CSSLTD CYBER INTEL

Cybersecurity Intelligence Report

17 June 2026 · 65 new unique items · 2 critical signals · 1 DLS victims monitored

KEV

CVEVendor/ProductScoreRequired action
CVE-2026-48907CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability - Widget Factory Joomla Content Editor 6Widget Factory Joomla Content Editor Improper Access Control Vulnerability - Widget Factory Joomla Content Editor . Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with…

DLS Victims

News

SCORE 11HelpNetSecurity

Software supply chains are heading for a transparency test

Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automation,…

SCORE 7HelpNetSecurity

Attackers are exploiting FortiSandbox vulnerabilities

Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The…

CVE-2026-39808, CVE-2026-25089, CVE-2026-39813

SCORE 7HelpNetSecurity

Cybercriminals mask malicious communications through Microsoft Teams relays

The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. DragonForce is a ransomware-as-a-service operation…

SCORE 7TheHackerNews

Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. "A vulnerability in the web UI of Cisco…

CVE-2026-20262

SCORE 7BleepingComputer

CISA warns of another cPanel plugin flaw exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin.

CVE-2026-54420

SCORE 5SecurityWeek

iRhythm Confirms Data Stolen in Hack

The digital health company said it learned of the breach on June 8 and the attackers demanded a ransom. The post iRhythm Confirms Data Stolen in Hack appeared first on SecurityWeek

SCORE 5TheHackerNews

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The…

CVE-2026-54420

SCORE 4SecurityWeek

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR. The post Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages appeared first on SecurityWeek

SCORE 3TheHackerNews

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24…

CVE-2026-39808, CVE-2026-25089, CVE-2026-39813

SCORE 3TheHackerNews

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. "The attack email contained a message impersonating an MS…

SCORE 3SecurityWeek

Cal Water Investigating Iranian Hackers’ Claims

California Water Service says there is no indication of operational disruptions to its water and wastewater systems. The post Cal Water Investigating Iranian Hackers’ Claims appeared first on SecurityWeek

SCORE 2BleepingComputer

UK to require ID or face scan before you can make social media accounts

Opening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security experts warn the age checks are easy to circumvent and create new data-breach…

SCORE 0HelpNetSecurity

TekStream launches Proactive Cyber Defense to counter AI-driven threats

TekStream has announced the launch of TekStream Proactive Cyber Defense, a new expert-operated security service powered by Cosmos, the company’s cyber defense intelligence platform. The launch comes as organizations face a rapidly changing threat landscape shaped by…

SCORE 0SecurityWeek

Cybercrime Group Claims Novo Nordisk Hack

The hack-and-leak group FulcrumSec claims to have stolen 1.3TB of data from the pharmaceutical giant. The post Cybercrime Group Claims Novo Nordisk Hack appeared first on SecurityWeek

SCORE 0SecurityWeek

White House Issues Memo to Bolster NSS Cybersecurity

NSPM-12 establishes a clear structure for NSS cybersecurity governance and accountability and reestablishes CNSS. The post White House Issues Memo to Bolster NSS Cybersecurity appeared first on SecurityWeek

SCORE 0HelpNetSecurity

Crypto scammers are sending couriers to victims’ homes to collect cash

Scammers behind cryptocurrency investment schemes are dispatching couriers to pick up cash from victims in person, the FBI warns. According to the agency, scammers usually approach victims through social media, text messages, or fake investment personas, luring them into…