STORIES LAST WEEK
Five Eyes agencies warn frontier AI could speed cyberattacks
Five Eyes agencies warned that frontier AI models could accelerate vulnerability discovery, exploit development and intrusion planning, raising pressure on defenders to shrink exposed services and patch faster. Reuters, June 22, 2026
AutoJack attack lets malicious webpages run code through AI browser agents
Microsoft’s AutoJack research showed a malicious page loaded by an AI browsing agent could cross the localhost boundary and run code on the host, exposing a weak default in agent tooling. The Hacker News, June 19, 2026
Amazon Q Developer patches workspace command execution flaws
AWS patched flaws in Language Servers for AWS that could let a trusted malicious workspace execute project commands through Amazon Q Developer plugins across major IDEs. Amazon Web Services, June 23, 2026
FortiBleed leak exposes credentials for 73,932 FortiGate systems
Insikt Group said a FortiBleed dataset exposed valid administrative and VPN credentials for 73,932 FortiGate systems, forcing edge-device credential rotation and exposure checks. Recorded Future, June 19, 2026
Cisco SD-WAN zero-day gave attackers root on service provider infrastructure
Mandiant said attackers used CVE-2026-20245 to turn compromised Cisco Catalyst SD-WAN administrator access into root on service provider infrastructure. Google Cloud, June 24, 2026
CISA orders Splunk Enterprise patching after exploited flaw
CISA ordered agencies to patch exploited Splunk Enterprise CVE-2026-20253 after proof-of-concept code showed unauthenticated file operations could be chained toward remote code execution. BleepingComputer, June 19, 2026
Attackers exploit PTC Windchill flaw to deploy web shells
Attackers exploited PTC Windchill CVE-2026-12569, an input validation flaw that can allow remote code execution through malicious network requests and web shell deployment. The Hacker News, June 26, 2026
Lantronix serial-to-IP flaw exploited after OT warning
A Lantronix EDS5000 command injection flaw was exploited after BRIDGE:BREAK disclosures, raising risk for serial-to-IP converters that bridge legacy industrial equipment into IP networks. SecurityWeek, June 25, 2026
Klue breach exposes Salesforce data through SaaS integration tokens
Klue’s Salesforce integration breach exposed customer data for multiple enterprise customers, showing how stolen OAuth tokens in SaaS connectors can bypass otherwise separate CRM environments. Cybersecurity Dive, June 23, 2026
FCC tightens security rules for undersea cable systems
The FCC voted to expand oversight of undersea cable systems and submarine line terminal equipment, adding supply chain restrictions to infrastructure that carries nearly all internet traffic. The Record, June 26, 2026
Tata Electronics confirms cyberattack after supplier documents appear online
Tata Electronics confirmed a cyber incident after alleged Apple supplier specifications and Tesla manufacturing documents appeared online, underscoring third-party exposure in high-tech manufacturing supply chains. The Record, June 23, 2026
NIST releases draft IoT cybersecurity rules for federal networks
NIST released draft SP 800-213 Rev. 1 to help federal agencies define cybersecurity requirements for IoT products before connecting them to government networks. NIST, June 24, 2026
Linux Foundation launches shared response program for critical open source flaws
The Linux Foundation launched Akrites as a shared security incident response and coordinated disclosure program for critical open source software, backed by major cloud, finance, and security companies. Linux Foundation, June 26, 2026
CI/CD flaws expose millions of repositories to supply chain takeover
Novee found exploitable GitHub Actions patterns that let unauthenticated attackers hijack workflows, push code, forge approvals, and steal credentials, turning generated CI/CD files into a supply chain control point. SecurityWeek, June 24, 2026
More cybersecurity news
- Last week’s news roundup
- More cybersecurity news
- All articles sponsored by NetworkTigers
