Vendors
-
macOS flaw let standard users disable CrowdStrike and Kandji tools, researchers say
Researchers said a macOS flaw let standard user accounts disable major enterprise security tools, including CrowdStrike Falcon Sensor and Kandji, by abusing XPC communication. Vendors have patched the issue or are working on fixes.
-
Cisco Unified CM flaw under active exploitation after public disclosure
Threat actors are exploiting CVE-2026-20230 in Cisco Unified CM and Unified CM SME, a critical flaw that can enable server-side request forgery and file writes. Cisco has patched affected versions, and WebDialer must be enabled for abuse.
-
LastPass says Salesforce customer data exposed in Klue supply chain attack
LastPass said hackers used OAuth tokens stolen in the Klue supply chain attack to reach customer data in its Salesforce environment. The company said vaults were not affected and warned about phishing risk.
-
Salesforce disables Klue app after data theft incident
Salesforce disabled the Klue Battlecards app after a June 11 security incident at Klue that may have exposed customer data through connected accounts. Klue said legacy credentials were used to steal OAuth tokens.
-
Apple patches Beats Studio Buds flaw that could let nearby attackers eavesdrop
Apple has patched a high-severity Beats Studio Buds Bluetooth flaw that could let nearby attackers eavesdrop through the microphone. The advisory says the fix is in Beats Firmware Update 1B211 and requires no user interaction.
-
F5 patches two critical NGINX flaws that could lead to code execution
F5 has patched two critical NGINX Open Source vulnerabilities that could permit remote code execution. The company released fixes, listed affected products and offered mitigations, while saying it has not seen in-the-wild exploitation.
-
CISA flags LiteSpeed cPanel plugin flaw in Known Exploited Vulnerabilities catalog
CISA has added a LiteSpeed cPanel Plugin privilege escalation flaw to its Known Exploited Vulnerabilities catalog and set a June 18 deadline for federal agencies to patch. The issue can let a user with FTP or web shell access gain root on some shared hosting servers.
-
SimpleHelp bug lets attackers create rogue technician accounts
A critical SimpleHelp flaw lets unauthenticated attackers create privileged technician accounts on OIDC-enabled servers. The bug affects version 5.5.15 and older, along with 6.0 pre-release builds, and was fixed on June 9.
-
Malicious WordPress scripts in three popular plugins exposed more than 1.2 million sites
Malicious JavaScript in WordPress plugins PushEngage, OptinMonster and TrustPulse exposed more than 1.2 million sites to possible takeover when a logged-in administrator loaded the script, according to a Sansec technical analysis.
-
Palo Alto says PAN-OS flaw is under active exploitation
Palo Alto Networks said it has seen active exploitation of a PAN-OS authentication bypass flaw, CVE-2026-0257, in limited attacks against GlobalProtect portals. The company published indicators and urged customers to review logs for signs of abuse.







