A curated dispatch from GajShield

The GajShield Gazette

Lead story

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

The active exploitation of CVE-2026-20230 in Cisco Unified Communications Manager and Unified CM Session Management Edition highlights the risk posed by internet-reachable enterprise communication platforms.The vulnerability is a server-side request forgery flaw affecting …

Also today
In brief

JaredFromSubway MEV bot hacked in $15 million crypto theft

The theft of up to $15 million from the JaredFromSubway Ethereum MEV bot demonstrates how automated trading systems can be manipulated thro…

Jun 23, 2026

WhatsApp phishing attack uses fake business docs to hack PCs

The WhatsApp phishing campaign using fake business documents shows how attackers are exploiting trust in known contacts rather than relying…

Jun 23, 2026

CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)

The continued exploitation of SonicWall firewalls shows that installing a firmware update is only one part of remediation. Organizations ma…

Jun 23, 2026

AryStinger botnet infected thousands of D-Link routers worldwide

AryStinger has compromised at least 4,300 legacy routers, primarily D-Link DIR-850L and DIR-818LW devices, using vulnerabilities dating bac…

Jun 22, 2026

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

The disclosure of the USBLighter8 exploit demonstrates that even the earliest and most trusted stages of a modern device’s boot process can…

Jun 20, 2026

Texas govt data breach exposes over 3 million driver’s licenses

The Texas Parks and Wildlife Department data breach demonstrates how a compromise at a third-party service provider can expose millions of …

Jun 20, 2026

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

The active exploitation of an information-disclosure vulnerability in the Gravity SMTP WordPress plugin demonstrates how a flaw that does n…

Jun 20, 2026

CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure

CISA’s warning that a critical Splunk Enterprise vulnerability is being actively exploited should be treated as an urgent security event, p…

Jun 19, 2026

Telegram admits it couldn't police exam-leak channels, India tells court

India’s temporary restriction of Telegram over alleged examination-leak and fraud channels highlights the difficult balance between platfor…

Jun 19, 2026

Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks

The Klue OAuth breach demonstrates how third-party SaaS integrations can become a highly effective route into enterprise cloud data. Instea…

Jun 19, 2026

USB worm spreads crypto-stealing malware via Windows shortcut files

The discovery of a USB-spreading malware campaign targeting cryptocurrency users demonstrates that removable media remains an effective att…

Jun 19, 2026