radar.cysentrix

Security Radar

Page 1 of 10 · 338 stories from the last 30 days across 20 trusted sources.

Actively exploited 10 actively exploited CVEs in current coverage
View all CVEs →
  • CVE-2025-8088

    Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs

    1storyEPSS 81%
  • CVE-2026-42271

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    1storyEPSS 54%
  • CVE-2026-50751

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    1storyEPSS 41%
  • CVE-2026-20253

    AICritical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) exploited in wild; CISA added to KEV, federal agencies must patch by June 21.

    5storiesEPSS 10%
  • CVE-2026-0257

    AIPalo Alto Networks warns of active exploitation of CVE-2026-0257, a PAN-OS GlobalProtect VPN flaw. Unknown threat actors are using it to gain unauthorized access to portals.

    2storiesEPSS 19%
  • CVE-2026-35273

    ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

    1storyEPSS 8%
Security Affairs

Inside GentleKiller: The EDR-Killer Powering The Gentlemen

The Gentlemen equips affiliates with a centralized EDR-killer suite, rapidly weaponizing BYOVD exploits to disable security tools before ransomware attacks. ESET published a detailed breakdown of The Gentlemen‘s technical infrastructure on June 18, the result of months of inci...

ransomware
Security Affairs

FortiBleed Exposes Global Credential-Spraying Operation

FortiBleed exposed a massive campaign that made billions of login attempts against Fortinet VPNs, compromising organizations worldwide. FortiBleed wasn’t a targeted hack. It was a factory. A multi-operator crew ran an industrial-scale attack against Fortinet FortiGate SSL VPN ...

Security Affairs · The Hacker News · BleepingComputer · Help Net Security4 stories

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

AICISA urged Fortinet customers to secure devices after the "FortiBleed" data leak exposed credentials from tens of thousands of firewalls and VPN gateways.

Open narrative →
data breach
Show all coverage
Unit 42

Threat Brief: Mitigating Large-Scale Credential Attacks

We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42.

BleepingComputer

Klue OAuth breach victim list grows as Icarus hackers claim attack

Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. [...]

data breach
Schneier on Security

Friday Squid Blogging: Victims of Unregulated Squid Fishing

Dolphins, sharks, turtles, and human workers are all victims of unregulated squid fishing fleets. Another news article. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

The Hacker News · BleepingComputer2 stories

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

AIGentlemen RaaS uses GentleKiller EDR framework targeting over 400 security processes to disable defenses before deploying ransomware.

Open narrative →
ransomware
Show all coverage
Graham Cluley

Apple’s Hide My Email tweak leaves privacy fans fuming

Apple has long marketed itself as the privacy-first tech giant. So why is it making a change to Hide My Email that will make it easier for websites to block anonymous sign-ups - and harder for you to stay private online? Read more in my article on the Hot for Security blog.

The Hacker News

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the same ...

microsoft
SOCRadar · Help Net Security · BleepingComputer · Security Affairs · SecurityWeek · The Hacker News6 stories

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

AICritical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) exploited in wild; CISA added to KEV, federal agencies must patch by June 21.

Open narrative →
vulnerabilityzero day Actively exploitedCVE-2026-20253 · EPSS 10%
Show all coverage
The Hacker News · Security Affairs · The Record · SecurityWeek · CyberScoop · Help Net Security · BleepingComputer7 stories

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

AIOperation Endgame disrupted SocGholish botnet infrastructure linked to Russia's Evil Corp, taking down 106 servers and cleaning nearly 15,000 infected WordPress sites.

Open narrative →
malware
Show all coverage