Amazon EKS now supports customer-routed control plane egress

Today’s signal AWS What’s New recently reported Amazon EKS now supports customer-routed control plane egress. Published context: June 18, 2026. Today, Amazon Elastic Kubernetes Service (Amazon EKS) introduces customer-routed control plane egress, a capability that lets you route outbound Kubernetes API server traffic through your own Amazon VPC. This includes admission webhook callbacks, OpenID Connect (OIDC) provider lookups, and aggregate API server requests. With customer-routed control plane egr The reason this matters is simple: buyers are paying attention to speed, operational resilience, and credible technical execution. A trending story can create awareness, but the business question is what a team should do with that attention. ...

June 19, 2026 · 3 min · David Gomez

Announcing Web Search on Amazon Bedrock AgentCore for Agentic Web Retrieval

Today’s signal AWS What’s New recently reported Announcing Web Search on Amazon Bedrock AgentCore for Agentic Web Retrieval. Published context: June 16, 2026. As AI agents become more capable, they need access to information beyond a model’s training data - to answer questions, retrieve latest facts, and take action grounded in current developments. Today, we’re making that easy with the general availability of Web Search on AgentCore. Web Search is a fully managed tool that enables agents to ground responses in c ...

June 18, 2026 · 3 min · David Gomez

The Top 10 Attack Surface Exposures in 2026

Today’s signal The Hacker News recently reported The Top 10 Attack Surface Exposures in 2026. Published context: June 17, 2026. Breaches don’t always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk. Wit ...

June 17, 2026 · 3 min · David Gomez

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Today’s signal The Hacker News recently reported Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week. Published context: June 16, 2026. Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability ...

June 16, 2026 · 3 min · David Gomez

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Today’s signal The Hacker News recently reported Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw. Published context: June 15, 2026. Palo Alto Networks has revealed that it has observed “active exploitation” of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS softwar ...

June 15, 2026 · 3 min · David Gomez

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Today’s signal The Hacker News recently reported Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication. Published context: June 13, 2026. Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. “In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user ...

June 14, 2026 · 3 min · David Gomez

Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE

Today’s signal The Hacker News recently reported Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE. Published context: June 10, 2026. A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of path traversal that could allow an attacker to write files to arbitrar ...

June 13, 2026 · 3 min · David Gomez

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

Today’s signal The Hacker News recently reported ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities. Published context: June 11, 2026. The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google’s Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory un ...

June 12, 2026 · 3 min · David Gomez

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Today’s signal The Hacker News recently reported Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities. Published context: June 10, 2026. Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It’s tracked as CVE-2026- ...

June 11, 2026 · 3 min · David Gomez

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Today’s signal The Hacker News recently reported Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now. Published context: June 9, 2026. Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Chrome’s JavaScript and WebAssembly engine. “Out-of-bounds read and write in V8 in Goog ...

June 10, 2026 · 3 min · David Gomez

How to Reduce Your AWS Bill: A Practical Cost-Optimization Guide

AWS bills creep. A proof-of-concept that became production, an oversized instance nobody resized, a dev environment running 24/7 - it adds up quietly until someone finally asks “why are we paying this much?” The good news: most AWS overspend comes from a short list of fixable causes. Here’s how to reduce your AWS bill, roughly in order of effort-to-savings ratio. Want a senior set of eyes on your account? See managed cloud teams, book a free call, or grab the free AWS checklist. ...

June 10, 2026 · 5 min · David Gomez