Security news.
Today's security landscape highlights critical vulnerabilities in widely used software and applications, alongside significant data breaches impacting global users and critical infrastructure. The increasing role of AI in both defense and offense is a recurring theme, with new flaws and exploits emerging in AI agents and models.
WordPress Core SQL Injection (CVE-2026-63030) Under Active Exploitation
A critical SQL injection vulnerability in WordPress Core, leading to unauthenticated remote code execution, is currently being actively exploited. All WordPress versions before 4.14.0 are affected.
Vatican's Official Prayer App Leaks Over 700K Users' PII
A vulnerable API endpoint in the Vatican's official prayer app exposed names, email addresses, location, and site status of more than 700,000 global users.
Bing Images Flaws Allowed SYSTEM-Level Command Execution on Microsoft Servers
Crafted SVGs submitted to Bing's image search could run commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, leading to two critical CVEs: CVE-2026-32194 and CVE-2026-32195.
AI Agents Discovered Redis Zero-Days and Built RCE Exploits
Researchers reported that Kimi K3 AI agents found multiple authenticated RCE zero-days in Redis, leading to seven security releases for versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
Clop Ransomware Targets PTC Windchill and FlexPLM in Data Theft Attacks
The Clop ransomware gang is actively exploiting internet-exposed instances of PTC Windchill and FlexPLM in a new data theft and extortion campaign.
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine
A Russian state-sponsored group, "Laundry Bear," used a zero-day vulnerability in Zimbra's webmail client via "half-click" phishing to steal emails and 2FA codes from Western government and commercial organizations.
ChatGPT AgentForger Flaw Allowed Rogue AI Agent Deployment via Phishing
A critical vulnerability, codenamed AgentForger, in OpenAI's ChatGPT Workspace Agents could have allowed a single phishing link to deploy autonomous AI agents within a victim's organization. OpenAI addressed the issue on June 8.
Australian Energy Giant Origin Energy Confirms Data Breach, 2 Million Customers Affected
Origin Energy confirmed a data breach where a hacker claims to have stolen information belonging to 2 million customers and is threatening to leak it.