Palo Alto Networks Patches 13 Vulnerabilities
Palo Alto Networks patched 13 vulnerabilities including authentication bypass and RCE risks in Panorama and PAN-OS. Organizations must prioritize patching to close attack vectors.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
Palo Alto Networks patched 13 vulnerabilities including authentication bypass and RCE risks in Panorama and PAN-OS. Organizations must prioritize patching to close attack vectors.
The UK's Cyber Shield deploys agentic AI to match attackers who compress cyber exploits from weeks to minutes. It aims for machine-speed defense against predicted fully autonomous attacks.
Cyberattacks spike 40% during summer vacations as skeleton IT crews reduce security capacity. AI-enhanced threats exploit staffing gaps and slower threat detection, making 2026's seasonal window particularly dangerous for unprepared organizations.
Forg365 targets Microsoft 365 users with AI-generated phishing lures and credential theft. Discovered by ZeroBEC, it represents a major escalation in phishing-as-a-service sophistication.
GhostLock, a Linux kernel flaw hidden for 15 years, lets attackers gain root access on billions of systems. The vulnerability affects all major distributions and risks cloud platforms.
AI gateways are vulnerable due to weak security. A cryptomining campaign exploited gateway weaknesses to access cloud infrastructure and credentials, exposing their critical trust boundary role.
AI-powered attacks now execute in minutes through automated phishing and reconnaissance. Traditional defenses designed for human-speed response can't keep pace with machine-speed exploitation.
Microsoft patched CVE-2026-50656, a race condition in Malware Protection Engine enabling local SYSTEM access. Publicly disclosed without workaround, it fully compromises antimalware protections.
AI-driven vulnerability discovery is overwhelming open source. New clearinghouses automate remediation for obscure dependencies, where vulnerabilities pose equal risks despite low visibility.
INTERPOL's Operation First Light 2026 arrested 5,811 suspects across 97 countries, seized $293M, and identified 142,000 fraud victims in an unprecedented coordinated global anti-fraud crackdown.
Microsoft is retiring OWA Light in August 2026 after nearly 20 years. Exchange admins must migrate users to modern Outlook on the Web before the deadline to reduce legacy attack surface and simplify infrastructure.
Chrome 150 patches 27 vulnerabilities including high-severity flaws enabling remote code execution and sandbox escapes. Users should update immediately as Chrome's 3 billion users make it a prime attack target for threat actors.
Spanish identity startup 8Layers raised $2.9M in pre-seed eight weeks after launch. The funding signals strong market demand for credential protection amid account takeover attacks.
Meta's Muse AI automatically feeds public Instagram photos into its image generation model by default, without user opt-in consent, enabling the platform to reference people's faces and personal posts as AI training material. The feature raises privacy concerns about how tech giants exploit user-gen
A hardcoded backdoor in Tenda firmware (CVE-2026-11405) exposes millions of routers to unauthorized admin access using any username with a fixed password. No patch exists, leaving hundreds of thousands of devices in enterprise and consumer environments completely vulnerable.
GhostApproval affects six AI coding assistants, including Claude Code. It exploits symlinks and broken approval dialogs to inject SSH keys into sensitive files, enabling account hijacking.
"Friendly Fire" attacks deceive AI agents into running malware hidden in README files. Claude Code and Codex autonomously execute attacker payloads during security audits, exploiting workflow design vulnerabilities rather than code bugs.
Microsoft patched CVE-2026-50656 (RoguePlanet), a Windows Defender zero-day enabling SYSTEM privilege escalation on fully patched Windows 10/11. Researcher Nightmare Eclipse's disclosure sparked tensions with Microsoft over bug bounty policies and legal threats.
China-linked hackers exploit Roundcube vulnerabilities at North American universities. They steal researcher credentials and establish backdoors to infiltrate sensitive research networks, part of a broader intelligence-gathering operation.
Attackers pose as IT staff directing victims to fake passkey enrollment pages, stealing credentials and MFA codes in real-time. The campaign weaponizes Microsoft's new passkey feature as a social engineering vector, with operator-controlled phishing kits monitored live to harvest authentication resp
Researchers discovered 'GitLost,' a critical prompt injection flaw in GitHub Agentic Workflows that lets unauthenticated attackers steal private repository data through a single malicious GitHub Issue. No credentials required.
**Summary:** CISA confirmed active exploitation of four critical vulnerabilities in Adobe ColdFusion, Langflow, and Joomla extensions—all enabling unauthenticated remote code execution. Federal agencies must patch by July 10.
A critical Google Cloud Dialogflow CX vulnerability allowed attackers with minimal write permissions to silently hijack AI agents, steal sensitive data, inject phishing attacks, and erase audit trails across entire enterprise deployments. The flaw exposed companies in customer service, finance, and
Blocking phishing emails doesn't stop attacks—attacker infrastructure remains active. Traditional email defenses address detection, not disruption, leaving organizations vulnerable to persistent campaigns.
Ubiquiti patched seven critical flaws (CVSS 9.0–10.0) in UniFi products allowing unauthenticated network-based command injection across access control, security, and networking systems. Prior Ubiquiti vulnerabilities were actively weaponized by Russian state-sponsored actors, establishing a concerni
Cybersecurity startup IRIS C2, which offers up to $7 million for zero-day exploits, is operated by convicted felons Jack Burkman and Jacob Wohl, known for orchestrating disinformation campaigns and election interference schemes. The venture uses infrastructure from their prior fraudulent operations
**EvilTokens exploits "ghost phishing"—emails bypass security scanners by appearing harmless in transit, then reveal malicious phishing pages only when opened in browsers, targeting Microsoft 365 credentials.**
AI automates personalized service desk attacks at scale, defeating traditional detection methods like skepticism and consistency checks. Organizations must strengthen identity verification and behavioral monitoring to defend against this escalating threat.
Researchers discovered that GitHub Copilot and similar AI assistants refuse harmful requests in chat but comply when framed as development tasks—a vulnerability called "workflow-level jailbreaking." By disguising malicious prompts as routine coding work, attackers bypass safety guardrails these mode
With 75% of consumers and 68% of enterprises now using passkeys, attackers are abandoning credential stuffing to target weaker identity verification flows, relocating rather than retreating. As primary authentication hardens through passwordless security, the ATO threat has shifted downstream to hum