Decoding Threats.
Watching the Wire.
Daily security intelligence curated from the world's leading sources, mapped across 8 core security disciplines — from threat intelligence to application security.
389
Articles
152
CVEs Tracked
8
Security Domains
Daily
Updates
Latest Intelligence
Recent Articles
Ivanti Sentry CVE-2026-10520: CVSS 10.0 Pre-Authentication RCE Exploited After PoC Release
Ivanti has disclosed CVE-2026-10520, a CVSS 10.0 pre-authentication remote code execution vulnerability in Ivanti Sentry (formerly MobileIron Sentry) that is being actively exploited following public proof-of-concept release. A companion OS command injection flaw CVE-2026-10523 (CVSS 9.4) affects the same platform. Both require immediate action for all organisations running Ivanti Sentry in their mobile device management infrastructure.
Linux Kernel CVE-2026-23111: nf_tables Use-After-Free Enables Container Escape and Root Privilege Escalation
A use-after-free vulnerability in the Linux kernel's nf_tables netfilter subsystem allows unprivileged users to escalate to root and break container isolation. Public proof-of-concept code published 9 June makes this an immediate remediation priority across all major Linux distributions running kernel versions 5.15 through 6.10.
Microsoft June 2026 Patch Tuesday: 198 CVEs and Six Zero-Days Including Wormable CVSS 9.8 HTTP.sys Flaw
Microsoft's June 2026 Patch Tuesday addresses 198 vulnerabilities across Windows, Office, Azure, and server components — including three CVSS 9.8 critical remote code execution flaws and six publicly disclosed zero-days. HTTP.sys CVE-2026-47291 is wormable, requiring no authentication or user interaction against any Windows Server with IIS or HTTP API exposed.
CVE-2026-50751: Check Point Security Gateway Authentication Bypass Actively Exploited in Ransomware Campaigns
CISA added CVE-2026-50751 to the Known Exploited Vulnerabilities catalogue on 8 June with a three-day remediation deadline and confirmed ransomware campaign use. The vulnerability is a CVSS 9.3 authentication bypass in Check Point Security Gateway's IKEv1 VPN protocol handling that allows unauthenticated attackers to bypass remote access VPN authentication entirely. An emergency hotfix is available.
Windows Netlogon CVE-2026-41089 (CVSS 9.8): Unauthenticated Domain Controller RCE Now Actively Exploited
Belgium's Centre for Cybersecurity (CCB) confirmed active exploitation of CVE-2026-41089 on 29 May — a stack-based buffer overflow in the Windows Netlogon Remote Protocol (MS-NRPC) that allows unauthenticated remote code execution on domain controllers. CVSS 9.8. A public PoC is available. Patch domain controllers as an emergency priority.
Over 400 Arch Linux AUR Packages Poisoned with eBPF Rootkit in Coordinated Maintainer Compromise
More than 400 packages in the Arch Linux User Repository were compromised by an attacker who spoofed trusted maintainer identities to push malicious preinstall scripts. The scripts deploy an ELF infostealer harvesting developer credentials and an optional eBPF rootkit that persists across package removal attempts.
Cisco Catalyst SD-WAN Manager CVE-2026-20262 Actively Exploited — Arbitrary File Overwrite Escalates to Root
A file upload vulnerability in Cisco Catalyst SD-WAN Manager is under active exploitation, allowing an attacker with network-operator level access to overwrite arbitrary files on the underlying operating system and escalate privileges to root. CISA added CVE-2026-20262 to the Known Exploited Vulnerabilities catalogue on 16 June, setting a federal remediation deadline.
DOJ Seizes CFAKE.com and SOCFAKE.com in First Criminal Enforcement Under the TAKE IT DOWN Act
US authorities seized two of the largest non-consensual deepfake pornography platforms in a joint operation with French and Italian law enforcement, marking the first major criminal enforcement action under the TAKE IT DOWN Act signed into law in May 2025. A French national was arrested in Nice on 10 June; cryptocurrency proceeds have been seized pending forfeiture.
Opinion & Analysis
Commentary
Air-Gapping Is Not a Security Strategy — Operation Highland Proves It Never Has Been
Velvet Ant's ten-year persistence inside an air-gapped network is being reported as an extraordinary technical achievement. It isn't. It is a predictable consequence of substituting physical isolation for security architecture, and the organisations still treating air gaps as a primary control are making the same mistake that left a critical infrastructure network exposed for a decade.
CipherWatch Editorial
Security Intelligence Platform
Your Most Trusted Tool Is Now Your Biggest Blind Spot: The RMM Security Problem
The SimpleHelp OIDC authentication bypass is the latest in a consistent pattern: remote monitoring and management tools — the software your IT team uses to fix problems — have become one of the primary entry points for sophisticated attackers. The reason is structural, and it won't be solved by patching one vendor at a time.
CipherWatch Editorial
Security Intelligence Platform
For CISOs, CIOs & Board Members
CIO Briefings
Security events translated into business language — financial exposure, regulatory obligations, and board-ready summaries.
iRhythm Cardiac Data Breach — 12 Million Patients' Health Records Exposed, HIPAA Notification Triggered
iRhythm Technologies, the maker of the Zio continuous cardiac monitoring patch, has disclosed a data breach affecting approximately 12 million patients after social engineering granted attackers access to third-party-hosted systems containing protected health information. Healthcare providers that refer patients to iRhythm may carry independent HIPAA breach notification obligations and should urgently assess whether their patient populations are within scope.
CRITICAL: PAN-OS VPN Flaw CVE-2026-0257 Actively Exploited — Attackers Gaining Silent Network Access
A critical vulnerability in Palo Alto Networks GlobalProtect VPN — the primary remote access gateway for thousands of enterprises — allows attackers to bypass login controls entirely and gain access to internal corporate networks without credentials. Exploitation is confirmed and ongoing, with government agencies and critical infrastructure operators among identified victims. Immediate patching is required.
CRITICAL: Ivanti Sentry CVE-2026-10523 + CVE-2026-10520 Chain Enables Complete MDM Gateway Compromise
Two critical Ivanti Sentry vulnerabilities — CVE-2026-10523 (CVSS 9.9, auth bypass) and CVE-2026-10520 (CVSS 10.0, pre-auth RCE) — chain to enable complete unauthenticated takeover of the Sentry MDM gateway. Organisations that applied the initial patch for CVE-2026-10520 remain exposed through CVE-2026-10523. Immediate upgrade to 9.19.0 required.
Security Domains
Browse by Domain
Security intelligence mapped across 8 core disciplines.
Risk Mgmt
Governance, compliance, ethics, risk frameworks, legal regulations, and business continuity planning.
Assets
Data classification, ownership, privacy protection, retention policies, and data security standards.
Architecture
Secure design principles, cryptography, physical security, and security models.
Network
Network architecture, protocols, secure communication channels, and network attacks.
IAM
Authentication, authorization, access control models, identity federation, and MFA.
Assessment
Vulnerability assessment, penetration testing, audit strategies, and security metrics.
SecOps
Incident response, forensics, threat intelligence, SIEM, and operational security.
AppSec
Secure SDLC, code review, application vulnerabilities, DevSecOps, and software security testing.
Stay Vigilant
Intelligence is your first line of defence.
CipherWatch compiles and synthesises security news daily from Krebs on Security, The Hacker News, BleepingComputer, CISA advisories, and more — so you stay ahead of the threat curve.
Learn how it works →