Latest Security News

Aggregated from vendors, research teams & government advisories

Updated: 3 June 2026, 10:30 BST
CS

CISA Alerts & Advisories

UK

NCSC (UK)

NV

Notable CVEs (NVD)

SW

SonicWall

FT

Fortinet

ES

ESET / WeLiveSecurity

Webworm: New burrowing techniques

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

welivesecurity.com
ZS

Zscaler / ThreatLabz

HN

The Hacker News

Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation. Tracked as CVE-2025-48595 (CVSS score: 8....

thehackernews.com
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path trav...

thehackernews.com
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability, CVE-2024-21182 (C...

thehackernews.com
How Leading Organizations Are Turning EDR Into Operational Resilience

Most organizations now recognize that endpoint protection alone is no longer sufficient. That's why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional preventio...

thehackernews.com
BC

BleepingComputer

VS Code zero-day lets hackers steal GitHub tokens in one click

A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. [...]

bleepingcomputer.com
Microsoft's Coreutils project brings Linux commands to Windows

Microsoft announced today at its Build 2026 developer conference the release of Coreutils for Windows, bringing many commonly used Linux command-line utilities to Windows as native applications. [...]

bleepingcomputer.com
SW

SecurityWeek

Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis

As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control. The post <a href="https://www.securityweek.com/two-new-reports-offer-competing-explanations-for-cy...

securityweek.com
DR

Dark Reading