Researchers Disclose New GreatXML Vulnerability That May Bypass BitLocker Protections Through Windows Recovery Mode

317/69 Friday, June 12, 2026 Security researcher Chaotic Eclipse, also known as Nightmare Eclipse, has published a proof-of-concept (PoC) for a newly discovered vulnerability dubbed GreatXML, which may allow attackers to bypass BitLocker protections and obtain a SYSTEM-level command shell while Windows is running in Recovery Mode. The vulnerability was disclosed on June 10, 2026, […]

sittisak mintaboon

June 12, 2026

High-Severity Vulnerability in Langflow AI Development Platform Actively Exploited; Immediate Updates Recommended

316/69 Friday, June 12, 2026 Reports indicate that threat actors have begun exploiting a vulnerability in Langflow, a popular open-source drag-and-drop platform used for developing AI applications, AI agents, and Retrieval-Augmented Generation (RAG) systems. The vulnerability, tracked as CVE-2026-5027, allows attackers to write arbitrary files directly to servers running the platform. This poses a significant […]

sittisak mintaboon

June 12, 2026

Google Releases Emergency Update to Patch Actively Exploited Chrome Zero-Day Vulnerability

315/69 Thursday, June 11, 2026 Google Chrome has released an emergency security update to address an actively exploited zero-day vulnerability tracked as CVE-2026-11645. The flaw is the fifth Chrome zero-day vulnerability patched by Google since the beginning of 2026. Security updates are being rolled out for Windows and Linux (version 149.0.7827.102) and macOS (version 149.0.7827.103). […]

sittisak mintaboon

June 11, 2026

ServiceNow Releases Security Update After Vulnerability Used to Access Customer Instances Without Authorization

314/69 Thursday, June 11, 2026 ServiceNow has issued a security advisory after discovering that an unidentified threat actor exploited a vulnerability to gain access to certain customer ServiceNow instances with privileges exceeding those intended by the platform. The company stated that on June 5, 2026, it deployed a security update to affected hosted customer instances […]

sittisak mintaboon

June 11, 2026

Critical Vulnerability in Veeam Backup & Replication Could Allow Remote Code Execution

313/69 Thursday, June 11, 2026 Veeam has released a security update to address a critical vulnerability in its Veeam Backup & Replication software, an enterprise backup and recovery platform widely used by organizations. The vulnerability could allow an authenticated domain user to execute code remotely on a backup server, potentially enabling unauthorized access to and […]

sittisak mintaboon

June 11, 2026

Gogs Releases Patch for Zero-Day Vulnerability That Could Lead to Remote Code Execution

Gogs has released a patch to address a critical zero-day vulnerability that has not yet been assigned a CVE identifier. The flaw is an Argument Injection vulnerability that could allow attackers to execute code remotely on affected servers. The vulnerability affects all Gogs versions up to 0.14.2, including 0.15.0+dev, and has been fixed in version […]

chanapon

June 10, 2026

CISA Adds BerriAI LiteLLM and Check Point Security Gateway Vulnerabilities to KEV Catalog After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that they have been actively exploited in attacks. The vulnerabilities are CVE-2026-42271 in BerriAI LiteLLM, a Command Injection flaw with a CVSS score of 8.7, and CVE-2026-50751 in Check Point Security Gateway, a Critical […]

chanapon

June 10, 2026

WhatsApp Blocks New Pegasus Spyware Campaign and Files Motion in U.S. Court Against Developer

WhatsApp has blocked a new wave of cyberattack activity linked to Pegasus spyware, developed by the Israeli company NSO Group. The company has also filed a motion in a U.S. federal court seeking sanctions against NSO Group for allegedly violating a previous court order that barred it from targeting users of the platform in connection […]

chanapon

June 10, 2026

Instagram Users Urged to Enable 2FA After Vulnerability Found in Account Recovery System

309/69 Tuesday, June 9, 2026 Meta disclosed that 20,225 Instagram accounts were taken over after attackers exploited a vulnerability in its AI-assisted account recovery system, known as High Touch Support (HTS), to request password reset links. The system was designed to help users recover access to their Instagram accounts when they are unable to log […]

chanapon

June 9, 2026

New C0XMO Botnet Malware Targets DD-WRT Router Vulnerability

307/69 Tuesday, June 9, 2026 Cybersecurity researchers from Fortinet have discovered a new botnet malware named C0XMO, which is derived from the Gafgyt botnet. The malware targets router devices running DD-WRT firmware, as well as video recording devices, video management platforms, and devices running the Android operating system. It can operate across various processor architectures, […]

chanapon

June 9, 2026
1 11 12 13 107