← Latest brief

Security news.

·Morning Brief

Today's security brief highlights critical vulnerabilities under active exploitation, significant data breaches impacting millions, and the ongoing evolution of AI in both defensive and offensive cybersecurity. Patching remains crucial, with several zero-days reported, while nation-state actors continue sophisticated campaigns.

BLEEPINGZERO-DAY
14h agoREAD

Fastjson RCE Zero-Day Actively Exploited

Hackers are actively exploiting a critical remote code execution vulnerability in the Fastjson open-source Java library, allowing unauthenticated RCE.

BLEEPINGZERO-DAY
15h agoREAD

Arista VeloCloud Orchestrator Zero-Day Exploited

A maximum-severity OS command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, with CISA adding it to its KEV catalog.

THNVULN
6h agoREAD

Critical TeamCity Flaw Allows OS Command Execution

JetBrains has patched a critical security vulnerability (CVE-2026-63077, CVSS 9.8) in on-premise TeamCity versions that could lead to arbitrary code execution without authentication.

BLEEPINGVULN
2h agoREAD

24,000+ Servers Expose Password Hashes via Old BMC Flaw

Over 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.

SECURITYWEEKBREACH
9h agoREAD

Origin Energy Data Breach Affects 900,000 Australians

Origin Energy confirmed a data breach claimed by hackers, potentially impacting up to 2 million customers, with details of 900,000 Australians confirmed stolen.

BLEEPINGBREACH
5h agoREAD

Medical Billing Firm MCBS Breach Affects 1.26 Million

Medical Computer Business Services (MCBS) disclosed a network breach from 2025 that exposed the sensitive information of over 1.2 million individuals.

THNNATION-STATE
2h agoREAD

Iranian APT Nimbus Manticore Uses New Backdoor

The Iranian state-backed group Nimbus Manticore (aka GalaxyGato) is using a new Windows backdoor, NightLedger, and custom WebSocket tunnelers in attacks targeting the Middle East, Africa, and South Asia.

DARK READINGAI
13h agoREAD

AI Agent Used in Espionage Attack on Thai Ministry of Finance

Attackers leveraged Hermes, an autonomous open-source AI tool in "YOLO mode," to conduct espionage against Thailand's Ministry of Finance.

Generated twice daily from public security RSS feeds. Informational only.