Wednesday , June 24 2026

CISA Adds Microsoft Exchange Server Flaw To Its KEV

CISA has given a new warning about a Microsoft Exchange Server flaw that attackers are already using, which worries organizations that depend on local email systems.

The issue CVE-2026-42897 is a cross-site scripting (XSS) flaw in Microsoft Exchange Server, mainly in Outlook Web Access (OWA).

LastPass says hackers stole customer data via Klue, supply chain breach

LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
LastPass says hackers stole customer data via Klue, supply chain breach

New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The official warning says the flaw happens when making a web page. It can occur when certain actions happen, letting attackers run any JavaScript in someone else’s browser.

The flaw was added to CISA’s list of known issues on May 15, 2026, showing that it is being actively used by attackers.

Federal agencies and groups that follow the Binding Operational Directive (BOD) 22-01 must fix the problem by May 29, 2026.

Microsoft Exchange Server Vulnerability Exploit

Security experts say that XSS flaws in business email systems like Exchange are very risky because they can be used to take over logged-in accounts.

An attacker could fool a user into clicking a special link that runs bad scripts in their browser.This can lead to credential theft, mailbox access, or further internal compromise.

Exchange servers have always been a prime target for hackers because they manage important messages and account information.

The flaw is marked as CWE-79, a common type of web security issue that happens when input is not properly cleaned up while making web pages.

CISA wants agencies to apply the security updates and fixes from vendors without delay.

If patches are not ready or cannot be used, agencies should follow other safety steps suggested by Microsoft or think about stopping the use of affected systems until they are safe.

Security teams need to check Exchange server logs for any strange activity. This includes odd login patterns, unexpected script running, or unusual user actions in Outlook Web Access sessions.

New AsyncRAT malware campaign detected in Bangladesh cyber space

Check Also

F5

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let …