IT Security Newsletter - 6/11/2026
CISA, researchers warn of escalating attacks using Cisco Catalyst SD-WAN flaws
The Cybersecurity and Infrastructure Security Agency on Tuesday added a zero-day flaw in the Cisco Catalyst SD-WAN product line to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-20245, could allow an attacker to execute arbitrary commands as root. The vulnerability, which has a severity score of 7.8, could enable an attacker to conduct command injection attacks on a targeted system. READ MORE...
FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort
Federal authorities have seized 13 internet domains allegedly used to target current and former U.S. government employees and military personnel with access to classified and sensitive information. The Justice Department stated that the domains were backed by suspected Chinese agents seeking information of interest to the Chinese government. The individuals behind the operation denied involvement by any foreign government. READ MORE...
Microsoft fixes BitLocker recovery bug on Windows Server 2025
Microsoft has resolved a known issue causing some Windows Server 2025 devices to boot into BitLocker recovery after installing the April 2026 security update. The BitLocker security feature encrypts storage drives to prevent data theft and will typically force Windows computers to enter recovery mode after hardware changes or events, such as TPM (Trusted Platform Module) updates, to allow regaining access to protected drives that have not been unlocked via the default unlock mechanism. READ MORE...
Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware
Cybercriminals are using TikTok and Instagram Reels videos to spread Vidar, an infostealer malware, through fake downloads for popular paid software, according to ReversingLabs. The researchers uncovered two campaigns behind the activity, each using a different approach to draw in viewers before sending them to external download sites. One campaign centered on fake software installation tutorials featuring polished graphics and voiceovers. READ MORE...
OpenAI: 'Likely' Chinese influence operation tried to use ChatGPT to stir debate on data centers
OpenAI's threat intelligence team tracked what it believes are two distinct clusters of activity online from groups with ties to China and posting content seemingly designed to stoke anger around divisive topics like AI and data centers. The first, dubbed "Data Center Bandwagon," used ChatGPT to create imagery and social media comments claiming data center buildouts were raising electricity prices for Americans. READ MORE...
Angry bug hunter with Microsoft beef drops new Windows 0-day
They are angry at Redmond and will have their revenge. Nightmare Eclipse, the prolific bug hunter and possibly disgruntled ex-Microsoft employee, disclosed another zero-day vulnerability just hours after Redmond issued a record-breaking number of CVEs and fixes for June Patch Tuesday. The latest zero-day, RoguePlanet, targets Microsoft Defender and works against fully patched Windows 10 and Windows 11 systems, according to the researcher. READ MORE...
Hackers Exploit Langflow Vulnerability for Remote Code Execution
Threat actors have begun exploiting a high-severity vulnerability in the popular low-code AI development platform Langflow, according to VulnCheck. Tracked as CVE-2026-5027 (CVSS score of 8.8), the security defect is described as a path traversal issue that allows attackers to write files to arbitrary locations on the system. Successful exploitation of the bug allows unauthenticated attackers to execute arbitrary code on vulnerable instances. READ MORE...
Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
Oracle on Thursday released an out-of-band advisory addressing a PeopleSoft vulnerability that can be exploited by an unauthenticated attacker for remote code execution. The security alert comes amid reports that the notorious ShinyHunters hacker group has been targeting organizations that use PeopleSoft. PeopleSoft is an integrated enterprise resource planning (ERP) software suite widely used by large organizations for managing core business functions. READ MORE...
- ...in 1509, Henry VIII marries his first wife, Catherine of Aragon; their subsequent divorce led to England's split from the Catholic Church.
- ...in 1776, the Continental Congress appoints the Committee of Five to draft the Declaration of Independence.
- ...in 1963, two African-American students, Vivian Malone and James Hood, register at the previously segregrated University of Alabama.
- ...in 1982, "E.T.: The Extra-Terrestrial" opens in U.S. theaters, going on to become one of the highest-grossing films of all time.






