Wednesday , June 24 2026
cPanel

ALERT
Patch Now! Critical Exchange Server, cPanel, and Kubernetes Flaws Exploited

cPanel & WHM and WP Squared have recently provided fixes for five critical flaws. These issues include the ability to read any file and SQL injection, which threaten server safety and data privacy.

The biggest flaw found this time let anyone get into sensitive system resources without permission.

LastPass says hackers stole customer data via Klue, supply chain breach

LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
LastPass says hackers stole customer data via Klue, supply chain breach

New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

CVE-2026-29205 (CVSS 8.6) – Arbitrary File Read: A mix of wrong privilege dropping and not enough path filtering lets attackers read random files through some cpdavd endpoints. This impacts versions 120 and above.

CVE-2026-32993 (CVSS 8.3) – HTTP Header Injection: An insecure endpoint in cpsrvd was found to let users add any HTTP headers. This affects versions 132 and up.

CVE-2026-32992 (CVSS 8.2) – Credential Theft via DNS Cluster: SSL checks were not completely applied in the DNS Cluster system. A bad server could do a man-in-the-middle attack to steal credentials. This impacts versions 126 and above.

CVE-2026-29206 (CVSS 8.1) – SQL Injection: The sqloptimizer script has a flaw that lets anyone run any SQL query they want. This is important because it affects all versions of cPanel and WHM.

CVE-2026-32991 (CVSS 7.1)  Team Member Privilege Escalation: Low-privilege team users (role=default) can gain full owner rights using certain UAPI modules. This applies to versions 110 and above.

Patches have been sent out to different release levels so all active users can protect their environments.

Exchange Server

Microsoft has sent out an urgent alert for groups using on-site email systems. A new security flaw in Outlook Web Access (OWA) is now being targeted by attackers, who can run harmful code just by sending a specially made email.
The flaw, known as CVE-2026-42897 (CVSS 8.1), is a big risk for company security because it affects the user’s browser.
According to the Exchange Team, this is a Microsoft Exchange Server Spoofing Vulnerability that hinges on user interaction within a web browser. The mechanism of the attack is deceptively simple: “An attacker could exploit this issue by sending a specially crafted email to a user. If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context”.

Microsoft has confirmed that this flaw has been used in real situations, which means criminals are already using it to get around security measures.

The vulnerability impacts several generations of on-premises servers:

Exchange Server 2016 (Any update level)
Exchange Server 2019 (Any update level)
Exchange Server Subscription Edition (SE) (Any update level)

Kubernetes 

Researchers have found security flaw in Kubernetes-based database systems. This issue is in CloudNativePG (CNPG) and is called CVE-2026-44477 with a high CVSS score of 9.4. It lets users with low privileges gain full PostgreSQL superuser access and run any commands on the operating system.

The flaw is with how this exporter connects. It first connects as the postgres superuser through a local Unix socket. Then, it tries to lower its access with the SET ROLE pg_monitor command. But this lowering is not real.

Researchers identified two distinct ways this flaw can be weaponized in the wild:

Path 1: Custom Metric Sabotage: Any database user who owns a schema on the search_path of a scraped database can “shadow” a common function used in a custom metric query. Within one scrape interval (typically 30 seconds), their malicious shadow expression executes with superuser rights.

Path 2: The “Stock” Vulnerability: Even deployments using only default configurations are at risk. A specific metric, pg_extensions, used an unqualified call that could be shadowed by any non-superuser who owns a user database.
This vulnerability affects all deployments on any supported release with default monitoring enabled.

Affected Versions: All versions prior to 1.28.3 and version 1.29.0. The CloudNativePG team has put out three fixes for the problem, now available in Patched Versions 1.28.3 and 1.29.1.

Microsoft’s MDASH VS Anthropic’s Mythos VS OpenAI’s Daybreak

Check Also

F5

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let …