FortiBleed Hits FortiGate Devices

FortiBleed: When VPN Credentials Become Everyone’s Problem CISA warned Fortinet customers about FortiBleed, a large-scale campaign targeting internet-facing FortiGate devices. As of 19 June 2026, 86,644 devices were reportedly compromised. Attackers appear to be using leaked, weak and reused credentials, along with automated spraying against Fortinet remote login endpoints. The campaign has affected telecom, government […]

Read More

Legacy Infrastructure Hijacking AI Agent

Your AI Agent May Be Secure. Your Old Server Probably Isn’t. This article argues that attackers do not need to attack AI systems directly when legacy infrastructure already provides a path to compromise them. AI agents inherit access from identity providers, cloud roles, service accounts and developer environments. A chain involving an unpatched Tomcat server, […]

Read More

Squidbleed-Squid Proxy Bug

Squidbleed: The 29-Year-Old Proxy Bug That Still Had One More Trick A 29-year-old Squid proxy bug, named “Squidbleed” and tracked as CVE-2026-47729, can leak cleartext HTTP requests from other users sharing the same proxy. The flaw sits in Squid’s FTP directory-listing parser and can expose headers, credentials or session tokens if traffic is visible to […]

Read More

Check Point VPN Flaw Exploited

Check Point VPN Flaw: Passwords Optional, Apparently Check Point warned that CVE-2026-50751, a critical flaw affecting Remote Access VPN and Mobile Access deployments using deprecated IKEv1, is being actively exploited. The logic flaw in certificate validation allows unauthenticated attackers to bypass password requirements and establish VPN sessions under specific configurations. Exploitation requires remote access or […]

Read More

One-Character Linux Kernel Flaw

Linux Kernel Bug: One Character, Root Access, Big Headache Researchers published working exploit details for CVE-2026-23111, a Linux kernel use-after-free in nf_tables that can let an unprivileged local user escalate to root and escape containers. The flaw was patched upstream in February 2026 and resulted from a one-character logic error. Exploits have been demonstrated across […]

Read More

LiteLLM Exploited

LiteLLM Flaw Turns AI Gateway Into an Attack Gateway CISA added LiteLLM CVE-2026-42271 to its Known Exploited Vulnerabilities catalogue after evidence of active exploitation. The flaw is a command injection vulnerability affecting LiteLLM versions 1.74.2 through before 1.83.7, allowing authenticated users to execute arbitrary commands on the host. Researchers also showed it could be chained […]

Read More

Chrome V8 Zero-Day

Chrome Zero-Day: Update Before Your Browser Gets Ideas Google released Chrome security updates fixing 74 vulnerabilities, including CVE-2026-11645, a high-severity V8 zero-day exploited in the wild. The issue is an out-of-bounds memory access flaw in Chrome’s JavaScript and WebAssembly engine that could allow remote code execution inside the browser sandbox via a crafted HTML page. […]

Read More

Veeam Backup & Replication RCE

Veeam RCE: Because Attackers Love Backups Too Veeam patched a critical remote code execution vulnerability in Backup & Replication, tracked as CVE-2026-44963 with a CVSS score of 9.4. The flaw allows an authenticated domain user to execute remote code on the backup server. It affects Veeam Backup & Replication 12.3.2.4465 and earlier version 12 builds, […]

Read More

Microsoft Defender RoguePlanet Zero-Day

RoguePlanet: When Microsoft Defender Needs Defending A researcher known as Chaotic Eclipse released proof-of-concept exploit code for a Microsoft Defender zero-day named RoguePlanet. The flaw is described as a race condition that can grant SYSTEM-level privileges when successfully exploited. It was reportedly tested on fully updated Windows 10 and Windows 11 systems after June 2026 […]

Read More