← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity landscape highlights a surge in active exploitation, particularly targeting WordPress, SharePoint, and Palo Alto Networks VPNs, with CISA adding several to its Known Exploited Vulnerabilities Catalog. Ransomware groups are quickly leveraging newly disclosed flaws, while AI continues to be a double-edged sword, assisting in both vulnerability discovery and new attack vectors.

BLEEPINGEXPLOIT
5h agoREAD

Critical wp2shell WordPress flaws actively exploited

Hackers are exploiting critical vulnerabilities CVE-2026-63030 and CVE-2026-60137 in WordPress Core to install persistent webshells and malicious plugins.

RCE
READ

Critical SharePoint RCE (CVE-2026-50522) under active exploitation

A critical deserialization of untrusted data flaw in Microsoft Office SharePoint, patched in July 2026, is now being actively exploited following a public Proof-of-Concept.

BLEEPINGRANSOMWARE
11h agoREAD

Qilin ransomware exploiting critical Palo Alto VPN bug

The Qilin ransomware gang is leveraging a critical PAN-OS GlobalProtect authentication bypass flaw (CVE-2026-0257) to breach networks and deploy their ransomware.

CISAKEV
9h agoREAD

CISA adds four vulnerabilities to KEV Catalog

CISA has added CVE-2021-27137, CVE-2026-0770, CVE-2026-63030, and CVE-2026-60137 to its Known Exploited Vulnerabilities Catalog, urging immediate remediation.

BLEEPINGRANSOMWARE
3h agoREAD

Anubis ransomware claims Coca-Cola Fairlife attack

The Anubis ransomware group has taken credit for a cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to leak stolen data if a ransom is not paid.

THNVULN
5h agoREAD

AWS Kiro flaw allowed poisoned web pages to run code

A vulnerability in AWS's agentic coding IDE, Kiro, allowed hidden text on a web page to rewrite its configuration and execute attacker code on a developer's machine.

DARK READINGAI
3h agoREAD

Hacker turns AI jailbreaks into offensive attack platform

A Russian-speaking actor known as "Trim" has been observed integrating dismantled frontier AI models with offensive security tools to create an attack platform.

RANSOMWARE
READ

New ENCFORGE ransomware targets AI model files

Researchers link a second attack on a Langflow server to the JADEPUFFER operator, now deploying ENCFORGE, a new Go ransomware designed to encrypt AI infrastructure files.

Generated twice daily from public security RSS feeds. Informational only.