← Latest brief

Security news.

·Morning Brief

Today's security brief highlights critical vulnerabilities, with Cl0p affiliates actively exploiting flaws in PTC Windchill and FlexPLM, and a researcher publishing a PoC for a GitLab RCE. Several organizations, including OnTrac and Chick-fil-A, have also reported data breaches. The ongoing discussion around AI security and its implications for cyberattacks remains a key theme.

THNRCE
4h agoREAD

Cl0p Affiliates Target PTC Windchill and FlexPLM with RCE

Threat actors linked to the Cl0p ransomware are exploiting unauthenticated RCE flaws in internet-exposed PTC Windchill and FlexPLM deployments for data extortion.

THNRCE
4h agoREAD

GitLab RCE PoC Published for Unpatched Servers

A working exploit has been released for a GitLab flaw (patched six weeks ago), allowing authenticated users to run commands as git on self-managed servers running version 18.11.3 without the update.

THN
4h agoREAD

DevMan RaaS Portal Centralizes Operations

The DevMan ransomware-as-a-service (RaaS) scheme uses a dedicated web platform for affiliates to build payloads, manage victims, and oversee earnings, tracked as "Funky Mantis."

BLEEPINGBREACH
18h agoREAD

OnTrac Notifies Customers of Data Breach

The parcel delivery company OnTrac is informing customers about a data breach on its corporate network that may have exposed personal details.

BLEEPINGBREACH
1d agoREAD

Chick-fil-A Data Breach Affects Over 13,000 Customers

Chick-fil-A confirmed that over 13,000 customer accounts were compromised in credential stuffing attacks targeting its website and mobile app between June 17 and June 19.

THNPHISHING
4h agoREAD

Insurance Phishing Evolves to Real-Time Account Hijacking

Research by CTM360 shows that insurance-focused phishing campaigns are moving from credential harvesting to immediate account compromises.

SECURITYWEEKPATCH
6h agoREAD

Rockwell Patches Code Execution Flaws in Arena Simulation Software

Rockwell Automation has released patches for code execution vulnerabilities in its Arena Simulation Software that could be exploited to target industrial organizations.

CISA
2d agoREAD

Russian State-Supported Actors Target Zimbra Collaboration Suite

CISA warns that Russian state-supported cyber actors have been targeting Western government and commercial organizations using Zimbra Collaboration Suite (ZCS) software since at least July 2025.

Generated twice daily from public security RSS feeds. Informational only.