← Latest brief

Security news.

·Morning Brief

Today's security brief highlights critical vulnerabilities, active exploitation, and significant legal actions against cybercriminals. AI-related risks, including zero-click browser hijacking and token jacking, continue to be a prominent theme, alongside important patches from major vendors like Cisco and JetBrains.

RCE
READ

CISA Flags TeamCity RCE Flaw (CVE-2026-63077) Under Active Exploitation

CISA has added a critical JetBrains TeamCity vulnerability (CVE-2026-63077) to its Known Exploited Vulnerabilities Catalog, warning of active exploitation for remote code execution.

SECURITYWEEKAI
3h agoREAD

Zero-Click AI Browser Hacking Affects Claude and ChatGPT

Researchers uncovered unpatched zero-click vulnerabilities allowing threat actors to hijack AI browsers like Claude and ChatGPT Atlas through malicious emails and X posts.

THN
4h agoREAD

CryptoJS Weak RNG Leads to $5.7 Million in Crypto Wallet Drains

A weak random number generator in the 12-year-old CryptoJS library, specifically `CryptoJS.lib.WordArray.random()`, has been linked to over $5.7 million in crypto wallet drains due to insufficient entropy for generating recovery phrases.

THN
4h agoREAD

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

A security flaw in Apple's iCloud Private Relay, introduced with iOS 15, can potentially expose users' real IP addresses through WebKit proxy bypasses, despite its dual-hop architecture designed for privacy.

UNIT 42AI
5h agoREAD

Token Jacking: Cybercriminals Stealing AI Resources

Attackers are exploiting vulnerabilities to hijack AI tokens and developer API keys, fueling gray market transfer stations and stealing AI resources.

THN
6h agoREAD

Attackers Compile 'khunt' Toolkit Inside Oracle for Windows SYSTEM Access

Threat actors exploited a SQL injection vulnerability in a public-facing web application to breach an Oracle database and compile the "khunt" post-exploitation toolkit directly within the database engine, achieving Windows SYSTEM access.

SECURITYWEEKRANSOMWARE
6h agoREAD

Ransom Cartel Mastermind Sentenced to 16 Years in Prison

Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware-as-a-service operation, has been sentenced to 16 years in prison for his involvement in attacks against at least 18 companies.

SECURITYWEEKPATCH
8h agoREAD

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Cisco has released patches for two dozen vulnerabilities across its SD-WAN, IOS XE, and FMC products, including a critical bug with public proof-of-concept code.

Generated twice daily from public security RSS feeds. Informational only.