← Latest brief

Security news.

·Morning Brief

Today's cybersecurity news is dominated by widespread exploitation of recently disclosed vulnerabilities, with critical flaws in WordPress, ServiceNow, and Palo Alto VPNs now actively targeted. The evolving landscape of AI security also features prominently, highlighting new attack vectors and the risks associated with AI-generated code and agent-driven systems.

BLEEPINGRANSOMWARE
7h agoREAD

Critical Palo Alto VPN Bug Exploited by Qilin Ransomware

The Qilin ransomware gang is actively exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach networks.

THNEXPLOIT
8h agoREAD

WordPress 'wp2shell' Exploitation Grows

Attackers are increasingly exploiting critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) for unauthenticated remote code execution and website compromise.

SECURITYWEEKAI
8h agoREAD

ServiceNow AI Platform Vulnerability Exploited Days After Disclosure

A critical ServiceNow AI platform vulnerability (CVE-2026-6875) allowing unauthenticated remote code execution is now being actively exploited.

SECURITYWEEKZERO-DAY
6h agoREAD

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

Hackers exfiltrated personal, financial, and health information from Estée Lauder's Oracle EBS instance in August 2025 by exploiting a zero-day flaw.

THNAI
5h agoREAD

Open-Source Android AI Agents Vulnerable to Invisible Screen Text Attacks

Researchers demonstrated how Android apps can trick AI agents into running commands on host PCs using invisible screen text, showcasing seven different attack chains.

MALWARE
READ

HollowGraph Malware Abuses Microsoft 365 Calendar for C&C

A new espionage implant, HollowGraph, uses compromised Microsoft 365 accounts' calendars as a two-way dead-drop for command and control, leveraging legitimate Microsoft Graph API traffic.

THNRANSOMWARE
9h agoREAD

New ENCFORGE Ransomware Targets AI Model Files

Researchers linked a second attack on a Langflow server to the JADEPUFFER operator, which is now deploying ENCFORGE, a new Go ransomware designed to encrypt AI infrastructure files.

DARK READINGAI
4h agoREAD

AI-Generated Coding Risk Varies Significantly

AI-generated code introduces an average of 15 vulnerabilities per codebase, with risk levels heavily dependent on the chosen framework rather than the AI model itself.

Generated twice daily from public security RSS feeds. Informational only.