📡 Tech & Security Digest — 2026-06-12
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks — Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution…
- CISA tells govt agencies to patch critical exploited flaws in 3 days — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updat…
- Path traversal flaw in AI dev platform Langflow exploited in attacks — Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitr…
- CISA orders feds to patch actively exploited Ivanti flaw by Sunday — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within …
- Max severity Ivanti Sentry vulnerability now exploited in attacks — Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-…
- Nottingham University data breach affects over 450,000 students — The University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both curren…
Hacker News
- Who Runs the Ransomware Group ‘The Gentlemen?’ (70 pts)
- Show HN: Claw Patrol, a security firewall for agents (93 pts)
- Anthropic apologizes for invisible Claude Fable guardrails (421 pts)
- OpenAI mulls slashing prices as it competes with Anthropic for users (122 pts)
The Hacker News
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now — Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild.
The high-sever…
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to k…
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available — Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation.
The vulnerability, tracked …
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites — Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to exec…
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited…
- One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public — Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to roo…
- Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE — A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active …
- Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code — Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution.
T…
- WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine — Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after p…
- CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol f…