radar.cysentrix

Security Radar

Page 1 of 10 · 460 stories from the last 30 days across 19 trusted sources.

Actively exploited 15 actively exploited CVEs in current coverage
View all CVEs →
  • CVE-2026-20253

    AICritical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) exploited in wild; CISA added to KEV, federal agencies must patch by June 21.

    5storiesEPSS 92%
  • CVE-2026-0257

    Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

    2storiesEPSS 87%
  • CVE-2026-20262

    CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day Leads to Root

    3storiesEPSS 1%
  • CVE-2026-10520

    CISA Adds One Known Exploited Vulnerability to Catalog

    1storyEPSS 99%
  • CVE-2026-35273

    ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

    1storyEPSS 90%
  • CVE-2025-8088

    Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs

    1storyEPSS 86%
Security Affairs

DifyTap: Four Bugs Put over 1 million AI Apps at Risk

Four flaws in Dify exposed cross-tenant data, documents and AI conversations. Two critical bugs enabled unauthenticated access and data theft. Zafran Labs researchers disclosed four vulnerabilities in Dify, the open-source AI platform used by major companies like Volvo and Mae...

vulnerability
Krebs on Security · BleepingComputer · The Record · Help Net Security4 stories

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

AITwo Scattered Spider members pleaded guilty to the 2024 cyberattack on Transport for London, causing major disruption and £29 million in losses.

Open narrative →
Show all coverage
SecurityWeek

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs. The post Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps appeared first on SecurityWeek.

cloud
The Hacker News · SecurityWeek2 stories

Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration

AITrump signed an executive order setting a 2030 deadline for federal agencies to migrate high-value assets to post-quantum cryptography, with digital signatures due by 2031.

Open narrative →
Show all coverage
The Hacker News

GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns

GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code with the workflow's full privileges. Effective June 18, 2026...

supply chain
BleepingComputer

LastPass confirms data breach in Klue supply chain attack

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. [...]

data breachsupply chain
Help Net Security

Using Reddit to manipulate AI search results is surprisingly easy

A Reddit comment that takes only a few seconds to write can end up influencing the answers generated by AI research tools. A Cornell Tech study found that a short snippet of user-generated text, sometimes as little as 13 words, was enough to affect the output of deep-research ...