The Critical Cisco ISE Flaw Needed Admin Rights. The Other One Needed None.

Cisco ISE's critical command injection required an administrator, while the lower-scored flaw exposed hashed credentials without authentication.
Vulnerabilities, defensive security, architecture and operational security.

Cisco ISE's critical command injection required an administrator, while the lower-scored flaw exposed hashed credentials without authentication.

Cisco confirmed exploitation of two Catalyst SD-WAN control-plane flaws and told customers to preserve admin-tech evidence before patching or changing configuration.
A ShinyHunters campaign against Oracle PeopleSoft environments shows how a business-critical application can become a repeatable data-theft route when it is exposed, customised and difficult to update. Google’s Mandiant team reported an active campaign by the ShinyHunters-linked group it tracks…

A SimpleHelp OIDC bypass could create technician accounts, enrol attacker-controlled MFA and inherit remote-management permissions from a mapped group.
Unauthorised access to a World Food Programme registration system exposed data associated with roughly 600,000 Gaza households. In a conflict zone, ordinary identity and location fields can create extraordinary physical risk. The World Food Programme confirmed unauthorised access to its…

June 2026 Patch Tuesday covers 110 approved patch records and 392 unique CVEs across Microsoft, Adobe and SAP.

Apple extended Private Cloud Compute onto Google Cloud and NVIDIA hardware, turning attestation, independent roots of trust and public verification into the privacy boundary.

France says one hijacked Tchap account exposed public-room content associated with 73,467 officials. Private encrypted histories were not reported compromised.

Cisco’s new infrastructure-security platform combines faster vulnerability research with runtime protections. It could reduce emergency patch pressure, provided temporary shields do not become permanent exceptions. Cisco announced an agentic platform for operating and defending critical IT infrastructure on 2 June.…

CISA confirmed active exploitation of an unauthenticated SolarWinds Serv-U flaw that let one crafted request crash file-transfer services.