
Hello all,
As usual, this week held lots of announcements of vulnerabilities, malware, breaches, new interesting things, and of course, AI advances. A few items stood out, such as Cisco hitting the headline news for the third week in a row with yet another vulnerability, UniFi Ubiquiti with five new critical defects, a few nice takedowns and arrests of dirtbags by the good guys, Verizon’s annual report on the state of cyber security, and much more in the full list of links.
Headline NEWS:
- Cisco now has a threepeat for weekly critical vulnerabilities. This week’s special is an API issue in Cisco Secure Workload Cluster Software on SaaS and on-prem. Specially crafted API calls can enable a threat actor to access stie resources with the privileges of the Site Admin role. Cisco has fixed this via new software releases, there are no workarounds, so it is important that on-prem clients update to the latest version as soon as possible. Thankfully, this is not known to be currently exploited.
- Google Chrome needs to be updated to the latest version. Among the eleven vulnerabilities announced are two critical defects that can enable remote code execution simply by having the victim visit a maliciously crafted website. Naturally Chromium based browsers will be updating soon as well. Check your browsers now for updates, please.
- MiniPlasma Windows 0-Day vulnerability enables SYSTEM on fully patched Windows devices. Apparently, a once-patched defect in “cldflt.sys” was errantly broken again by a subsequent update at some point. This is why regression testing is so vital. Don’t break something else when you fix a thing please. Currently, there is no patch for this Windows Cloud Files Mini Driver flaw. I expect that Microsoft will address this rather quickly since it is a bit of a gaping hole right now.
- Ubiquiti UniFi OS vulnerabilities. Back in March of this year, Ubiquiti patched a critical defect that would enable account takeover and escalation of privileges. The latest set of three flaws announced early in the week enable a threat actor to get access to the underlying operating system which can enable access to the account, alter the access controls, and inject random commands. If that weren’t enough, there were two more vulnerabilities disclosed later in the week bringing the total to five critical or maximum severity UniFi defects receiving patches this week. If you use Ubiquiti in your enterprise, patch soon so that you can sleep better at night.
In Ransomware, Malware, and Vulnerabilities News:
- Verizon Data Breach Investigations Report (DBIR) 2026 was released this week. The seminal publication is eagerly anticipated by security minded professionals each year due to the fascinating insights and thorough research that it contains. Some highlights from this year’s edition are statistics such as 31% of all breaches were the result of unpatched vulnerabilities, yet vulnerability remediation patching time has risen from an average of 32 days in the prior year to 43 days in the reporting year. And Ransomware was involved in 48% of breaches, up from 44%. This 121 page report is well worth taking your time to read through and digest.
In Other News Events of Note and Interest:
- Google Cloud suspended major customer Railway.com without cause, causing outage is what the headline reads. Apparently, the author doesn’t read security news. Railway.com has been heavily abused by the EvilTokens Phishing-as-a-Service (PhaaS) There were hundreds of organizations impacted by Device Code authorization flow phishing that used Railway’s platform. To quote the Huntress article linke above, “Railway effectively hands adversaries a cloud-hosted token harvesting engine that is clean to Microsoft’s risk scoring, and whoever is behind this campaign is weaponizing it to full effect.” So, Railway certainly has significant culpability in their tool being used for evil purposes. To say the suspension was without cause is a rather disingenuous, but I would agree that, if the assertion of the article is correct that there was no notice, Google was draconian and should have alerted and given fair warning and opportunity to Railway to address any concerns prior to unilaterally disabling a portion of their operations.
Musings
In the Northern Hemisphere Summer is heating up, and based on the increasing vulnerability, malware, and breach reports, so are threat actors worldwide it would appear. Their newly found superpowers, courtesy of adversarial or hacked AI engines enable these dirt bags of the world to execute their malevolent schemes in a manner and scale that we defenders are still striving to understand. Thankfully, we also have the same tools available to us, we just need to ensure that we remain active, engaged, and vigilant so that we stay at least one step ahead.

And keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access
- Update Chrome now: Critical bugs could let attackers run code
- MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
- Ubiquiti patches three max severity UniFi OS vulnerabilities
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- ‘There is no universe in which Proton VPN compromises its no-logs policy’ — Proton joins the backlash against Canada’s surveillance bill
- CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
- US and Canada arrest and charge suspected Kimwolf botnet admin
- Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
- Netherlands seizes 800 servers of hosting firm enabling cyberattacks
- INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests
- INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
- Cybercriminal VPN used by ransomware actors dismantled in global crackdown
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
- Europol disrupts thousands of IRGC online accounts across 19 countries
- Fired hacker twins forget to end Teams recording, capture own crimes
- Vulnerabilities and Exploits
- Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
- Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
- Claude Code RCE Flaw Lets Attackers Execute Commands via Malicious Deeplinks
- To gain root access, intruder just had to ask
- Nvidia tells users to update GPU drivers now or face possible attack
- ‘Claw Chain’ Vulnerabilities Threaten OpenClaw Deployments
- SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
- Drupal core – Highly critical – SQL injection – SA-CORE-2026-004
- Microsoft shares mitigation for YellowKey Windows zero-day
- PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability
- Hackers bypass SonicWall VPN MFA due to incomplete patching
- NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
- New NGINX Vulnerability Allows Remote Attackers to Trigger Malicious Code
- Microsoft warns of new Defender zero-days exploited in attacks
- 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
- TrendAI Patches Apex One Zero-Day Exploited in the Wild
- Google publishes exploit code threatening millions of Chromium users
- Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI
- Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
- Phishing, Malware, and similar
- Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases
- The New Phishing Click: How OAuth Consent Bypasses MFA
- FBI warns of Kali365 as device code phishing soars
- Ukraine identifies infostealer operator tied to 28,000 stolen accounts
- Typosquatting Is No Longer a User Problem. It’s a Supply Chain Problem
- Fake OpenAI repository on Hugging Face pushes infostealer malware
- Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
- SHub macOS infostealer variant spoofs Apple security updates
- North Korean operatives stole $2 billion last year—and financial firms are the next target
- Microsoft Self-Service Password Reset abused in Azure data theft attacks
- Cybercrime service disrupted for abusing Microsoft platform to sign malware
- Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
- Most dark web activity revolves around a handful of topics
- Breaches, Leaks, and Ransomware
- Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom
- CISA Admin Leaked AWS GovCloud Keys on Github
- Grafana Confirms Breach After Hackers Claim They Stole Data
- ShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed
- NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people
- 46k plaintext passwords pwned in Myspace93 breach
- Apple server schematics stolen in May 2026 Foxconn cyberattack
- American Lending Center Data Breach Affects 123,000 Individuals
- GitHub admits major source code leak after 3,800 internal repositories breached
Other News Events of Note and Interest
- Cool Tool: WinDirStat 2.6.1
- Google Cloud suspended major customer Railway.com without cause, causing outage
- Everything Google announced at I/O 2026: Gemini, Android, more
- Google Introduces Cloud Fraud Defense as Successor to reCAPTCHA
- If you use Google accounts, it’s time to do a free security checkup
- Google’s new gradient Workspace icons are officially rolling out on the web
- First-gen Chromecast are now failing for many, 13 years later
- Meta quietly launches a new Reddit-like app called Forum
- T-Mobile Adds Live Translation
- Ordinary WiFi can now identify people with near perfect accuracy
- Poland builds its own Signal amid security concerns
- Qualcomm confirms a Snapdragon-powered Googlebook will launch this fall
- Unified EDR + ITDR: Closing the Identity Gap Before Attacks Spread
- Comcast’s Email Service Is Shutting Down – Act Now to Save Your Emails
- After Duke revokes ‘lifetime’ email promise, alumni scramble to untangle online accounts
- Discord rolls out end-to-end encryption on voice, video calls
- VMware quietly debuts Arm hypervisor tech preview
- Vivaldi 8.0 arrives as “the most significant design overhaul” in the browser’s history
- Mozilla officially confirms Firefox 2026 “Nova” redesign, and you can already enable it
- Mozilla explains Firefox crashes on Intel 13th, 14th Gen Raptor Lake systems
- WordPress 7.0 Is A Winner: Here’s What You Need To Know
- AI, LLM’s, and Skynet
- Companies Under Heavy AI Psychosis
- The Unsustainable Subsidy
- Why Young Teens Are Vulnerable to Conversational AI
- The Internet can’t stop watching Figure AI’s humanoid robots handling packages
- Project Glasswing: what Mythos showed us
- Anthropic’s Code with Claude showed off coding’s future—whether you like it or not
- Google adds AI to the search box
- AI Voice Cloning: The Technology Behind It, Who’s Building It, and Where It’s Headed
- Microsoft Releases Fara1.5: A Family of Browser Computer-Use Agents
- Microsoft AI Chief Mustafa Suleyman has a grim warning for every office worker- Within 18 months…
- Microsoft
- Microsoft finally begins testing movable and resizable Taskbar on Windows 11, restoring key customization features many users missed
- Microsoft is retiring Teams’ Together Mode
- Microsoft blames macOS update for undismissible Teams location prompts
- Windows has a built-in Wi-Fi report that shows every disconnect
- Microsoft admits customization is in Windows’ DNA, promises new Windows 11 controls
- Microsoft confirms the new Secure Boot folder in Windows 11 isn’t a bug, you don’t need to delete it
- Microsoft admits it needs feedback to fix Windows 11 UX, launches new research panel
- Microsoft is killing SMS codes for Microsoft account sign-in, aggressively pushes passkeys on Windows 11
- Microsoft surprises with its first server Linux distribution: Azure Linux 4.0
- Windows 11 24H2 and 25H2 get fixes for muted audio and non-working apps and notifications
- Microsoft confirms patching issues in restricted Windows networks
- Microsoft confirms Windows 11’s May 2026 update is failing to install with error 0x800f0922 and outlines a mitigation for affected PCs
- Microsoft May security patch fails for some due to boot partition size glitch
- Microsoft plans to improve Windows 11 driver quality in 2026
- Microsoft admits faulty drivers were killing Windows 11 battery life for years
- Microsoft says Windows 11’s explorer.exe has been unstable across taskbar, sign-in, and Task View, rolls out fix
