← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is marked by significant data breaches, critical vulnerabilities requiring immediate patching, and a rise in sophisticated social engineering attacks. Supply chain risks, particularly within the npm ecosystem, and the growing weaponization of AI by threat actors also remain prominent concerns for developers and IT teams.

BLEEPINGBREACH
2h agoREAD

Unlimited Technology Systems Breach Impacts 3.8 Million People

Healthcare software company Unlimited Technology Systems reported a data breach from October 2025 affecting over 3.8 million individuals.

SUPPLY CHAIN
READ

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A new campaign has flooded the npm registry with almost 800 malicious packages, using typo-squatting names to distribute a powerful RAT and infostealer targeting Windows, Mac, and Linux systems.

PATCH
READ

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress has patched a pre-authentication reflected cross-site scripting (XSS) flaw (CVE-2026-64638, CVSS 8.9) in its login screen, which can be chained to achieve PHP code execution on the server.

CISAKEV
10h agoREAD

CISA Adds Progress LoadMaster Command Injection Vulnerability (CVE-2026-8037) to KEV Catalog

CISA has added Progress LoadMaster Command Injection Vulnerability, CVE-2026-8037, to its Known Exploited Vulnerabilities Catalog, urging federal agencies to remediate it due to active exploitation.

BREACH
READ

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are deploying a Go-based macOS malware capable of stealing cryptocurrency, browser passwords, Apple iCloud Keychain data, and cached credentials.

PHISHING
READ

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

The data extortion group UNC6671 is conducting vishing attacks, posing as IT help desk staff to target financial, private equity, and professional services employees via their personal phones for SaaS data theft.

BLEEPING
6h agoREAD

Levi Strauss & Co. Says Hackers Stole Corporate Data in Cyberattack

Levi Strauss & Co. disclosed that hackers used social engineering to compromise three employees, gaining access to and stealing corporate data from their machines.

VULN
READ

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free bug in Linux's SCTP networking code, present since 2008, allows local users to gain root privileges and escape containers; fixes have been released in recent stable kernels.

Generated twice daily from public security RSS feeds. Informational only.