Vendors
-
Palo Alto says PAN-OS flaw is under active exploitation
Palo Alto Networks said it has seen active exploitation of a PAN-OS authentication bypass flaw, CVE-2026-0257, in limited attacks against GlobalProtect portals. The company published indicators and urged customers to review logs for signs of abuse.
-
GitHub to disable npm install scripts by default in version 12
GitHub said npm version 12 will disable install scripts by default next month to curb supply chain abuse. The change will also restrict Git and remote dependencies unless users explicitly allow them.
-
Google patches Chrome zero-day CVE-2026-11645 after active exploitation
Google has patched 74 Chrome flaws, including CVE-2026-11645, a high-severity zero-day in the V8 engine that the company said was being exploited in the wild. Users are urged to update Chrome and other Chromium-based browsers.
-
Veeam patches critical backup software flaw that could allow remote code execution
Veeam patched a critical flaw in Backup & Replication that could allow remote code execution on a backup server. The bug affects some 12.x releases and was fixed in version 12.3.2.4854.
-
CISA flags LiteLLM flaw as exploited in the wild
CISA said a high-severity LiteLLM command injection flaw is being actively exploited. The bug can let authenticated users run commands on the host, and researchers warned it may be chained with a Starlette issue for unauthenticated access.
-
VS Code adds 2 hour delay for extension auto updates
Microsoft has added a two hour delay before Visual Studio Code auto updates most extensions, a move aimed at limiting supply chain risk. Trusted publishers are exempt, and users can still update manually.
-
Oxford University says CareerConnect breach exposed user names, emails and passwords
Oxford University said a breach of its third-party CareerConnect platform exposed user names, email addresses and encrypted passwords on May 28. The university said its own systems were not compromised and warned of possible phishing attempts.
-
China-nexus group used BSD variant of BRICKSTORM in long-running intrusion, Volexity says
A China-nexus group used a BSD variant of BRICKSTORM, PLENET and AGENTPSD in a long-running intrusion against Linux systems, according to a Volexity technical analysis that traced activity through a victim, an MSP and a NAS device.
-
Hackers exploit critical Everest Forms Pro flaw to seize WordPress sites
Hackers are exploiting a critical flaw in Everest Forms Pro to take over WordPress sites. Wordfence said more than 29,300 attack attempts were blocked after the March patch, and some attacks created rogue administrator accounts.







