CISA Warns of Two-Year-Old Oracle WebLogic Server Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 CISA has issued a fresh warning highlighting active exploitation of a critical Oracle WebLogic Server vulnerability, tracked as CVE-2024-21182, adding it to its Known Exploited Vulnerabilities (KEV) …

Critical KMW CCTV Vulnerability Let Attackers Gain Unauthorized Access to Camera Feeds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical security flaw in KMW CCTV security cameras could allow attackers to gain full, unauthorized access to live camera feeds and device settings. The vulnerability, tracked …

CISA Flags Palo Alto Networks PAN-OS Vulnerability as Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Palo Alto Networks PAN-OS vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the …

Microsoft MSRC Allegedly Dismissed Dependency Confusion Vulnerability, Claims Researcher

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A dependency confusion vulnerability affecting Microsoft’s Azure Portal after the Microsoft Security Response Center (MSRC) closed the case, claiming the confirmed remote code execution evidence did not …

Mustang Panda Deploys PlugX RAT Through Multi-Stage LNK and PowerShell Attack Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A well-known Chinese state-sponsored threat group called Mustang Panda has been caught running a sophisticated cyberattack campaign using its signature remote access tool, PlugX. The group used …

TP-Link Router Vulnerability Allows Attackers to Execute Arbitrary System Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed high-severity vulnerability in TP-Link routers could allow attackers to execute arbitrary system commands and fully compromise affected devices. Tracked as CVE-2026-5509, the flaw affects Archer BE450 v1 …

Claude Code’s GitHub Actions Vulnerability Lets Attackers Compromise Any Repository

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical supply chain vulnerability in Claude Code’s GitHub Actions that could allow attackers to compromise any repository using Anthropic’s official CI/CD workflow, including Anthropic’s own infrastructure. …

Hackers Deploy AZUREVEIL Adaptix C2 Agent via Spearphishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly identified spearphishing campaign has been quietly targeting government officials, researchers, and technology workers in the Czech Republic and Taiwan. Threat researchers traced the operation to …

PHANTOMPULSE RAT Uses Process Injection and UAC Bypass to Compromise Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly analyzed remote access trojan called PHANTOMPULSE has drawn serious attention for its advanced approach to compromising Windows systems. The malware is the final-stage payload in …

Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A state-linked hacking group has been caught running a carefully crafted fake recruitment operation to push custom malware onto unsuspecting victims. The group, known as Nimbus Manticore …