1. Cisco Catalyst SD-WAN Manager zero-day under active exploitation (CVE-2026-20245). Attackers are actively exploiting a privilege-escalation flaw in Cisco Catalyst SD-WAN Manager that lets an authenticated local user upload a crafted file and execute commands as root. At the time of writing, no patch is available, leaving network operators dependent on access controls and monitoring. […]
Cyber Security Weekly: Top 5 Cybersecurity News Stories for the Week of June 8–14, 2026
1. ShinyHunters Exploit Oracle PeopleSoft Zero-Day to Breach Universities (CVE-2026-35273) A critical, unauthenticated remote code execution flaw (CVSS 9.8) in Oracle PeopleSoft PeopleTools was exploited in the wild as a zero-day between May 27 and June 9, roughly two weeks before Oracle’s out-of-band advisory. Mandiant attributed the campaign to the financially motivated group UNC6240 (ShinyHunters), […]
Cyber Security Weekly: Top 5 Cybersecurity News Stories for the Week of June 1–7, 2026
1. ShinyHunters Leaks Data on 42 Million Charter Communications Customers The ShinyHunters extortion group published a trove allegedly stolen from Charter Communications, the telecom giant behind the Spectrum brand, after the company let a May 27 ransom deadline pass. The attackers say they gained entry through a voice-phishing (vishing) call that compromised an employee’s Microsoft […]
Cyber Security Weekly Top 5: Week of May 18–24, 2026
1. Megalodon Supply Chain Attack Poisons 5,500+ GitHub Repositories in Six Hours On May 18, an automated campaign dubbed “Megalodon” pushed 5,718 malicious commits to 5,561 GitHub repositories in a single six-hour window — one of the most aggressive open-source supply chain attacks ever recorded. Using throwaway accounts with forged identities (build-bot, auto-ci, ci-bot, pipeline-bot), […]
Cyber Security Weekly Top 5: Week of May 11-17, 2026
1. Google Thwarts First AI-Driven Zero-Day Exploit Attempt Google’s Threat Intelligence Group revealed it disrupted a hacker operation that used artificial intelligence to discover and weaponize a zero-day vulnerability in a widely used open-source web administration tool. The attackers leveraged an AI model to bypass two-factor authentication and were planning what Google described as a […]






