Cyber Brief · Jul 6 · 8 stories
Monday, July 6, 2026 · sent to 1 subscribers
News
· The Hacker News · Jul 6
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.
The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEBAUTH-USER" header …
News
· BleepingComputer · Jul 2
CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. [...]
News
· The Hacker News · Jun 30
An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer.
The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authe…
News
· BleepingComputer · Jun 30
CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. [...]
News
· Help Net Security · Jun 30
Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with clou…
Advisories
· CISA · Jun 30
View CSAF
Summary
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to enumerate all user accounts and role assignments on a FUXA SCADA/HMI instance.
The following versions of Frangoteam FUXA SCADA/HMI are affected:
FUXA SCADA/HMI <=1.3.1 (CVE-2026-132…
Advisories
· CISA · Jul 2
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device.
The following versions of CubeSpace CW0057 Reaction Wheel are affected:
CW0057 Reaction Wheel
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.1
CubeSpac…
News
· SecurityWeek · Jul 2
CISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659).
The post CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability appeared first on SecurityWeek.