CVE Feed
- CVE-2026-47224 – NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check June 12, 2026
- CVE-2026-47222 – NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser via unsigned integer underflow June 12, 2026
- CVE-2026-53982 – Capgo Console < 12.28.2 Account Deletion DoS via Device Identifier Association June 12, 2026
- CVE-2026-9641 – Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations June 12, 2026
- CVE-2026-5792 – Authentication Bypass in Related Digital's Related Marketing Cloud (RMC) June 12, 2026
- CVE-2026-8828 – ChromaDB Authorization Bypass June 12, 2026
- CVE-2026-9638 – Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts June 12, 2026
- CVE-2026-53568 – Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value' June 12, 2026
- CVE-2026-50086 – Aqara unauthenticated AES oracle June 12, 2026
- CVE-2026-50087 – Aqara IAM/SSO Gateway cross-origin resource sharing June 12, 2026
- CVE-2026-50089 – Aqara IAM/SSO Gateway open redirect June 12, 2026
- CVE-2026-50090 – Aqara OAuth redirect_uri validation bypass June 12, 2026
- CVE-2026-50091 – Aqara Home Android SDK hardcoded keys June 12, 2026
- CVE-2026-50560 – Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature June 12, 2026
- CVE-2026-50085 – Aqara Board IoT insecure debug API June 12, 2026
- CVE-2026-50088 – Aqara Developer Portal cross-origin resource sharing June 12, 2026
- CVE-2026-50009 – Netty QUIC stateless reset token material exposed through header-visible connection IDs June 12, 2026
- CVE-2026-50011 – Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length June 12, 2026
- CVE-2026-50010 – Netty's wrapping plain trust manager silently disables hostname verification June 12, 2026
Microsoft Security
- Turn specs into evals for any agent with ASSERT June 10, 2026Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared first on Microsoft Security Blog.Mehrnoosh Sameki, Sandeep Atluri, Minsoo Thigpen and Abby Palia
- Reconstructing AI activity in investigations June 9, 2026Learn how to investigate AI activity in Microsoft 365 Copilot and Azure AI services using a structured, telemetry-driven approach. This playbook helps security teams reconstruct events, assess data exposure, and detect potential threats faster. The post Reconstructing AI activity in investigations appeared first on Microsoft Security Blog.Phillip Misner and Microsoft AI Red Team
- AI brands as bait: How threat actors are using the AI hype in social engineering June 8, 2026As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog.Microsoft Threat Intelligence and Microsoft Defender Security Research Team
- Securing CI/CD in an agentic world: Claude Code Github action case June 5, 2026Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows. The post Securing CI/CD in an agentic world: Claude Code Github action case appeared first […]Microsoft Defender Security Research Team, Dor Edry and Amit Eliahu
- Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us June 4, 2026A surge in real-world attacks against agentic AI systems is reshaping how we think about risk. Based on 12 months of red teaming, this update introduces seven new failure modes, from supply chain compromise to goal hijacking, and the practical mitigations teams need now. The post Updating the taxonomy of failure modes in agentic AI […]Microsoft AI Red Team



