Microsoft Patches Record 206 Flaws

Microsoft Patch Tuesday Breaks Records, and Probably Some Weekend Plans Microsoft’s June 2026 Patch Tuesday fixed a record 206 vulnerabilities, including 39 critical issues and three publicly disclosed zero-days. The updates cover privilege escalation, remote code execution, information disclosure, spoofing, security bypass and denial-of-service flaws. Major issues include a Windows Kernel remote code execution vulnerability, […]

Read More

Ivanti Fortinet SAP Critical Patches

Ivanti, Fortinet and SAP Critical Patches Ivanti, Fortinet and SAP released fixes for multiple critical vulnerabilities affecting enterprise products. Fortinet patched a FortiSandbox command injection flaw. Ivanti fixed two critical Ivanti Sentry issues, including unauthenticated root-level remote code execution and authentication bypass allowing arbitrary admin account creation. SAP also addressed critical flaws across NetWeaver, ABAP […]

Read More

Cisco Secure Workload CVSS 10.0 Vulnerability

Cisco Secure Workload Gets the Full CVSS 10.0 Treatment Cisco has patched a critical CVSS 10.0 vulnerability affecting Secure Workload environments. The flaw could allow unauthenticated remote attackers to compromise affected systems completely. Cisco confirmed the issue impacts certain management components and urged organisations to apply updates immediately. The vulnerability highlights the continued risks associated […]

Read More

Drupal Core SQL Injection Vulnerability

Drupal SQL Injection Bug Reminds Everyone It’s Still 2008 Somewhere An actively exploited SQL injection vulnerability has been identified in Drupal Core. The flaw could allow attackers to execute malicious database queries, potentially resulting in data exposure, authentication bypass, or remote code execution under certain conditions. Researchers have confirmed exploitation attempts in the wild, and […]

Read More

LiteSpeed cPanel Plugin Vulnerability

LiteSpeed Plugin Flaw Gives Hosting Admins Another Headache A critical vulnerability (CVE-2026-48172) has been identified in a LiteSpeed cPanel plugin, potentially allowing attackers to compromise hosting environments remotely. The flaw impacts systems running vulnerable plugin versions and could lead to unauthorised access or server compromise. Hosting providers and administrators are strongly advised to apply patches […]

Read More

Trapdoor Supply Chain Attack

“Trapdoor” Shows Why Trusted Software Isn’t Always Trustworthy Researchers have uncovered a supply chain malware campaign named “Trapdoor”, where attackers compromised trusted software distribution channels to deliver malicious payloads to downstream users. The attack leveraged legitimate update mechanisms and trusted software packages, making detection significantly more difficult. Once installed, the malware enabled remote access, persistence, […]

Read More

Lazarus Goes Fileless Again

Lazarus Deploys RemotePE Malware North Korean threat group Lazarus has deployed a memory-only malware framework named RemotePE in recent campaigns. The malware executes payloads directly in memory, reducing forensic visibility and bypassing traditional security controls. Researchers believe the campaign targets organisations for espionage and credential theft. The use of fileless malware techniques continues to increase […]

Read More

Linux Kernel Copy Fail Vulnerability

Linux’s “Copy Fail” Shows Old Bugs Never Truly Die Researchers disclosed a nine-year-old Linux kernel vulnerability nicknamed “Copy Fail” (CVE-2026-31431), enabling local privilege escalation to root. The flaw impacts the Linux kernel cryptographic subsystem and has already been observed in active exploitation. Several major Linux distributions are affected, including Ubuntu, RHEL, and Amazon Linux. Public […]

Read More

Microsoft SharePoint RCE Vulnerability

SharePoint Servers Once Again Having a Rough Week Microsoft has patched a remote code execution vulnerability affecting SharePoint Server. The flaw could allow attackers to execute arbitrary code remotely under certain conditions, potentially leading to server compromise. The issue primarily affects on-premise SharePoint deployments and highlights continued risks facing legacy collaboration infrastructure. Microsoft has released […]

Read More