The vulnerability, tracked as CVE-2026-42271 (CVSS score: 8.7), is a command injection vulnerability that could allow any authenticated user to run arbitrary commands on the
Category Added in a WPeMatico Campaign
One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
The flaw, CVE-2026-23111, sits in the kernel’s nf_tables packet-filtering code and was patched upstream on February 5, 2026. Exodus Intelligence released its full technical walkthrough on June 8, and it is not even
Meta Blocks NSO Group’s New WhatsApp Phishing Attack, Files Contempt Order
In addition, the tech giant said it’s filing a federal court contempt order against the company for violating a permanent injunction that barred it from targeting WhatsApp and its users.
“They tried to trick people into clicking on malicious links to drive them to external websites
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of a logic flow weakness in certificate validation that allows an unauthenticated remote attacker to bypass user
AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload
Attackers can now create convincing emails, fake login pages, and tailored lures in minutes. Every polished message adds another case for Tier 1 to review, another link to inspect, and another alert that cannot be dismissed at a glance.
As the queue grows, a credential theft attempt or malware delivery can easily
The Hardest Fork
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
The activity has been attributed by Volexity to a threat cluster it tracks as VerdantBamboo, which it said overlaps with hacking groups known as Clay Typhoon (Microsoft),
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
“When automatic updates are enabled, new versions are auto-updated two hours after they are published, adding an extra layer of protection
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
The feature is primarily designed for people and organizations that handle sensitive data and require stricter protection guarantees. Lockdown Mode is available to logged-in users across Free, Go, Plus, and Pro, and
