radar.cysentrix

Security Radar

Page 1 of 10 · 516 stories from the last 30 days across 19 trusted sources.

Actively exploited 16 actively exploited CVEs in current coverage
View all CVEs →
  • CVE-2026-10520

    An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

    1storyEPSS 99%
  • CVE-2026-20253

    AICritical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) exploited in wild; CISA added to KEV, federal agencies must patch by June 21.

    5storiesEPSS 92%
  • CVE-2026-35273

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

    2storiesEPSS 90%
  • CVE-2026-50751

    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

    1storyEPSS 71%
  • CVE-2024-40766

    An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

    1storyEPSS 16%
  • CVE-2026-34908

    AICISA added max-severity Ubiquiti UniFi OS and Lantronix EDS5000 flaws to its Known Exploited Vulnerabilities catalog, warning they are actively exploited.

    1storyEPSS 2%
BleepingComputer · Security Affairs · CISA Alerts3 stories

CISA warns of max severity Ubiquiti flaws exploited in attacks

AICISA added max-severity Ubiquiti UniFi OS and Lantronix EDS5000 flaws to its Known Exploited Vulnerabilities catalog, warning they are actively exploited.

Open narrative →
vulnerability Actively exploited · EPSS 2%
Show all coverage
Help Net Security · CyberScoop · SecurityWeek3 stories

Algerian national accused of running cybercrime marketplaces extradited to US

AIAlgerian national Abdellah Belmili extradited to US for allegedly running marketplaces Market0Day and Spoxy that sold phishing kits and stolen credentials.

Open narrative →
phishing
Show all coverage
BleepingComputer

Securing the service desk: Why social engineering attacks keep succeeding

Service desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk social engineering attacks work and how organizations can defend against them. [...]

phishing
Help Net Security

Anthropic’s Claude Tag gives AI agents independent identities

Anthropic introduced an agent identity model for Claude Tag, its AI assistant designed for team collaboration in shared workspaces. The model gives Claude its own identity, permissions, and tool access, configured by administrators and tied to a workspace or channel. Because C...

SecurityWeek

macOS Weaknesses Chained to Silently Disable Endpoint Security Agents

A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities. The post macOS Weaknesses Chained to Silently Disable Endpoint Security Agents appeared first on SecurityWeek.

vulnerability
Security Affairs · Help Net Security · The Hacker News · SecurityWeek · BleepingComputer5 stories

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

AICisco Unified CM SSRF flaw (CVE-2026-20230) actively exploited for webshell deployment after PoC release.

Open narrative →
vulnerabilityzero day EPSS 26%
Show all coverage
SecurityWeek

Third DraftKings Hacker Sentenced to 18 Months in Prison

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. The post Third DraftKings Hacker Sentenced to 18 Months in Prison appeared first on SecurityWeek.

The Hacker News · SecurityWeek2 stories

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

AICordyceps CI/CD workflow flaws allow attackers to hijack open-source supply chains, exposing 300+ GitHub repos and potentially millions more, researchers warn.

Open narrative →
vulnerabilitysupply chain
Show all coverage
SecurityWeek

Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs

The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands. The post Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs appeared first on SecurityWeek.

vulnerability
CyberScoop

In a first, a court takedown goes after two cybercrime tools at once

Microsoft, with law enforcement and industry partners, disrupted more than 200 command and control servers for Amadey and StealC, often used in conjunction. The post In a first, a court takedown goes after two cybercrime tools at once appeared first on CyberScoop.

microsoft
Help Net Security

Phishing attack on healthcare firm Xsolis impacts 1.4 million people

Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January 22...

phishing