← Latest brief

Security news.

·Morning Brief

Today's security landscape highlights critical vulnerabilities in widely used software and applications, alongside significant data breaches impacting global users and critical infrastructure. The increasing role of AI in both defense and offense is a recurring theme, with new flaws and exploits emerging in AI agents and models.

SANS INTERNET STORM CENTEREXPLOIT
4d agoREAD

WordPress Core SQL Injection (CVE-2026-63030) Under Active Exploitation

A critical SQL injection vulnerability in WordPress Core, leading to unauthenticated remote code execution, is currently being actively exploited. All WordPress versions before 4.14.0 are affected.

DARK READINGBREACH
17h agoREAD

Vatican's Official Prayer App Leaks Over 700K Users' PII

A vulnerable API endpoint in the Vatican's official prayer app exposed names, email addresses, location, and site status of more than 700,000 global users.

THNVULN
18h agoREAD

Bing Images Flaws Allowed SYSTEM-Level Command Execution on Microsoft Servers

Crafted SVGs submitted to Bing's image search could run commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, leading to two critical CVEs: CVE-2026-32194 and CVE-2026-32195.

THNRCE
23h agoREAD

AI Agents Discovered Redis Zero-Days and Built RCE Exploits

Researchers reported that Kimi K3 AI agents found multiple authenticated RCE zero-days in Redis, leading to seven security releases for versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

BLEEPINGRANSOMWARE
22h agoREAD

Clop Ransomware Targets PTC Windchill and FlexPLM in Data Theft Attacks

The Clop ransomware gang is actively exploiting internet-exposed instances of PTC Windchill and FlexPLM in a new data theft and extortion campaign.

DARK READINGZERO-DAY
1d agoREAD

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine

A Russian state-sponsored group, "Laundry Bear," used a zero-day vulnerability in Zimbra's webmail client via "half-click" phishing to steal emails and 2FA codes from Western government and commercial organizations.

THNPHISHING
18h agoREAD

ChatGPT AgentForger Flaw Allowed Rogue AI Agent Deployment via Phishing

A critical vulnerability, codenamed AgentForger, in OpenAI's ChatGPT Workspace Agents could have allowed a single phishing link to deploy autonomous AI agents within a victim's organization. OpenAI addressed the issue on June 8.

SECURITYWEEKBREACH
1d agoREAD

Australian Energy Giant Origin Energy Confirms Data Breach, 2 Million Customers Affected

Origin Energy confirmed a data breach where a hacker claims to have stolen information belonging to 2 million customers and is threatening to leak it.

Generated twice daily from public security RSS feeds. Informational only.