June 2, 2026

GammaWorm Malware: How Gamaredon APT Hides in Windows

GammaWorm malware is an active Gamaredon APT campaign hiding fileless worm modules in Windows NTFS Alternate Data Streams and using Telegram and Cloudflare as dead drop C2 resolvers. Security teams must patch CVE-2025-8088 immediately and deploy behavioral endpoint detection to counter this ongoing threat.
June 4, 2026

AI-Powered Attacks: Active Directory and EDR Evasion Exposed

AI Active Directory attacks are now confirmed operational, with Sophos uncovering a live ransomware-linked framework that uses AI agents to automate AD enumeration and iteratively test EDR evasion against Sophos, CrowdStrike, and Microsoft Defender. Security teams must harden Active Directory, deploy behavioral EDR, and enforce Zero Trust controls immediately.
June 5, 2026

Cisco SD-WAN Vulnerability CVE-2026-20182 Actively Exploited

The Cisco SD-WAN vulnerability CVE-2026-20182 carries a CVSS 10.0 score and is being actively exploited by UAT-8616 to gain full admin access to enterprise SD-WAN infrastructure with zero credentials required. Patch immediately, audit for compromise, and restrict management access now.
June 6, 2026

Hugging Face RCE Vulnerability Exposes Millions of AIs

The Hugging Face RCE vulnerability CVE-2026-4372 silently exposed 2.2 billion Transformers installs to remote code execution for six months by bypassing the trust_remote_code=False safety control through a poisoned AI model config. Patch to version 5.3.0 immediately and audit your ML environments for compromise.
June 8, 2026

Redis RCE Vulnerability DarkReplica: Full Host Takeover

The Redis RCE vulnerability DarkReplica CVE-2026-23631 lets authenticated attackers gain full host control via Lua use-after-free during replication. One of five Redis RCE flaws patched May 5, 2026. Patch to fixed releases and audit for compromise immediately.