CISA Warns of Actively Exploited Joomla JCE Flaw — CVE-2026-48907 Scores Perfect CVSS 10.0
Summary CISA has added a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) extension to its Known Exploited Vulnerabilities catalog, citing active exploitation in the wild. CVE-2026-48907, which…
Equixly Brings Continuous Penetration Testing to AI Coding Assistants via MCP Integration
Summary Equixly, an AI-powered offensive security platform, has launched a Model Context Protocol (MCP) integration that embeds continuous penetration testing capabilities directly into AI coding assistants like GitHub Copilot and…
CISA Adds Cisco Catalyst SD-WAN and LiteSpeed cPanel Plugin Flaws to KEV Catalog
Summary On June 16, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch within…
Critical Veeam Backup & Replication RCE Puts Enterprise Backup Infrastructure at Risk
Summary A critical remote code execution vulnerability in Veeam Backup & Replication (VBR), tracked as CVE-2026-44963 (CVSS v4 9.4), allows authenticated domain users to execute arbitrary code on backup servers.…
cPanel/WHM Authentication Bypass Leads to Mass Exploitation — Over 40,000 Servers Compromised
Summary A critical authentication bypass vulnerability in cPanel and WebHost Manager (WHM), tracked as CVE-2026-41940 (CVSS 9.8), has been aggressively exploited in the wild, with confirmed compromises of over 40,000…
ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach 100+ Universities
Summary ShinyHunters — the prolific data-theft and extortion group tracked by Mandiant as UNC6240 — has exploited a critical zero-day vulnerability in Oracle PeopleSoft to breach more than 100 organizations,…
MS-ISAC Hemorrhages 70% of Members After Federal Funding Cut — Thousands of Jurisdictions Left Exposed
Summary The Multi-State Information Sharing and Analysis Center (MS-ISAC), a cornerstone of US state and local government cybersecurity defense, has lost roughly 70% of its membership after the Department of…
Palo Alto GlobalProtect VPN Auth Bypass Under Active Exploitation — CVE-2026-0257 Upgraded to Critical
Summary Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect VPN. The flaw lets unauthenticated attackers forge authentication override cookies to establish unauthorized…
Miasma Supply Chain Worm Compromises 73 Microsoft GitHub Repos and Expands to PyPI in Aggressive Campaign
Summary The Miasma supply chain worm — an evolved variant of the Mini Shai-Hulud worm family — has dramatically expanded its reach beyond the initial Red Hat NPM compromise. On…
Check Point VPN Zero-Day Exploited by Qilin Ransomware Since May — CVE-2026-50751 Hits CVSS 9.3
Summary A critical authentication bypass vulnerability in Check Point’s Remote Access VPN and Mobile Access products, tracked as CVE-2026-50751 (CVSS 9.3), has been actively exploited in the wild since at…
