Cyber Brief · Jun 28 · 12 stories
Sunday, June 28, 2026 · sent to 1 subscribers
News
· BleepingComputer · Jun 28
Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. [...]
News
· The Hacker News · Jun 26
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabi…
News
· The Hacker News · Jun 26
DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant.
Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user co…
News
· BleepingComputer · Jun 26
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]
News
· CSO Online · Jun 26
Hackers are exploiting a critical vulnerability recently patched in PTC Windchill and FlexPLM, two product lifecycle management solutions used by organizations across a range of industries, including defense, aerospace, automotive, medical, electronics, industrial machinery, and consumer goods.
…
News
· Help Net Security · Jun 28
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone watching a network li…
Advisories
· CISA · Jun 25
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code.
The following versions of Delta Electronics DTM Soft are affected:
DTMSoft vers:all/*
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Delta Electronics
Delta Electronics D…
Advisories
· CISA · Jun 25
View CSAF
Summary
Successful exploitation of this vulnerability could allow a local attacker to disclose information and execute arbitrary code.
The following versions of Horner Automation Cscape are affected:
Cscape <10.2_SP3
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Horner A…
Research
· SANS ISC · Jun 29
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Research
· SANS ISC · Jun 28
YARA-X&#;x26;#;39;s 1.18.0 release brings 3 improvements and 2 bugfixes.
Video
· IppSec · Jun 27
00:00 - Introduction
01:00 - Start of nmap
03:20 - Searching for vulnerabilities in Wing FTP Server
06:20 - Testing the RCE and running a command
09:30 - Weaponizing the POC to get a reverse shell
12:10 - Shell returned, grabbing the password hashes, discovering it uses a hard-coded salt and then c…
News
· SecurityWeek · Jun 26
CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.
The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek.