Vulnerabilities
VulnCheck: Windmill CVE-2026-29059 Path-Traversal Vulnerability Under Active Exploitation
An open-source dev-platform flaw hits active exploitation — defender verification for Windmill deployments this week.
Master cloud security and identity management. Get technical insights into securing multi-cloud environments, hardening IAM roles, and defending against sophisticated credential-based attacks.
Vulnerabilities
An open-source dev-platform flaw hits active exploitation — defender verification for Windmill deployments this week.
Vulnerabilities
A use-after-free in the Linux kernel's nf_tables code — patched in February, exploited publicly in June — shows how a single misplaced character in a critical subsystem becomes the keystone of a privilege-escalation chain.
Cyber Attacks
Hunt.io found that a threat actor called PCPJack hijacked about 230 AWS, Google Cloud and Azure servers into a covert SMTP relay network — quietly converting business servers into verified mail proxies synced to a downstream consumer every five minutes.
Phishing
Kali365, the phishing-as-a-service kit the FBI flagged in May for stealing Microsoft 365 tokens past MFA, has broadened its targets to AWS, Okta, Xerox DocuShare and Russian services, Arctic Wolf reports — extending its core OAuth device-code phishing to far more of the stack.
Supply Chain Attack
A compromised Red Hat employee GitHub account pushed a new 'Miasma' build of the Mini Shai-Hulud worm into 32 Cloud Services npm packages. Red Hat says the code was internal-only and never reached customers; any pipeline that installed a poisoned version should rotate its secrets.
Mobile Security
A single debug setting left enabled in Microsoft's Android Office apps — Word, Excel, PowerPoint, OneNote, Loop and Microsoft 365 Copilot — let any other app on the same device read Microsoft account tokens, per a SecurityWeek exclusive. Microsoft has patched the flaws.
Artificial Intelligence (AI)
Google Cloud launched AI Threat Defense on May 27, 2026 — an automated platform that pairs Gemini, the Wiz cloud-security stack, and the CodeMender AI code-fixing agent to find, prioritize, and patch software vulnerabilities at machine speed.
Application Security
SentinelLABS disclosed PCPJack on May 7 — a Linux cloud worm that exploits 5 CVEs across Docker, Kubernetes, Redis, MongoDB, and RayML, then evicts rival TeamPCP malware before stealing credentials. The "PCP replaced" telemetry field is the editorial differentiator.
Vulnerabilities
A pro-Ukrainian hacktivist group called PhantomCore has been exploiting three TrueConf video conferencing flaws (BDU-2025-10114, 10115, 10116) since September 2025 to breach Russian networks. By chaining these vulnerabilities, the group bypasses authentication and executes arbitrary OS commands, turning video conferencing servers into springboards for lateral movement and
Vulnerabilities
Microsoft has patched a serious Entra ID (Azure AD) misconfiguration that exposed an “agent-only” role for Microsoft Graph PowerShell that was not properly restricted to Microsoft’s own internal agents. Attackers who obtained secrets for a service-principal-linked app registration could exploit this role to escalate privileges and
Vulnerability Management
A reported Broken Object Level Authorization (BOLA) flaw on the Lovable AI platform allegedly exposed thousands of private coding projects, prompts, and credentials, sparking a debate over "vibe coding" security standards. Stockholm, Sweden — Lovable, the rapidly growing AI "app builder" platform, has found itself at the
M&A (Mergers & Acquisitions)
In the largest acquisition in its history, Alphabet has completed its $32 billion takeover of cloud security leader Wiz, signaling an aggressive pivot toward autonomous, AI-driven defense systems. Mountain View, CA — Google has officially crossed the Rubicon in the cybersecurity arms race. By finalizing the $32 billion acquisition of