Citrix Fixes Six Critical NetScaler Vulnerabilities That Could Expose Systems to File Theft and DoS Attacks

Citrix has released security updates to fix six vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances. According to the company, these flaws could allow attackers to read sensitive files without authentication or cause affected systems to stop responding through denial-of-service (DoS) attacks. The vulnerabilities impact several NetScaler deployments depending on how they are configured. Citrix … Continued

Aflac Confirms Data Breach After Hack Hits Japan Insurance Systems

American insurance company Aflac has disclosed a new cybersecurity incident after hackers gained unauthorized access to systems belonging to its Japan subsidiary. According to the company, the breach was discovered on June 25, 2026, following suspicious activity that occurred between June 15 and June 25. The company confirmed that an unauthorized third party accessed certain … Continued

Critical SimpleHelp Flaw Exploited to Deploy TaskWeaver and Djinn Stealer Malware

A newly discovered cyberattack campaign is exploiting a critical security flaw in SimpleHelp remote monitoring and management (RMM) software to install two previously unknown malware families named TaskWeaver and Djinn Stealer. The vulnerability, tracked as CVE-2026-48558, has received the highest possible CVSS score of 10.0 because it allows attackers to gain unauthorized access without valid … Continued

282 AI-Powered iPhone Apps Found Leaking API Keys and Exposing AI Services

A new security study has revealed a major problem affecting AI-powered iPhone applications. Researchers from Wake Forest University found that 282 out of 444 iOS apps using large language model (LLM) features exposed sensitive API credentials or backend access during normal network communication. The issue was discovered after examining hundreds of AI-enabled apps across the … Continued

Mustang Panda Abuses Zoho WorkDrive to Target Indian Government in Stealthy Cyber Espionage Campaign

A cyber espionage campaign linked to the China-aligned hacking group Mustang Panda has been found targeting Indian government organizations. Security researchers discovered that the attackers used Zoho WorkDrive, a trusted cloud storage service, as part of their command-and-control infrastructure. By relying on a legitimate cloud platform instead of suspicious servers, the attackers attempted to make … Continued

Amazon Q Developer Flaw Could Let Malicious Repositories Execute Code Through MCP Configurations

Amazon has fixed a high-severity security vulnerability in Amazon Q Developer that could have allowed attackers to execute malicious code on a developer’s computer through specially crafted repositories. The flaw has been assigned CVE-2026-12957 with a CVSS score of 8.5. Security researchers at Wiz discovered the issue and responsibly reported it to Amazon before the … Continued

New DirtyClone Linux Kernel Flaw Lets Attackers Gain Root Access Through Cloned Packets

Security researchers have uncovered a new Linux kernel vulnerability called DirtyClone, tracked as CVE-2026-43503, that allows a local attacker to gain root privileges on vulnerable systems. The flaw was discovered by JFrog Security Research while reviewing recent Linux kernel patches. Researchers found that although earlier fixes addressed the DirtyFrag vulnerability family, a similar weakness remained … Continued

Newsletter line