← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity landscape is marked by widespread exploitation, with several critical vulnerabilities actively targeted. Threat actors are leveraging everything from authentication bypasses in remote management tools to malicious npm packages and fake software installers, emphasizing the ongoing challenges in software supply chain security and user vigilance.

BLEEPINGEXPLOIT
4h agoREAD

N-able warns of N-central auth bypass flaw exploited in attacks

N-able has issued a warning regarding active exploitation of an authentication bypass vulnerability (CVE-2026-18577) in its N-central servers, affecting both hosted and on-premises deployments.

THNRANSOMWARE
5h agoREAD

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation is reportedly the primary threat actor actively exploiting recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances for initial access and lateral movement.

BLEEPINGBREACH
6h agoREAD

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) led to the compromise and dark web publication of contact data for over 100,000 police officers and criminal justice professionals.

THNSUPPLY CHAIN
3h agoREAD

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Researchers uncovered 18 malicious npm packages, including "lib-mtop," delivering a cross-platform remote access trojan (RAT) to users of Alibaba developer tools in a targeted software supply chain attack.

BLEEPINGMALWARE
2h agoREAD

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Unsuspecting Roblox players are being infected with infostealer and RAT malware through fake "Xeno Executor" installers, providing remote access and stealing sensitive information.

THNBREACH
5h agoREAD

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

New research reveals that malware on a Windows machine can sign into passkey-protected accounts managed by Google Password Manager without user interaction, bypassing PINs or fingerprints.

SECURITYWEEK
13h agoREAD

US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States

Attacks on US water systems, likely by Iran-linked hackers, have extended beyond Minnesota to critical infrastructure in at least six other states, disrupting operations and affecting industrial control systems.

BLEEPINGBREACH
1d agoREAD

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A vulnerability in COLDCARD hardware wallet firmware, specifically in its random number generator, is believed to have led to the theft of approximately $88.6 million in Bitcoin from thousands of wallets.

Generated twice daily from public security RSS feeds. Informational only.