| unknown |
CVE-2026-47645 Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-48582 Microsoft Exchange Online Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-48584 Microsoft Azure Synapse Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-54130 M365 Copilot Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-42895 Microsoft Copilot Tampering Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-45480 Azure Active Directory Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-32174 Azure Bot Service Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-32208 Microsoft Edge (Chromium-based) Spoofing Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-47633 Microsoft Cost Management Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| critical |
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic |
news |
general-news |
|
ransomware, botnet |
2026-06-18 |
| high |
Schneider Electric EasyLogic T150 and Saitel DP |
advisory |
cisa-advisories, vendor-blogs |
|
phishing, ics |
2026-06-18 |
| high |
AVer PTC cameras |
advisory |
cisa-advisories, vendor-blogs |
|
phishing, ics |
2026-06-18 |
| high |
Rockwell Automation FactoryTalk Historian Site Edition |
advisory |
cisa-advisories, vendor-blogs |
|
phishing, ics |
2026-06-18 |
| unknown |
CISA Adds One Known Exploited Vulnerability to Catalog |
advisory |
cisa-advisories |
|
|
2026-06-18 |
| high |
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products |
advisory |
cisa-advisories, vendor-blogs |
|
botnet, ics |
2026-06-18 |
| high |
Mitsubishi Electric MELSEC iQ-F Series |
advisory |
cisa-advisories, vendor-blogs |
|
ics |
2026-06-18 |
| high |
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module |
advisory |
cisa-advisories, vendor-blogs |
|
ics |
2026-06-18 |
| high |
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT |
advisory |
cisa-advisories, vendor-blogs |
|
ics |
2026-06-18 |
| critical |
AzeoTech DAQFactory |
advisory |
cisa-advisories, vendor-blogs |
|
zeroday, phishing, ics |
2026-06-18 |
| medium |
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure |
advisory |
cisa-advisories |
|
phishing |
2026-06-18 |
| unknown |
LATAM Infrastructure Hit by Fortinet and Ivanti Exploits |
news |
general-news |
|
|
2026-06-18 |
| unknown |
Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
Hostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC Warns |
news |
general-news |
|
|
2026-06-18 |
| unknown |
CVE-2026-46293 clk: microchip: mpfs-ccc: fix out of bounds access during output registration |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-46291 crypto: caam - guard HMAC key hex dumps in hash_digest_key |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-46274 io-wq: check that the predecessor is hashed in io_wq_remove_pending() |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-28387 Potential Use-after-free in DANE Client Code |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-46292 pmdomain: core: Fix detach procedure for virtual devices in genpd |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-43308 btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2025-71072 shmem: fix recovery on rename failures |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2025-71073 Input: lkkbd - disable pending work before freeing device |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| unknown |
CVE-2026-48854 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc |
advisory |
vendor-blogs |
|
|
2026-06-18 |
| high |
CVE-2026-20253 — Splunk Enterprise Missing Authentication for Critical Function Vulnerability |
vulnerability |
cisa-kev |
CVE-2026-20253 |
|
2026-06-18 |
| critical |
INC Ransomware Thrives by Mastering the Basics |
news |
general-news |
|
ransomware |
2026-06-17 |
| medium |
Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments |
news |
general-news |
|
phishing |
2026-06-17 |
| critical |
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development |
news |
general-news |
|
zeroday |
2026-06-17 |
| high |
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline |
news |
general-news |
|
botnet, infostealer |
2026-06-17 |
| unknown |
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April |
news |
general-news |
|
|
2026-06-17 |
| medium |
Sweeping Credential-Harvesting Heist Compromises 30K+ Fortinet Devices |
news |
general-news |
|
phishing |
2026-06-17 |
| medium |
Serverless Phishing Kit on GitHub Targets Mexican Banks |
news |
general-news |
|
phishing |
2026-06-17 |
| unknown |
CVE-2026-42828 Windows Projected File System Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-17 |
| unknown |
CVE-2026-47636 Microsoft SharePoint Server Spoofing Vulnerability |
advisory |
vendor-blogs |
|
|
2026-06-17 |
| unknown |
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats |
news |
general-news |
|
|
2026-06-17 |
| unknown |
AI Threats and Alert Fatigue Challenge Cybersecurity Teams |
news |
general-news |
|
|
2026-06-17 |
| critical |
The Top 10 Attack Surface Exposures in 2026 |
news |
general-news |
|
zeroday |
2026-06-17 |