[16] BlueHammer Vulnerability Exploited in Ransomware Attacks (SecurityWeek) — CVE-2026-33825
The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released.
The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek.
[14] Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) (HelpNetSecurity) — CVE-2026-46817
Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploitation attempts (Source: Defused) “On 27 June 2026 our Oracle E-Business Suite decoys recorded the first in-the-wild exploitation of CVE-2026-46817 — roughly six weeks after Oracle’s May 2026 patch and before any
[13] CISA: Windows BlueHammer flaw now exploited by ransomware gangs (BleepingComputer)
CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. [...]
[13] Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints (TheHackerNews) — CVE-2026-33017
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner.
The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI)
[10] Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild (TheHackerNews) — CVE-2026-46817
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.
The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to take over susceptible instances.
"Easily exploitable vulnerability allows
No CISA KEV items in the last 14 days.
Unknown: [RANSOMWARE] blacknevas leaked Arkin Group, [RANSOMWARE] pear leaked Sociedad Latina, [RANSOMWARE] aurora leaked Primed Halberstadt Medizintechnik, [RANSOMWARE] play leaked Western Construction, [RANSOMWARE] chaos leaked universalplant.com, [RANSOMWARE] BrainCipher leaked paipharma.com, [RANSOMWARE] genesis leaked Brooklyn Defender Services, [RANSOMWARE] settra leaked petradiamonds.com, [RANSOMWARE] settra leaked orion4value.com, [RANSOMWARE] incransom leaked https://sza.it/, [RANSOMWARE] settra leaked clc-tn.com, [RANSOMWARE] settra leaked joyconstructionnyc.com, [RANSOMWARE] settra leaked wilfley.com, [RANSOMWARE] qilin leaked Chamco, [RANSOMWARE] qilin leaked Hemmersbach GmbH & Co. KG, [RANSOMWARE] pear leaked Spector and Lenz, PC, [RANSOMWARE] pear leaked ORA Group Information, [RANSOMWARE] gunra leaked Pirámide Seguros, [RANSOMWARE] gunra leaked on-us, [RANSOMWARE] gunra leaked Yuditec S.A., [RANSOMWARE] akira leaked About Todd Hamaker & Johnson, [RANSOMWARE] settra leaked rcfassoc.com, [RANSOMWARE] akira leaked Advanced Business Systems, [RANSOMWARE] settra leaked owensborograin.com, [RANSOMWARE] settra leaked ilex-paysages.com, [RANSOMWARE] settra leaked touredge.com, [RANSOMWARE] settra leaked vcnyhome.com, [RANSOMWARE] settra leaked infinedi.net, [RANSOMWARE] cmdorganization leaked Medlink Georgia, [RANSOMWARE] cmdorganization leaked Port Angeles Composite, [RANSOMWARE] embargo leaked www.maytrucking.com
[9] SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) (HelpNetSecurity) —
Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets,” BlackPoint Cyber’s researchers discovered.
[8] Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer (TheHackerNews) — An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (OIDC) flow that an unauthenticated
[8] Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks (SecurityWeek) —
Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors.
The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first on SecurityWeek.
[8] Aikido Security acquires Root to expand backported fixes for open source vulnerabilities (HelpNetSecurity) —