Aggregator
CVE-2026-23288 | Linux Kernel up to 6.19.6/7.0-rc1 amdxdna memset out-of-bounds write (Nessus ID 304072 / WID-SEC-2026-0861)
CVE-2026-23287 | Linux Kernel up to 7.0-rc1 sifive-plic plic_irq_eoi denial of service (Nessus ID 311783 / WID-SEC-2026-0861)
Cisco security advisory (AV26-602)
618倒计时!公众号粉丝课程半价福利,错过再等一年!
Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase
Two of the more active ransomware groups operating today, Interlock and Rhysida, have more in common than previously thought. New research shows both groups share a backdoor called Supper, and that several of their malware tools appear to have grown from the same original code. The Interlock group, tracked internally as Hive0163, has been running […]
The post Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase appeared first on Cyber Security News.
CVE-2026-23286 | Linux Kernel up to 7.0-rc2 recv_vcc lec_arp_clear_vccs memory leak (Nessus ID 311783 / WID-SEC-2026-0861)
CVE-2026-23285 | Linux Kernel up to 7.0-rc1 drbd drbd_request_endio null pointer dereference (Nessus ID 311340 / WID-SEC-2026-0861)
CVE-2026-23284 | Linux Kernel up to 7.0-rc2 mtk_eth_soc mtk_xdp_setup privilege escalation (Nessus ID 311783 / WID-SEC-2026-0861)
CVE-2026-23283 | Linux Kernel up to 6.19.6/7.0-rc1 regulator fp9931_hwmon_read memory leak (Nessus ID 304069 / WID-SEC-2026-0861)
Урны не тронули — атаковали мозги избирателей. Франция раскрыла четырёх иностранных игроков, влиявших на выборы
Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating BOD 22-01. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV catalog? Submit for potential addition: KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Over Two-Thirds of Security Pros Say Cyber Is Getting Harder
CVE-2026-6047 | LibreOffice up to 25.8.6/26.2.2 out-of-bounds write (Nessus ID 321146)
CVE-2026-52719 | GStreamer gst-plugins-bad out-of-bounds (Nessus ID 321147 / WID-SEC-2026-1919)
CVE-2026-52718 | GStreamer AV1 Codec Parser gst_av1_parser_parse_tile_list_obu assertion (Nessus ID 321145 / WID-SEC-2026-1919)
CVE-2026-53704 | GStreamer FILEINFO re_skip_pascal_string out-of-bounds (Nessus ID 321148 / WID-SEC-2026-1919)
Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets
Danish pharmaceutical giant Novo Nordisk has confirmed a cyberattack in which threat actors gained unauthorized access to internal IT systems, exfiltrating pseudonymized patient data from clinical trials and, according to the alleged attackers, a trove of proprietary AI model assets. Novo Nordisk disclosed the incident on June 11, 2026, stating that attackers copied “certain non-public […]
The post Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets appeared first on Cyber Security News.