Daily cybersecurity intelligence

The latest unpatched intel.

Raw, actionable daily security news for defenders tracking exploited vulnerabilities, ransomware, breaches, malware, cloud risk, supply-chain security, and practical detection guidance.

Latest stories

highData BreachesJun 15, 2026·3 min read

AI Models Weaponized for Vulnerability Identification: Urgent Security Measures Needed

AI models have been weaponized to identify software vulnerabilities, posing significant risks. Organizations must adopt proactive measures to secure against these AI-driven threats.

highAPT / Nation-StateJun 15, 2026·4 min read

CISA Catalogs Two Actively Exploited Vulnerabilities: Critical Patches Urged

Two critical vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog: Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and LiteSpeed cPanel Plugin (CVE-2026-54420).

criticalExploited VulnerabilitiesJun 13, 2026·3 min read

Unauthenticated File Manipulation Flaw in Splunk Enterprise Exposes Critical Risk

A critical vulnerability in Splunk Enterprise allows unauthenticated users to create or truncate arbitrary files through the PostgreSQL sidecar service endpoint.

highExploited VulnerabilitiesJun 12, 2026·4 min read

U.S. CISA Mandates Immediate Patching of Exploited Ivanti Sentry Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch an actively exploited Ivanti Sentry vulnerability within three days due to its severe risk of

criticalRansomwareJun 11, 2026·3 min read

Critical Oracle PeopleSoft Zero-Day Exploited by ShinyHunters: Over 100 Organizations at Risk

A critical vulnerability in Oracle's PeopleSoft Enterprise PeopleTools (CVE-2026-35273) has been actively exploited by the ShinyHunters group to execute remote code execution attacks.

highExploited VulnerabilitiesJun 11, 2026·3 min read

GreatXML Exploit Bypasses BitLocker via Microsoft Defender's Offline Scan

A newly disclosed exploit named GreatXML allows attackers to bypass Windows BitLocker encryption by exploiting a vulnerability in Microsoft Defender's offline scan functionality.

mediumDefensive GuidanceJun 11, 2026·2 min read

Unauthorized Access Threat to Industrial Control Systems via Brickcom Camera Vulnerability

A recent advisory from CISA highlights a vulnerability in Brickcom Cameras that could allow unauthorized access to industrial control systems.

highDefensive GuidanceJun 11, 2026·3 min read

Unpatched Vulnerability Exposes Brickcom Cameras to Unauthorized Live Video Access

A significant vulnerability (CVE-2026-50245) has been identified in Brickcom's Cube cameras, allowing unauthenticated access to live video feeds via the `/ONVIF` endpoint.

highData BreachesJun 10, 2026·3 min read

Critical Path Traversal Flaw in Langflow Exploited, Immediate Upgrade Advised

A critical path traversal vulnerability in the AI development platform Langflow (CVE-2026-5027) is being actively exploited.

highData BreachesJun 10, 2026·3 min read

Exploited Ivanti Sentry Vulnerability Grants Root Access to Attackers

Attackers are exploiting a high-severity command injection vulnerability in Ivanti Sentry, allowing them to execute code with root privileges on exposed secure mobile gateways.

highAPT / Nation-StateJun 10, 2026·3 min read

Microsoft Fixes Critical XSS Flaw in Exchange Server Actively Exploited by Threat Actors

Microsoft has patched an actively exploited vulnerability in Exchange Server that allows threat actors to execute arbitrary JavaScript code via cross-site scripting (XSS) attacks.

highExploited VulnerabilitiesJun 10, 2026·2 min read

Microsoft Fixes Critical Zero-Days Allowing SYSTEM Privileges and BitLocker Bypass

Microsoft recently patched three zero-day vulnerabilities-GreenPlasma, MiniPlasma, and YellowKey-that could allow attackers to gain SYSTEM privileges or bypass BitLocker protection on Windows systems.