<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Yazoul Security - Cyber News</title><description>Multi-source correlated cybersecurity intelligence. Fast, high-signal threat reporting updated hourly.</description><link>https://www.yazoul.net/news/</link><language>en-us</language><copyright>Copyright 2026 Yazoul Security - https://www.yazoul.net/news</copyright><managingEditor>contact@yazoul.net (Yazoul Security)</managingEditor><webMaster>contact@yazoul.net (Yazoul Security)</webMaster><image><url>https://www.yazoul.net/news/icon-128.png</url><title>Yazoul Security - Cyber News</title><link>https://www.yazoul.net/news</link></image><atom:link href="https://www.yazoul.net/news/rss.xml" rel="self" type="application/rss+xml" xmlns:atom="http://www.w3.org/2005/Atom"/><item><title>Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts</title><link>https://www.yazoul.net/news/article/progress-kemp-loadmaster-flaw-hits-cisa-kev-after-792-reported-exploit-attempts/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/progress-kemp-loadmaster-flaw-hits-cisa-kev-after-792-reported-exploit-attempts/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catal&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/progress-kemp-loadmaster-flaw-hits-cisa-kev-after-792-reported-exploit-attempts/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild</title><link>https://www.yazoul.net/news/article/cisa-flags-teamcity-cve-2026-63077-rce-flaw-under-active-exploitation-in-the-wil/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-flags-teamcity-cve-2026-63077-rce-flaw-under-active-exploitation-in-the-wil/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-flags-teamcity-cve-2026-63077-rce-flaw-under-active-exploitation-in-the-wil/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited</title><link>https://www.yazoul.net/news/article/cisa-flags-langflow-rce-tomcat-and-n-central-flaws-as-actively-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-flags-langflow-rce-tomcat-and-n-central-flaws-as-actively-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in t&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-flags-langflow-rce-tomcat-and-n-central-flaws-as-actively-exploited/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises</title><link>https://www.yazoul.net/news/article/cisa-adds-exploited-n-able-n-central-flaw-to-kev-after-customer-compromises/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-adds-exploited-n-able-n-central-flaw-to-kev-after-customer-compromises/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-adds-exploited-n-able-n-central-flaw-to-kev-after-customer-compromises/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data</title><link>https://www.yazoul.net/news/article/cisco-fmc-zero-day-actively-exploited-static-credentials-could-expose-sensitive-/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisco-fmc-zero-day-actively-exploited-static-credentials-could-expose-sensitive-/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorize&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisco-fmc-zero-day-actively-exploited-static-credentials-could-expose-sensitive-/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw</title><link>https://www.yazoul.net/news/article/attackers-exploit-arista-velocloud-orchestrator-command-injection-flaw/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/attackers-exploit-arista-velocloud-orchestrator-command-injection-flaw/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/attackers-exploit-arista-velocloud-orchestrator-command-injection-flaw/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access</title><link>https://www.yazoul.net/news/article/check-point-patches-exploited-smartconsole-flaw-allowing-full-admin-access/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/check-point-patches-exploited-smartconsole-flaw-allowing-full-admin-access/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company&apos;s SmartConsole graphical user interface (GUI) admin panel. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/check-point-patches-exploited-smartconsole-flaw-allowing-full-admin-access/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Critical wp2shell WordPress flaws exploited to install webshells</title><link>https://www.yazoul.net/news/article/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Hackers are exploiting the &apos;wp2shell&apos; critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands</title><link>https://www.yazoul.net/news/article/two-sonicwall-sma-1000-zero-days-exploited-one-could-enable-admin-commands/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/two-sonicwall-sma-1000-zero-days-exploited-one-could-enable-admin-commands/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/two-sonicwall-sma-1000-zero-days-exploited-one-could-enable-admin-commands/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days</title><link>https://www.yazoul.net/news/article/icagenda-and-balbooa-forms-joomla-flaws-reportedly-exploited-as-zero-days/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/icagenda-and-balbooa-forms-joomla-flaws-reportedly-exploited-as-zero-days/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabiliti&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/icagenda-and-balbooa-forms-joomla-flaws-reportedly-exploited-as-zero-days/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-07-06 to 2026-07-12</title><link>https://www.yazoul.net/news/article/2026-w28-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w28-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-07-06 to 2026-07-12. 4 CVE advisories, 1 breach reports, 2 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w28-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV</title><link>https://www.yazoul.net/news/article/cisa-adds-4-actively-exploited-adobe-joomla-and-langflow-flaws-to-kev/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-adds-4-actively-exploited-adobe-joomla-and-langflow-flaws-to-kev/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-adds-4-actively-exploited-adobe-joomla-and-langflow-flaws-to-kev/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities</title><link>https://www.yazoul.net/news/article/suspected-china-aligned-hackers-exploit-roundcube-flaws-against-universities/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/suspected-china-aligned-hackers-exploit-roundcube-flaws-against-universities/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/suspected-china-aligned-hackers-exploit-roundcube-flaws-against-universities/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-06-29 to 2026-07-05</title><link>https://www.yazoul.net/news/article/2026-w27-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w27-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-06-29 to 2026-07-05. 