticated API key exposure (CVE-2026-62327) — Remote attackers can retrieve plaintext API keys for connected AI provider accounts via unprotected API endpoints.
- 9Router unauthenticated information disclosure (CVE-2026-62328) — Remote access to sensitive user data via unprotected API usage endpoints.
- Multiple OpenClaw vulnerabilities (CVE-2026-62194 through CVE-2026-62200) — Authentication bypass, privilege escalation, and authorization bypass in versions prior to 2026.6.9. These allow lower-trust callers to execute owner-only tools and bypass network policies. Immediate upgrades advised.
🕵️ Threat Research & Deep Dives
- Jscrambler npm package backdoored with infostealer malware — Malicious version of the Jscrambler npm package downloaded ~1,500 times, stealing sensitive info. Supply chain risk for client-side web security.
- Mini Shai-Hulud worm: npm and PyPI supply chain campaign — TeamPCP group compromised 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance attestations. Targets developer and cloud credentials. Any system with affected packages must be treated as fully compromised.
- CrashStealer macOS malware uses notarized dropper to bypass Gatekeeper — Native C++ macOS info stealer masquerading as an Apple crash-reporting tool. Harvests credentials, keychain data, crypto wallets. Validates the victim's login password locally before exfiltration.
- Verizon DBIR 2026 key findings — Vulnerability exploitation is now the top initial access vector (31% of breaches). Median patch time increased by 11 days. AI-driven vulnerability discovery and exploitation accelerate risk, emphasizing the need for continuous exposure management.
📋 Vendor Bulletins & Advisories
- Microsoft Entra ID security update — Passkeys are now the default authentication method, with a new model for SMS and voice authentication. Prepare for transition to passwordless sign-in.
- Oracle June 2026 CSPU: 243 CVEs, 122 critical — Monthly Critical Security Patch Update addresses 243 CVEs across Oracle products, with Fusion Middleware receiving the most patches (106). Immediate patching recommended for critical fixes.
- Microsoft June 2026 Patch Tuesday: 198 CVEs, 32 critical, 3 zero-days — Largest Patch Tuesday release to date, including fixes for zero-days and critical vulnerabilities across .NET, Azure, Active Directory, and more. Urgent deployment advised.
- Oracle May 2026 CSPU: 35 CVEs, 11 critical — Monthly update with critical patches for Oracle E-Business Suite and other products.
- Microsoft May 2026 Patch Tuesday: 118 CVEs — Includes patches for Azure services, .NET, and Microsoft Edge. No zero-days exploited in the wild this cycle.
📰 Lesser-Known / Under-Reported
- Google & Microsoft remove ModHeader extension (1.6M installs) — Hidden dormant browsing-history collector found in the ModHeader extension. No evidence of data exfiltration, but the extension was removed from the Chrome and Edge stores as a precaution.
- "Yellow Teams" shaping AI security — Emerging practice where engineers build AI-based offensive and defensive tools to test AI's cybersecurity potential and threats. Early insights into the evolution of AI security operations.