← Latest brief

Security news.

·Afternoon Brief

Today's security news highlights a flurry of data breaches, ongoing ransomware campaigns, and significant developments in AI security. Organizations like Coca-Cola and Ernst & Young have confirmed data thefts, while a critical vBulletin flaw has a public exploit available. On the AI front, NVIDIA is leading a new alliance to secure AI, and the challenges of managing "shadow AI" agents are coming to light.

THNEXPLOIT
7h agoREAD

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

A public exploit has been released for a pre-authentication code execution flaw in vBulletin versions 6.2.1 and earlier, and 6.1.6 and earlier, allowing unauthenticated attackers to execute code without user interaction.

BLEEPINGBREACH
6h agoREAD

Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang

The ShinyHunters gang has claimed responsibility for a data breach at Ernst & Young, stating they obtained system credentials through a supply-chain attack.

BLEEPINGRANSOMWARE
6h agoREAD

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack

The Coca-Cola Company has confirmed that data was stolen from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month, with the Anubis group claiming responsibility.

SECURITYWEEKRANSOMWARE
8h agoREAD

PTC Windchill Vulnerability Exploited in Ransomware Campaign

A critical unsafe deserialization flaw in PTC Windchill is being actively exploited in ransomware campaigns, allowing unauthenticated remote code execution.

BLEEPINGBREACH
4h agoREAD

Apple Sued Over Fake App Store Crypto Wallet App Stealing $1.8M in Bitcoin

Apple faces a lawsuit from users who claim $1.8 million in Bitcoin was stolen after they downloaded a fraudulent Sparrow Wallet application from the official App Store.

THNAI
3h agoREAD

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA, along with 36 other organizations including Microsoft and Cisco, has formed the Open Secure AI Alliance to develop open technologies and tools for securing software and AI agents.

BLEEPINGAI
7h agoREAD

Shadow AI Agents Are Multiplying: Here's How to Find and Secure Them

"Shadow AI" agents are rapidly spreading across enterprise platforms without IT or security visibility, posing risks through unmanaged permissions and autonomous actions.

THNMALWARE
4h agoREAD

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

The Dysphoria IoT botnet has evolved to use blockchain-based name services and infected-device relays, making it more resilient to disruption after a recent law enforcement operation.

Generated twice daily from public security RSS feeds. Informational only.