SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies
Austin, TX, USA, 17th June 2026, CyberNewswire
Latest Hacking News is the one-stop destination to find all the latest cyber security news, articles on hacking, network security, and more.
Austin, TX, USA, 17th June 2026, CyberNewswire
London, United Kingdom, 17th June 2026, CyberNewswire
CVE-2026-20253 is a CVSS 9.8 pre-auth flaw in Splunk Enterprise’s PostgreSQL sidecar service. An unauthenticated attacker can write files and chain the primitive to RCE. A public PoC exists; no workaround, patch only.
A three-CVE chain lets any default LiteLLM user escalate to admin and get a shell on the gateway server. A separate RCE is already in CISA’s KEV. Here’s what to check and how to patch.
CVE-2026-0257’s GlobalProtect authentication bypass went from advisory to active exploitation in four days. The recurring pattern of perimeter device failures demands more than a patch cycle.
MIT’s Fractal OS has found the first evidence of Apple M1 Phantom speculation and overturned prior research on the M1’s conditional branch predictor, challenging the assumption that Apple Silicon is safer from speculative execution attacks.
An AUR supply chain attack compromised more than 400 Arch Linux packages from 11 June 2026, planting a Rust credential stealer and an eBPF rootkit that hides from standard inspection tools.
A CVSS 9.3 flaw in Check Point Remote Access VPN let unauthenticated attackers bypass certificate validation by supplying a crafted IKEv1 VendorID payload — exploited for 32 days before a patch, with one confirmed Qilin ransomware post-compromise chain.
Rome, Italy, 15th May 2026, CyberNewswire
Rome, Italy, 13th May 2026, CyberNewswire