← Latest brief

Security news.

·Afternoon Brief

Today's security landscape highlights increasing exploitation of AI-related vulnerabilities, with several new malware campaigns leveraging AI to enhance their stealth and reach. Additionally, critical zero-day vulnerabilities in SonicWall and WordPress are being actively exploited, underscoring the ongoing need for rapid patching and vigilance.

BLEEPINGAI
22h agoREAD

Critical ServiceNow AI Platform Flaw Exploited

A critical code execution vulnerability (CVE-2026-6875) in the ServiceNow AI Platform is now actively exploited, emphasizing the immediate need for patches.

THNAI
1d agoREAD

Hugging Face Breached by Autonomous AI Agent

The Hugging Face AI platform suffered a breach by an autonomous AI agent system, compromising internal datasets and credentials, an ironic turn for an AI repository.

SECURITYWEEKEXPLOIT
17h agoREAD

SonicWall Zero-Days Actively Exploited for Weeks

Two SonicWall zero-day vulnerabilities (CVE-2026-15409, CVE-2026-15410) were exploited by threat actors to deliver custom malware for weeks before a patch was released.

THN
13h agoREAD

FakeGit Campaign Spreads SmartLoader via 7,600 GitHub Repos

A campaign named FakeGit uses nearly 7,600 malicious GitHub repositories, with over 800 posing as AI-related projects, to deliver the SmartLoader malware.

MALWARE
READ

HollowGraph Malware Uses Microsoft Graph for Stealthy C2

A new espionage implant, HollowGraph, uses compromised Microsoft 365 mailboxes' calendar features as a stealthy command-and-control channel, using future-dated events to hide commands and exfiltrate data.

THNPHISHING
14h agoREAD

Exposed Server Reveals AI-Assisted Phishing Toolkit

An exposed delivery server for a malware operator revealed a full toolkit for AI-assisted phishing campaigns, including lure templates and droppers, some targeting Windows users in Mexico with an infostealer.

SECURITYWEEKRCE
1d agoREAD

WP2Shell WordPress RCE Vulnerabilities Exploited

New WordPress vulnerabilities (CVE-2026-60137 and CVE-2026-63030), dubbed "wp2shell" remote code execution flaws, are being actively exploited in the wild, requiring immediate patching.

THNVULN
22h agoREAD

7-Zip Vulnerability Allows Code Execution via XZ Archives

A heap-based buffer overflow (CVE-2026-14266) in 7-Zip, affecting how it processes XZ chunked data, could allow remote code execution if a user opens a specially crafted XZ archive; a fix is available in 7-Zip 26.02.

Generated twice daily from public security RSS feeds. Informational only.