
Arista fixes exploited VeloCloud Orchestrator zero-day
Arista released an emergency patch for a maximum-severity vulnerability in VeloCloud Orchestrator that attackers were already exploiting in the wild.

Arista released an emergency patch for a maximum-severity vulnerability in VeloCloud Orchestrator that attackers were already exploiting in the wild.

HSTS-Enforced inverts the current HTTPS opt-in model, making encrypted connections the default while requiring explicit, verifiable exceptions for HTTP. The change aims to eliminate downgrade attacks but must preserve compatibility with legacy systems still reliant on unencrypted transport.

Security researchers discovered a vulnerability in OpenAI's ChatGPT workspace agents that allowed attackers to silently create and control malicious AI agents using a single link. The flaw, patched in June, enabled agents to act with the victim's permissions across connected corporate systems.

Check Point has issued a hotfix for a zero-day vulnerability in its SmartConsole GUI that attackers were already exploiting in the wild.

OVH deployed emergency fixes for the Januscape guest-host escape vulnerability across its infrastructure, rebooting tens of thousands of hosts to protect roughly one million virtual machines after testing the process in Australia.

Cloudflare has activated Web Application Firewall protections for two high-severity WordPress vulnerabilities—an unauthenticated remote code execution flaw and a SQL injection issue—affecting versions 6.8 and later. The rules block attack attempts while sites apply patches released in WordPress 7.0.2 and backported versions.

SonicWall has released emergency fixes for two zero-day vulnerabilities in its SMA1000 secure access gateways after observing active exploitation. No customer impact details have been disclosed.

Cybersecurity agencies from the United States and eight partner countries have released a coordinated advisory detailing Russian state-sponsored attacks on critical infrastructure via vulnerable network routers. The alert provides mitigation guidance for operators.

Progress Software has instructed customers running on-premises ShareFile Storage Zone Controllers to power down servers immediately after identifying a credible security threat.

A critical authentication bypass vulnerability in the official Gitea Docker image is being actively exploited, allowing attackers to gain unauthorized access to self-hosted Git services by impersonating users, including administrators.

Zimbra has released a security update for its Classic Web Client after discovering a critical cross-site scripting vulnerability that could allow attackers to hijack user sessions. The company advises all customers to apply the patch without delay.

A China-linked threat group has exploited a vulnerability in Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware, according to security researchers.

BeyondTrust issued fixes for critical vulnerabilities in its Remote Support and Privileged Remote Access software that allowed authentication bypass, potentially exposing customer sessions to unauthorized access.

A campaign targeting Python developers has been distributing malicious PyPI packages that compromise Telegram bot servers, allowing attackers to read arbitrary files since November 2025.

The World Wide Web Consortium has released a draft policy outlining how security researchers can report suspected vulnerabilities in its standards and specifications, aiming to streamline triage and resolution through formal W3C processes.

Attackers compromised an npm maintainer account to publish malicious updates to over 20 packages in the Leo Platform and RStreams ecosystems, stealing cloud credentials, GitHub tokens, and other secrets while evading two-factor authentication.

CISA has added four critical vulnerabilities in Ubiquiti UniFi OS and Lantronix EDS5000 serial-to-Ethernet servers to its Known Exploited Vulnerabilities catalog, citing active exploitation. Federal agencies must apply patches or mitigations by 27 June 2026.

Security researchers have identified Mistic, a stealthy backdoor malware attributed to the KongTuke initial access broker, which sells network access to ransomware groups. The malware, active since April 2026, enables long-term persistence and in-memory payload execution, evading traditional detection methods.

A server-side request forgery vulnerability (CVE-2026-20230) in Cisco Unified CM and Unified CM SME is under active exploitation, allowing unauthenticated attackers to write files and escalate privileges to root. Cisco released patches on June 3, but reconnaissance activity has since been detected.

Researchers at Qianxin's XLab identified the AryStinger botnet, which exploits known vulnerabilities in D-Link routers to enable distributed scanning, DNS tampering, and traffic monitoring. Nearly half of infections are in South Korea, with significant activity in China and Europe.