5 Critical Zero-Days Breaking Right Now: June 2026 Threat Intelligence Report

A real-time analysis of five critical cybersecurity threats active in June 2026: the RoguePlanet Windows Defender zero-day, actively exploited Cisco SD-WAN vManage, Oracle PeopleSoft RCE data theft, Exchange Server XSS, and the WhatsApp VBScript-to-RMM campaign.

Continue Reading5 Critical Zero-Days Breaking Right Now: June 2026 Threat Intelligence Report

VS Code GitHub Token Theft, Cisco’s 7th Zero-Day, and the Rise of AI Agent Security — Threat Intel Weekly

This week: VS Code one-click GitHub token theft, Cisco's 7th SD-WAN zero-day (CVE-2026-20245), Kirki and Burst Statistics WordPress plugins under active attack, and 100 AI agents tested for security.

Continue ReadingVS Code GitHub Token Theft, Cisco’s 7th Zero-Day, and the Rise of AI Agent Security — Threat Intel Weekly

Weekly Threat Intel: FIFA World Cup Scams, Cloud Hijacking, and AI Agent Attacks — June 2026

This week: FIFA World Cup 2026 phishing campaigns, PCPJack cloud server hijacking, Claude Code GitHub Action repo takeover, Cisco SD-WAN zero-day CVE-2026-20245, and the rise of agentic AI in cybersecurity defense.

Continue ReadingWeekly Threat Intel: FIFA World Cup Scams, Cloud Hijacking, and AI Agent Attacks — June 2026

CISA KEV June 2026: Android Framework RCE, Palo Alto VPN Bypass, and Oracle WebLogic Under Active Exploitation

CISA added five vulnerabilities to its Known Exploited Vulnerabilities Catalog in June 2026 — Android Framework RCE, Linux kernel privesc, Oracle WebLogic access, PAN-OS VPN bypass, and trojanized Daemon Tools builds. Here is what defenders need to know and do.

Continue ReadingCISA KEV June 2026: Android Framework RCE, Palo Alto VPN Bypass, and Oracle WebLogic Under Active Exploitation

Weekly Cyber Threat Intelligence: npm 2FA, LiteSpeed CVE, Drupal SQL Injection, and Ransomware VPN Takedowns

This week: npm 2FA-gated publishing, LiteSpeed CVE-2026-48172 exploited for root on shared hosting, Drupal SQLi added to CISA KEV, 8 Packagist packages shipping Linux malware, a CVSS 10.0 Cisco flaw, and the first VPN takedown over ransomware facilitation.

Continue ReadingWeekly Cyber Threat Intelligence: npm 2FA, LiteSpeed CVE, Drupal SQL Injection, and Ransomware VPN Takedowns

The State of Cybersecurity in May 2026: AI-Powered Attacks, Critical 0-Days, and What Defenders Must Know

May 2026 is defined by AI-powered attacks (Claude workspace npm stealers, Grandoreiro phishing), an exploited 0-day flood (NGINX CVE-2026-42945, Defender, DirtyDecrypt), the GitHub breach and Megalodon CI/CD poisoning, and OAuth consent phishing that sidesteps MFA. Defense strategies inside.

Continue ReadingThe State of Cybersecurity in May 2026: AI-Powered Attacks, Critical 0-Days, and What Defenders Must Know

April 2026 Cyber Threat Landscape: Zero-Days, Ransomware, and What Changed

April 2026 was one of the most volatile months in cybersecurity history: Microsoft's 167-flaw Patch Tuesday, exploited SharePoint and IKE zero-days, ransomware at Rockstar and McGraw-Hill, and two CISA emergency directives — everything defenders need to know.

Continue ReadingApril 2026 Cyber Threat Landscape: Zero-Days, Ransomware, and What Changed