Cisco Unified CM CVE-2026-20230 now drops webshells via Tor
Three weeks after the June 3 patch, Defused honeypots see automated Tor-routed sweeps deploying multi-stage JSP shells via the WebDialer SSRF. Patch alone won't evict them.
Three weeks after the June 3 patch, Defused honeypots see automated Tor-routed sweeps deploying multi-stage JSP shells via the WebDialer SSRF. Patch alone won't evict them.
Symantec links a stealth in-memory backdoor used since April 2026 to KongTuke (Woodgnat), the initial-access broker that has fed Interlock, Rhysida, Akira, 8Base and Black Basta.
Zafran Security discloses four Dify CVEs (41947–41950). Three patched in 1.14.2; the CVSS-9.4 Plugin Daemon path traversal CVE-2026-41948 remains unfixed at release time.
Squid project published SQUID-2026:4 on June 23 — a heap over-read in the FTP gateway that leaks raw memory to a malicious FTP server. Fix in Squid 7.6.
CVE-2026-20253 is a CVSS 9.8 missing-authentication flaw in Splunk Enterprise 10. CISA added it to KEV on June 18 with a three-day patch deadline. WatchTowr published a working RCE exploit.
TPWD says a third-party license vendor was breached, exposing driver's licenses, passport numbers, emails, phones and addresses for 3M+ hunting and fishing customers. SSNs and financials not affected.
Node.js v22.23.0, v24.17.0 and v26.3.1 fix 12 CVEs including a TLS wildcard hostname bypass (CVE-2026-48618) and a WebCrypto integer overflow DoS (CVE-2026-48933).
Wordfence blocked 17M attempts at the unauth REST endpoint that dumps Gravity SMTP's full System Report — live API keys and OAuth tokens included. Patch is 2.1.5.
Aikido Security found 15 JetBrains Marketplace plugins under 7 vendor accounts that exfiltrated OpenAI, DeepSeek, and SiliconFlow keys over plaintext HTTP. JetBrains pulled them on June 16, 2026.