1 CVE advisories, 1 breach reports, 3 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w27-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials</title><link>https://www.yazoul.net/news/article/ransomware-groups-turn-to-citrix-bleed-2-byovd-and-supply-chain-credentials/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/ransomware-groups-turn-to-citrix-bleed-2-byovd-and-supply-chain-credentials/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. &apos;Although tactics differ between &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/ransomware-groups-turn-to-citrix-bleed-2-byovd-and-supply-chain-credentials/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation</title><link>https://www.yazoul.net/news/article/sharepoint-rce-cve-2026-45659-added-to-cisa-kev-after-active-exploitation/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/sharepoint-rce-cve-2026-45659-added-to-cisa-kev-after-active-exploitation/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/sharepoint-rce-cve-2026-45659-added-to-cisa-kev-after-active-exploitation/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer</title><link>https://www.yazoul.net/news/article/attackers-exploit-simplehelp-cve-2026-48558-to-deploy-taskweaver-and-djinn-steal/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/attackers-exploit-simplehelp-cve-2026-48558-to-deploy-taskweaver-and-djinn-steal/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Steal&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/attackers-exploit-simplehelp-cve-2026-48558-to-deploy-taskweaver-and-djinn-steal/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-06-22 to 2026-06-28</title><link>https://www.yazoul.net/news/article/2026-w26-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w26-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;HIGH&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-06-22 to 2026-06-28. 0 CVE advisories, 3 breach reports, 2 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w26-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited</title><link>https://www.yazoul.net/news/article/cisa-warns-critical-lantronix-eds5000-flaw-is-being-actively-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-warns-critical-lantronix-eds5000-flaw-is-being-actively-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilia&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-warns-critical-lantronix-eds5000-flaw-is-being-actively-exploited/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)</title><link>https://www.yazoul.net/news/article/cve-2024-40766-the-patch-fixed-the-bug-nobody-fixed-the-configuration-tue-jun-23/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cve-2024-40766-the-patch-fixed-the-bug-nobody-fixed-the-configuration-tue-jun-23/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The vulnerability &amp;#xd;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cve-2024-40766-the-patch-fixed-the-bug-nobody-fixed-the-configuration-tue-jun-23/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-06-15 to 2026-06-21</title><link>https://www.yazoul.net/news/article/2026-w25-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w25-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;HIGH&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-06-15 to 2026-06-21. 1 CVE advisories, 5 breach reports, 3 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w25-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution</title><link>https://www.yazoul.net/news/article/cisa-warns-of-actively-exploited-joomla-jce-flaw-allowing-php-code-execution/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-warns-of-actively-exploited-joomla-jce-flaw-allowing-php-code-execution/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabi&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-warns-of-actively-exploited-joomla-jce-flaw-allowing-php-code-execution/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation</title><link>https://www.yazoul.net/news/article/cisa-flags-litespeed-cpanel-plugin-flaw-exploited-for-root-privilege-escalation/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-flags-litespeed-cpanel-plugin-flaw-exploited-for-root-privilege-escalation/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in t&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-flags-litespeed-cpanel-plugin-flaw-exploited-for-root-privilege-escalation/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw</title><link>https://www.yazoul.net/news/article/cisco-releases-security-updates-for-actively-exploited-sd-wan-manager-flaw/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisco-releases-security-updates-for-actively-exploited-sd-wan-manager-flaw/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisco-releases-security-updates-for-actively-exploited-sd-wan-manager-flaw/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-06-08 to 2026-06-14</title><link>https://www.yazoul.net/news/article/2026-w24-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w24-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-06-08 to 2026-06-14. 