← Latest brief

Security news.

·Afternoon Brief

Today's security brief highlights critical vulnerabilities under active exploitation, including a Cisco SD-WAN zero-day and a WordPress plugin flaw. We also see continued activity from botnets and ransomware groups, alongside new developments in AI-driven security and privacy concerns.

BLEEPINGMALWARE
Jun 7READ

C0XMO botnet exploits DD-WRT router flaw

A new Gafgyt botnet variant, C0XMO, is actively targeting DD-WRT router firmware and can spread to other device types.

BLEEPING
Jun 7READ

Silent Ransom Group targets law firms with fake IT support calls

The Silent Ransom Group is using social engineering, often leading to data theft within hours, to target U.S. law firms and professional services organizations.

BLEEPINGEXPLOIT
Jun 6READ

Critical Everest Forms Pro flaw exploited in WordPress sites

Hackers are actively exploiting CVE-2026-3300, a critical vulnerability in the Everest Forms Pro plugin, to gain full control of WordPress websites.

THNAI
Jun 6READ

New ChatGPT Lockdown Mode limits data exfiltration risks

OpenAI is rolling out a "Lockdown Mode" for ChatGPT personal accounts to reduce data exfiltration risks from prompt injection attacks, aimed at users handling sensitive data.

THNKEV
Jun 6READ

CISA adds actively exploited SolarWinds Serv-U DoS flaw to KEV

CISA has added CVE-2026-28318, a high-severity denial-of-service flaw in SolarWinds Serv-U, to its Known Exploited Vulnerabilities catalog due to active exploitation.

THNMALWARE
Jun 6READ

Miasma Worm hits 73 Microsoft GitHub repositories

The Miasma self-replicating supply chain attack campaign has impacted 73 Microsoft GitHub repositories, leading GitHub to disable access to them.

ZERO-DAY
READ

Cisco Catalyst SD-WAN Manager zero-day actively exploited

Cisco has warned of active exploitation of a high-severity, unpatched zero-day (CVE-2026-20245) in its Catalyst SD-WAN Manager, allowing root privilege escalation.

BLEEPING
Jun 5READ

Over 900 US gas station tank gauge systems exposed to attacks

More than 900 automatic tank gauge (ATG) systems in the U.S., used in critical infrastructure, are exposed online and vulnerable to ongoing attacks.

Generated twice daily from public security RSS feeds. Informational only.