Red-Team AI Tool Vulnerabilities Let Attackers Exfiltrate API Keys and Compromise Operators’ Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A first-of-its-kind security analysis of 12 widely deployed agentic offensive-security tools reveals critical architectural flaws that allow adversaries to steal LLM API keys, establish persistent footholds, and …

Hackers Exploit Unpatched SharePoint Servers to Deploy Ransomware and Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Unpatched on-premises SharePoint servers have become a prime target for sophisticated threat actors using known security flaws to break in, plant ransomware, and leave behind hidden backdoors. …

Malicious AI Agent Skill Bypasses Security Scans and Seized Full Control of Over 26,000 Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A malicious AI “skill” created as part of a controlled security experiment has exposed critical weaknesses in modern AI agent ecosystems, successfully bypassing security scanners and compromising …

FortiBleed Attack Hit 430,000+ FortiGate Firewalls, Stealing 110M+ Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A large-scale, ongoing credential-harvesting campaign dubbed “FortiBleed” has silently compromised more than 430,000 FortiGate firewalls globally, siphoning over 110 million credentials directly from live network traffic since …

Critical Cisco Unified CM and SME Flaw Enables Remote Attacker to Launch SSRF Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Cisco has warned customers about a critical server-side request forgery (SSRF) flaw in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM …

CISA Warns of Ubiquiti UniFi OS Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added multiple Ubiquiti UniFi OS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning that at least one of the flaws …

Hackers Use GoogleErrorReport Scheduled Task for Persistence in Dropping Elephant Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 23, 2026 A well-known threat actor called Dropping Elephant has returned with a refined and more dangerous campaign, using a China-themed lure document to drop a reworked remote access …