4 CVE advisories, 3 breach reports, 5 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w24-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation</title><link>https://www.yazoul.net/news/article/cisa-adds-cisco-chrome-and-arista-flaws-to-kev-catalog-amid-active-exploitation/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-adds-cisco-chrome-and-arista-flaws-to-kev-catalog-amid-active-exploitation/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitati&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-adds-cisco-chrome-and-arista-flaws-to-kev-catalog-amid-active-exploitation/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities</title><link>https://www.yazoul.net/news/article/cisa-issues-new-directive-improving-how-federal-agencies-prioritize-the-mitigati/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-issues-new-directive-improving-how-federal-agencies-prioritize-the-mitigati/</guid><description>&lt;p&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-issues-new-directive-improving-how-federal-agencies-prioritize-the-mitigati/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>medium</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now</title><link>https://www.yazoul.net/news/article/chrome-v8-zero-day-cve-2026-11645-exploited-in-the-wild-patch-now/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/chrome-v8-zero-day-cve-2026-11645-exploited-in-the-wild-patch-now/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/chrome-v8-zero-day-cve-2026-11645-exploited-in-the-wild-patch-now/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Announces Winners of the 2026 President’s Cup Cybersecurity Competition</title><link>https://www.yazoul.net/news/article/cisa-announces-winners-of-the-2026-president-s-cup-cybersecurity-competition/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-announces-winners-of-the-2026-president-s-cup-cybersecurity-competition/</guid><description>&lt;p&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-announces-winners-of-the-2026-president-s-cup-cybersecurity-competition/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>medium</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE</title><link>https://www.yazoul.net/news/article/litellm-flaw-cve-2026-42271-exploited-in-the-wild-chains-to-unauthenticated-rce/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/litellm-flaw-cve-2026-42271-exploited-in-the-wild-chains-to-unauthenticated-rce/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/litellm-flaw-cve-2026-42271-exploited-in-the-wild-chains-to-unauthenticated-rce/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups</title><link>https://www.yazoul.net/news/article/critical-check-point-vpn-flaw-exploited-to-bypass-passwords-in-ikev1-setups/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/critical-check-point-vpn-flaw-exploited-to-bypass-passwords-in-ikev1-setups/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protoco&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/critical-check-point-vpn-flaw-exploited-to-bypass-passwords-in-ikev1-setups/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-06-01 to 2026-06-07</title><link>https://www.yazoul.net/news/article/2026-w23-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w23-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;HIGH&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-06-01 to 2026-06-07. 2 CVE advisories, 4 breach reports, 4 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w23-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog</title><link>https://www.yazoul.net/news/article/cisa-adds-actively-exploited-solarwinds-serv-u-dos-flaw-to-kev-catalog/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-adds-actively-exploited-solarwinds-serv-u-dos-flaw-to-kev-catalog/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;CISA warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-adds-actively-exploited-solarwinds-serv-u-dos-flaw-to-kev-catalog/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog</title><link>https://www.yazoul.net/news/article/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Urges Stronger Security for Automatic Tank Gauge Systems</title><link>https://www.yazoul.net/news/article/cisa-urges-stronger-security-for-automatic-tank-gauge-systems/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-urges-stronger-security-for-automatic-tank-gauge-systems/</guid><description>&lt;p&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-urges-stronger-security-for-automatic-tank-gauge-systems/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>medium</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation</title><link>https://www.yazoul.net/news/article/oracle-weblogic-cve-2024-21182-added-to-kev-catalog-after-active-exploitation/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/oracle-weblogic-cve-2024-21182-added-to-kev-catalog-after-active-exploitation/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, ba&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/oracle-weblogic-cve-2024-21182-added-to-kev-catalog-after-active-exploitation/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-05-25 to 2026-05-31</title><link>https://www.yazoul.net/news/article/2026-w22-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w22-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-05-25 to 2026-05-31. 2 CVE advisories, 5 breach reports, 4 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w22-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation</title><link>https://www.yazoul.net/news/article/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitati/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitati/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as C&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitati/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit</title><link>https://www.yazoul.net/news/article/attackers-use-llm-agent-for-post-exploitation-after-marimo-cve-2026-39987-exploi/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/attackers-use-llm-agent-for-post-exploitation-after-marimo-cve-2026-39987-exploi/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/attackers-use-llm-agent-for-post-exploitation-after-marimo-cve-2026-39987-exploi/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer</title><link>https://www.yazoul.net/news/article/threat-actors-exploit-critical-forticlient-ems-flaw-to-deploy-credential-stealer/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/threat-actors-exploit-critical-forticlient-ems-flaw-to-deploy-credential-stealer/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/threat-actors-exploit-critical-forticlient-ems-flaw-to-deploy-credential-stealer/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Announces Revised Town Hall Schedule to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure</title><link>https://www.yazoul.net/news/article/cisa-announces-revised-town-hall-schedule-to-engage-with-stakeholders-on-cyber-i/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-announces-revised-town-hall-schedule-to-engage-with-stakeholders-on-cyber-i/</guid><description>&lt;p&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-announces-revised-town-hall-schedule-to-engage-with-stakeholders-on-cyber-i/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>medium</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-05-18 to 2026-05-24</title><link>https://www.yazoul.net/news/article/2026-w21-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w21-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;HIGH&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-05-18 to 2026-05-24. 