radar.cysentrix

Security Radar

Page 1 of 10 · 383 stories from the last 30 days across 20 trusted sources.

Actively exploited 10 actively exploited CVEs in current coverage
View all CVEs →
  • CVE-2026-20253

    AICritical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) exploited in wild; CISA added to KEV, federal agencies must patch by June 21.

    5storiesEPSS 10%
  • CVE-2026-0257

    Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

    2storiesEPSS 19%
  • CVE-2026-20262

    CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day Leads to Root

    2storiesEPSS 1%
  • CVE-2025-8088

    Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs

    1storyEPSS 81%
  • CVE-2026-42271

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    1storyEPSS 54%
  • CVE-2026-50751

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    1storyEPSS 41%
BleepingComputer

FFmpeg fixes PixelSmash flaw in widely used video decoder

A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]

Security Affairs

WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools

WhatsApp accounts were hijacked to spread fake debt notices that install remote access software, giving attackers control of victims’ PCs. Kaspersky published a technical analysis this week of an active malware campaign that spreads through WhatsApp messages and ends with a re...

malware
Microsoft Security

Guarding AI memory

What happens when threat actors target what AI remembers? Microsoft breaks down the risks and the defenses. The post Guarding AI memory appeared first on Microsoft Security Blog.

microsoft
Security Affairs · SecurityWeek · BleepingComputer3 stories

Texas govt data breach exposes over 3 million driver’s licenses

AITexas Parks & Wildlife data breach via third-party vendor exposed personal info of over 3 million, including driver’s licenses.

Open narrative →
data breach
Show all coverage
The Hacker News · BleepingComputer2 stories

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

AIThreat actors compromised ShapedPlugin's build pipeline, backdooring multiple WordPress plugins and distributing malicious updates to paying customers via the official update system.

Open narrative →
supply chain
Show all coverage
BleepingComputer

Microsoft fixes AutoGen Studio flaw that enabled code execution

A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system simply by visiting a malicious webpage. [...]

vulnerabilitymicrosoft
Microsoft Security

One intrusion, two cyberattackers: Uncovering parallel threat activity

Ransomware case reveals two parallel threat actors, blending tactics and evasion—showing why isolated signals can often miss modern, overlapping cyberattacks. The post One intrusion, two cyberattackers: Uncovering parallel threat activity appeared first on Microsoft Security B...

ransomwaremicrosoft
The Hacker News

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is still live in Sq...

SANS Internet Storm Center

Webshells Remain Popular, (Mon, Jun 22nd)

Webshells have been popular for a long time. We already covered this topic across multiple diaries[1][2]. I spent some time to track them[3] and slighly paid less attention to them but today I found another one. It seems to be a new player (pushed on Github two months ago).

Security Affairs

Anthropic’s Mythos AI broke into almost all NSA classified systems in hours

Senate testimony claims Anthropic’s Mythos AI breached NSA and Cyber Command systems in hours, prompting a U.S.-ordered shutdown. On June 12, the Trump administration directed Anthropic to restrict access to Fable 5 and Mythos 5, its two most capable models, exclusively to US ...

The Hacker News

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute ...

malware