Squidbleed — 29-Year-Old Squid Proxy Memory Leak Has Been Exposing Credentials Since 1997
Summary Security researcher Joshua Rogers has disclosed “Squidbleed” (CVE-2026-47729), a memory leak vulnerability in the Squid web proxy that has existed in the codebase since 1997 — making it 29…
AutoJack — Single Malicious Webpage Hijacks AI Browsing Agent for Full Host-Level RCE
Summary Microsoft researchers have disclosed “AutoJack,” an exploit chain that allows a single malicious webpage to hijack an AI browsing agent and achieve full remote code execution on the host…
FortiBleed — Credentials for 73,000+ FortiGate Devices Dumped in Massive VPN Leak Campaign
Summary A large-scale credential compromise campaign dubbed “FortiBleed” has exposed valid VPN and administrator credentials for over 73,000 internet-facing FortiGate firewalls across 194 countries — roughly half of all reachable…
Trump Signs Executive Orders Accelerating Nationwide Migration to Post-Quantum Cryptography
Summary On June 22, 2026, President Trump signed two executive orders aimed at securing the United States against advanced cryptographic threats posed by quantum computing. The orders mandate an accelerated…
Five Eyes Alliance Warns Frontier AI Models Will Transform Offensive Cyber Capabilities Within Months
Summary In a rare joint statement issued June 22–23, the Five Eyes intelligence alliance — the United States, United Kingdom, Canada, Australia, and New Zealand — warned that frontier AI…
Nintendo of America Hit by Data Breach After Hackers Compromise Third-Party Survey Platform
Summary Nintendo of America has confirmed a data breach originating from a cyberattack on TinyPulse, a third-party employee engagement and survey platform owned by WebMD Health Services. A threat actor…
Databricks Acquires Panther to Build the AI-Native Security Lakehouse
Summary Databricks has announced an agreement to acquire Panther, an AI-native Security Operations Center (SOC) platform, marking the company’s third cybersecurity acquisition following SiftD.ai and Antimatter. The deal was announced…
Cisco Acquires WideField Security to Supercharge Splunk’s Agentic SOC With Identity Intelligence
Summary Cisco has announced its intent to acquire WideField Security Inc., a startup specializing in identity lifecycle security, to bolster Splunk’s Agentic Security Operations Center (SOC) capabilities. The deal, expected…
Usbliter8 — Unpatchable BootROM Exploit Hits Millions of iPhones With A12 and A13 Chips
Summary Security researchers at Paradigm Shift have publicly disclosed “usbliter8,” a new unpatchable BootROM exploit affecting Apple’s A12 and A13 chips along with S4 and S5 SoCs. The exploit and…
Check Point VPN Zero-Day Exploited by Qilin Ransomware — CISA Issues Emergency Directive
Summary A critical zero-day authentication bypass vulnerability in Check Point VPN products, tracked as CVE-2026-50751 (CVSS 9.3), is under active exploitation by threat actors linked to the Qilin ransomware operation.…
