Threat Intelligence

2026-06-22 00:00

Microsoft says Windows 11 26H2 is coming soon, details upgrade process

Microsoft says Windows 11 26H2 is coming soon, details upgrade process

Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablement package. The...

Read Article

2026-06-22 00:00

Microsoft fixes AutoGen Studio flaw that enabled code execution

Microsoft fixes AutoGen Studio flaw that enabled code execution

A vulnerability chain dubbed AutoJack in Microsoft’s AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system...

Read Article

2026-06-22 00:00

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins fromShapedPluginwere compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code....

Read Article

2026-06-22 00:00

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the...

Read Article

2026-06-22 00:00

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Cybersecurity researchers have disclosed details of four vulnerabilities inDify, an open-source agentic workflow platform with more than146,000 GitHub stars, that could allow attackers to stealthily...

Read Article

2026-06-22 00:00

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbedOXLOADER. According to Elastic Security Labs,...

Read Article