
Velvet Ant Linux Login Backdoors: Check PAM and OpenSSH
Sygnia says Velvet Ant replaced Linux PAM and OpenSSH components in a long-running intrusion. Hosting admins should verify login-stack integrity before rotating credentials.

Sygnia says Velvet Ant replaced Linux PAM and OpenSSH components in a long-running intrusion. Hosting admins should verify login-stack integrity before rotating credentials.

Arch AUR users should review recent AUR builds after the Atomic Arch campaign hijacked orphaned packages to deliver credential-stealing malware.

Patch self-hosted LangGraph deployments for SQLite, msgpack, and Redis checkpointer flaws, then review checkpoint stores, secrets, network access, and AI workflows.

Update phpBB forums to 3.3.17 after a critical authentication bypass report, then test login, OAuth, admin access, backups, and forum moderation workflows.

Update the Palo Alto Networks CommvaultSecurityIQ Marketplace integration for Cortex XSOAR and Cortex XSIAM to 1.2.0 or later for CVE-2026-0274.

Patch Splunk Enterprise CVE-2026-20253 by upgrading to 10.2.4, 10.0.7, or a later fixed release, then verify search, forwarding, apps, and access controls.

CISA KEV now lists Oracle PeopleSoft CVE-2026-35273. Apply Oracle mitigation guidance, restrict HTTP exposure, review logs, and plan patch work.

Update Langflow after CVE-2026-5027, rebuild deployed containers, restrict exposed AI app servers, and review files, logs, secrets, and workflow access.

Patch Ivanti Sentry to R10.5.2, R10.6.2, or R10.7.1 after CISA KEV listing, then review exposed gateways, administrator accounts, logs, mobile traffic, and customer access.

CISA added Arista EOS CVE-2026-7473 to KEV on June 9, 2026. Patch affected EOS switches, review VXLAN/GRE decapsulation exposure, and verify fabric behavior.