← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is marked by active exploitation of critical vulnerabilities, sophisticated phishing campaigns, and data breaches. Threat actors are leveraging new techniques, including in-browser malware assembly and AI-powered automation, underscoring the need for vigilant patching and robust security measures.

THNRCE
9h agoREAD

Fastjson 1.x RCE Vulnerability Under Active Attack

Attackers are targeting CVE-2026-16723, a critical remote code execution flaw in Alibaba's Fastjson library (CVSS 9.0), affecting unpatched Spring Boot applications.

THNRCE
12h agoREAD

Cl0p Affiliates Exploit PTC Windchill and FlexPLM for RCE

Threat actors linked to the Cl0p ransomware group are exploiting pre-authentication information disclosure and server-side flaws in internet-exposed PTC Windchill and FlexPLM to achieve unauthenticated remote code execution.

BLEEPINGMALWARE
7h agoREAD

Malvertising Campaign Builds Malware in Browser Memory

A large-scale malvertising campaign is using malicious JavaScript on fake Solana, Luno, and TradingView sites to assemble malware directly in browser memory, avoiding traditional detection.

THNRCE
12h agoREAD

GitLab RCE PoC Released for Unpatched Servers

A working exploit (CVE-2026-16723) has been published for a GitLab flaw, allowing authenticated users to run commands as 'git' on self-managed servers not updated to version 18.11.3 or higher.

CISAKEV
3d agoREAD

CISA Adds Two Vulnerabilities to KEV Catalog

CISA has added CVE-2026-16232 (Check Point SmartConsole Improper Authentication) and CVE-2026-50522 (Microsoft SharePoint Deserialization of Untrusted Data) to its Known Exploited Vulnerabilities Catalog, urging immediate patching.

BLEEPINGBREACH
8h agoREAD

ShinyHunters Data Leaks Fuel $2,000 Sextortion Scams

Email addresses exposed in data breaches by the ShinyHunters group are being used by threat actors to send sextortion emails demanding $2,000 in Bitcoin.

BLEEPINGBREACH
1d agoREAD

OnTrac Notifies Customers of Data Breach

The parcel delivery company OnTrac is informing customers that hackers breached its corporate network, potentially accessing personal details.

BLEEPINGBREACH
1d agoREAD

Hackers Hijack Hotel Wi-Fi DNS for Microsoft 365 Account Theft

Threat actors are manipulating DNS settings on Wi-Fi devices in hotels and conference centers to redirect users to fake Microsoft 365 login pages and steal credentials.

Generated twice daily from public security RSS feeds. Informational only.