Vulnerabilities & Patches
Your backup server just became a CVSS 9.4 problem.
Your backup server just became a CVSS 9.4 problem. Veeam disclosed CVE-2026-44963 on June 9: any authenticated domain user — not an admin, not a privileged account — can execute code directly on a Veeam Backup & Replication server. A standard Active Directory login is enough. The flaw was discovered by watchTowr researcher Sina Kheirkhah.…
Read MoreThe biggest Patch Tuesday in Microsoft history dropped yesterday: 200 vulnerabilities. 33 Critical. 3 disclosed zero-days.
The biggest Patch Tuesday in Microsoft history dropped yesterday: 200 vulnerabilities. 33 Critical. 3 disclosed zero-days. And then â hours after the patches shipped â a researcher published an unpatched one that works on fully updated Windows 10 and 11. You patched everything available. You still have a gap. Here is what the June 9…
Read MoreYour Check Point VPN has a zero-day. Qilin ransomware is already using it.
Your Check Point VPN has a zero-day. Qilin ransomware is already using it. The vulnerability requires no stolen credentials, no phishing, no user interaction. It requires only that your VPN still supports a protocol from 2005. CVE-2026-50751, disclosed on June 8, is an authentication bypass in Check Point Remote Access VPN and Mobile Access. The…
Read MoreYour password manager just had encrypted vaults stolen. That’s not a near-miss.
Your password manager just had encrypted vaults stolen. That’s not a near-miss. Dashlane disclosed this week that attackers successfully downloaded encrypted password vaults belonging to fewer than 20 users via a brute-force attack. Dashlane notes the vaults remain encrypted and there’s no evidence of successful decryption. Most organizations reading this will breathe a sigh of…
Read MoreYour VPN just let someone in without a password.
Your VPN just let someone in without a password. Not because they guessed it. Not because someone clicked a phishing link. Because the authentication check never happened at all. CVE-2026-0257 is an authentication bypass in Palo Alto Networks PAN-OS that affects GlobalProtect portal and gateway. The flaw is subtle: when the certificate used to encrypt…
Read More
