News
-
Microsoft removes 73 GitHub repositories during malware investigation
Microsoft removed 73 GitHub repositories on June 5 while investigating potential malicious content, briefly disrupting developer pipelines tied to Azure Functions. Researchers linked the incident to a broader Miasma and Shai-Hulud supply-chain campaign.
-
Veeam patches critical backup software flaw that could allow remote code execution
Veeam patched a critical flaw in Backup & Replication that could allow remote code execution on a backup server. The bug affects some 12.x releases and was fixed in version 12.3.2.4854.
-
CISA flags LiteLLM flaw as exploited in the wild
CISA said a high-severity LiteLLM command injection flaw is being actively exploited. The bug can let authenticated users run commands on the host, and researchers warned it may be chained with a Starlette issue for unauthenticated access.
-
VS Code adds 2 hour delay for extension auto updates
Microsoft has added a two hour delay before Visual Studio Code auto updates most extensions, a move aimed at limiting supply chain risk. Trusted publishers are exempt, and users can still update manually.
-
Check Point warns of active exploitation of critical VPN flaw in IKEv1 setups
Check Point said attackers are exploiting a critical VPN flaw in older IKEv1 deployments, with activity dating back to May 7 and affecting a few dozen organizations globally. The bug can let an unauthenticated attacker bypass password checks and open a VPN session.
-
Oxford University says CareerConnect breach exposed user names, emails and passwords
Oxford University said a breach of its third-party CareerConnect platform exposed user names, email addresses and encrypted passwords on May 28. The university said its own systems were not compromised and warned of possible phishing attempts.
-
Hackers exploit critical Everest Forms Pro flaw to seize WordPress sites
Hackers are exploiting a critical flaw in Everest Forms Pro to take over WordPress sites. Wordfence said more than 29,300 attack attempts were blocked after the March patch, and some attacks created rogue administrator accounts.





