SysBlue Cyber Solutions

SysBlue Cyber Solutions Sysblue is an information security consulting and managed cybersecurity services firm with headquarters in Romania.

We help clients solve information security challenges based on risk, not fear.

 Microsoft working on Defender patch for RoguePlanet zero-day.Microsoft confirmed that it's working on a security patch ...
17/06/2026



Microsoft working on Defender patch for RoguePlanet zero-day.

Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago.

The security researcher who published a RoguePlanet exploit during the June 2026 Patch Tuesday (known as Nightmare Eclipse) said it affects fully patched Windows 10 and Windows 11 devices and allows attackers to spawn command prompts with SYSTEM privileges via a Microsoft Defender race condition.

Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago.

 Critical Fortinet FortiSandbox flaws now exploited in attacks.Attackers are now exploiting several critical vulnerabili...
16/06/2026



Critical Fortinet FortiSandbox flaws now exploited in attacks.

Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused.

Fortinet released security updates for these three critical-severity security flaws (tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089) on April 14.

Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused.

 FBI disrupts massive AI-powered phishing service using a million URLs.In a coordinated effort, the FBI, working with Go...
15/06/2026



FBI disrupts massive AI-powered phishing service using a million URLs.

In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.

The cybercrime operation used AI and distributed phishing kits for campaigns impersonating various trusted brands in texts sent through AT&T, T-Mobile, and Verizon.

In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.

 Max severity Ivanti Sentry vulnerability now exploited in attacks.Attackers are now targeting a recently patched maximu...
11/06/2026



Max severity Ivanti Sentry vulnerability now exploited in attacks.

Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways.

Formerly known as MobileIron Sentry, the Ivanti Sentry security gateway appliance secures traffic between back-end corporate systems and remote mobile devices.

Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways.

 Ivanti: Max severity Sentry flaw allows code ex*****on as root.Security software company Ivanti has released patches to...
10/06/2026



Ivanti: Max severity Sentry flaw allows code ex*****on as root.

Security software company Ivanti has released patches to address two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with root privileges.

Formerly known as MobileIron Sentry, Ivanti Sentry is a security gateway appliance that secures traffic between back-end corporate systems and remote mobile devices.

Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with root privileges.

 Google patches new Chrome zero-day flaw exploited in the wild.Google has released emergency updates to patch another Ch...
09/06/2026



Google patches new Chrome zero-day flaw exploited in the wild.

Google has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year.

"Google is aware that an exploit for CVE-2026-11645 exists in the wild," the company said in a Monday security advisory.

Google has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year.

 WhatsApp says it disrupted new NSO spyware phishing attacks.WhatsApp has detected and stopped spear-phishing campaigns ...
08/06/2026



WhatsApp says it disrupted new NSO spyware phishing attacks.

WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks.

The NSO Group is an Israeli commercial spyware vendor known for its advanced “Pegasus” tool that has been deployed against politicians, activists, journalists, academics, and other “high-interest” individuals.

WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks.

 C0XMO botnet spreads via DD-WRT router flaw, kills rival malware.A new variant of the Gafgyt botnet called C0XMO is tar...
07/06/2026



C0XMO botnet spreads via DD-WRT router flaw, kills rival malware.

A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.

The researchers found samples for ARM, MIPS, PowerPC, SuperH, x86, x86_64, and other architectures, featuring exploits for DVRs, routers, video management platforms, and Android-based devices.

A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.

 Critical Everest Forms Pro flaw exploited to take over WordPress sites.Hackers are actively exploiting a critical vulne...
06/06/2026



Critical Everest Forms Pro flaw exploited to take over WordPress sites.

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.

The security issue affects versions 1.9.12 and earlier of the plugin and can be leveraged without authentication to execute arbitrary code on the server.

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.

 Chinese APT deploys new malware to keep access to hacked networks.A Chinese espionage group tracked as UNC5221 has been...
05/06/2026



Chinese APT deploys new malware to keep access to hacked networks.

A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD.

An investigation into the incident revealed that the threat actor had gained access to the victim network at least 18 months before detection, and had also compromised the victim organization's managed services provider (MSP).

A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD.

Address

București
Bucharest
030171

Alerts

Be the first to know and let us send you an email when SysBlue Cyber Solutions posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share