4 CVE advisories, 5 breach reports, 3 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w21-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate><category>high</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV</title><link>https://www.yazoul.net/news/article/cisa-adds-exploited-langflow-and-trend-micro-apex-one-vulnerabilities-to-kev/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-adds-exploited-langflow-and-trend-micro-apex-one-vulnerabilities-to-kev/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-adds-exploited-langflow-and-trend-micro-apex-one-vulnerabilities-to-kev/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV</title><link>https://www.yazoul.net/news/article/drupal-core-sql-injection-bug-actively-exploited-added-to-cisa-kev/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/drupal-core-sql-injection-bug-actively-exploited-added-to-cisa-kev/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Drupal is warning that hackers are attempting to exploit a &apos;highly critical&apos; SQL injection vulnerability announced earlier this week. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/drupal-core-sql-injection-bug-actively-exploited-added-to-cisa-kev/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form</title><link>https://www.yazoul.net/news/article/cisa-enhances-known-exploited-vulnerabilities-catalog-to-include-new-nomination-/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisa-enhances-known-exploited-vulnerabilities-catalog-to-include-new-nomination-/</guid><description>&lt;p&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 1 correlated source&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisa-enhances-known-exploited-vulnerabilities-catalog-to-include-new-nomination-/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><category>medium</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-05-11 to 2026-05-17</title><link>https://www.yazoul.net/news/article/2026-w20-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w20-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-05-11 to 2026-05-17. 3 CVE advisories, 3 breach reports, 1 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w20-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access</title><link>https://www.yazoul.net/news/article/cisco-catalyst-sd-wan-controller-auth-bypass-actively-exploited-to-gain-admin-ac/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/cisco-catalyst-sd-wan-controller-auth-bypass-actively-exploited-to-gain-admin-ac/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrat&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 3 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/cisco-catalyst-sd-wan-controller-auth-bypass-actively-exploited-to-gain-admin-ac/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Weekly Threat Roundup: 2026-05-04 to 2026-05-10</title><link>https://www.yazoul.net/news/article/2026-w19-weekly-threat-roundup/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/2026-w19-weekly-threat-roundup/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - roundup&lt;/p&gt;
&lt;p&gt;Cybersecurity roundup for 2026-05-04 to 2026-05-10. 10 CVE advisories, 5 breach reports, 4 threat news stories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 0 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/2026-w19-weekly-threat-roundup/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>roundup</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access</title><link>https://www.yazoul.net/news/article/ivanti-epmm-cve-2026-6973-rce-under-active-exploitation-grants-admin-level-acces/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/ivanti-epmm-cve-2026-6973-rce-under-active-exploitation-grants-admin-level-acces/</guid><description>&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Ivanti warned customers today to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) exploited in zero-day attacks. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/ivanti-epmm-cve-2026-6973-rce-under-active-exploitation-grants-admin-level-acces/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution</title><link>https://www.yazoul.net/news/article/palo-alto-pan-os-flaw-under-active-exploitation-enables-remote-code-execution/</link><guid isPermaLink="true">https://www.yazoul.net/news/article/palo-alto-pan-os-flaw-under-active-exploitation-enables-remote-code-execution/</guid><description>&lt;p&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; - vulnerability&lt;/p&gt;
&lt;p&gt;Palo Alto Networks warned customers today that a critical-severity unpatched vulnerability in the PAN-OS User-ID Authentication Portal is being exploited in attacks. [...]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt; 2 correlated sources&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/news/article/palo-alto-pan-os-flaw-under-active-exploitation-enables-remote-code-execution/&quot;&gt;Read the full article on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;Published by &lt;a href=&quot;https://www.yazoul.net/news&quot;&gt;Yazoul Security - Cyber News&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>medium</category><category>vulnerability</category><category>Security</category><category>CyberNews</category><author>Yazoul Security (contact@yazoul.net)</author></item></channel></rss>