CISA placed three severe Ubiquiti UniFi OS vulnerabilities and one critical Lantronix command injection flaw into its Known Exploited Vulnerabilities catalog on June 23, 2026, after confirming active attacks. Federal agencies must apply patches or mitigations within three days under BOD 26-04, while Bishop Fox demonstrated the Ubiquiti issues can be chained for full remote code execution and released a free detection script.

Security researchers at Bishop Fox later showed the flaws can be combined to reach full remote code execution with elevated privileges on affected UniFi OS devices.
CISA has not shared any details about the observed exploitation of any of the four flaws, while the "use in ransomware campaigns" flag was set to "Unknown" for all of them.
Organizations running UniFi OS should prioritize the May patches immediately, as chaining these three flaws grants unauthenticated root access with minimal effort.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Google is set to implement lower Play Store fees and external payment options in Europe, the UK, and the US starting June 30 as part of its Epic Games settlement. The changes introduce a 10 percent service fee on the first $1 million in annual earnings for small developers and expand globally through 2027.
Anthropic has introduced Claude Tag for Slack, enabling the model to act as a proactive colleague that joins discussions, handles tasks in sequence, posts results in threads, operates in ambient mode and schedules its own reminders. Internally the company now generates 65 percent of its code with the tool while administrators retain token caps to manage spending.
Qualcomm is nearing a deal to acquire Modular for nearly $4 billion in a stock-and-cash transaction that would bring the startup's entire team onboard. The reported purchase would accelerate Qualcomm's move into broader AI software platforms and data-center chips beyond its traditional mobile business.