← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is dominated by critical patching efforts, with Microsoft addressing hundreds of vulnerabilities including actively exploited zero-days. Additionally, Cisco has issued warnings about an actively exploited VPN flaw, and threat actors continue to innovate with sophisticated social engineering and ransomware tactics.

SECURITYWEEKZERO-DAY
5d agoREAD

Microsoft August Patch Tuesday Fixes Exploited Zero-Day and 421 CVEs

Microsoft released updates addressing 421 vulnerabilities, including a Windows kernel-mode driver use-after-free bug (afd.sys) that has been actively exploited to gain SYSTEM privileges.

BLEEPINGEXPLOIT
4d agoREAD

Cisco Warns of Actively Exploited VPN Flaw in ASA and FTD

Cisco is alerting users to a high-severity denial-of-service vulnerability in its Secure Firewall ASA and Threat Defense (FTD) software, which is being actively exploited to remotely crash affected VPN devices.

BLEEPINGPATCH
5d agoREAD

Microsoft August Patch Tuesday Addresses 400 Flaws, 3 Zero-Days

Microsoft's August 2026 Patch Tuesday includes fixes for 400 vulnerabilities, with one actively exploited zero-day and two publicly disclosed zero-days across its product line.

SECURITYWEEKPATCH
5d agoREAD

Adobe Urges Immediate Patching for Critical ColdFusion and Campaign Classic Flaws

Adobe has released urgent patches for critical vulnerabilities in ColdFusion and Campaign Classic that could lead to arbitrary code execution and denial-of-service.

THNMALWARE
5d agoREAD

Sandworm-Linked Group Uses Fake Job Interviews to Distribute Malware

The Russian nation-state threat actor UAC-0145 (a subgroup of Sandworm) is conducting social engineering campaigns using fake job interviews to trick IT workers into installing malicious VPN software capable of running commands.

THNRANSOMWARE
5d agoREAD

DeadLock Ransomware Leverages Polygon Smart Contracts for Resilience

The DeadLock ransomware group is utilizing decentralized infrastructure, including Polygon smart contracts and the Session messaging network, to enhance the resilience of their victim communication and data leak operations.

SECURITYWEEKPATCH
5d agoREAD

Zoom Patches Zero-Click Code Execution Vulnerability

Zoom has released a patch for a zero-click code execution vulnerability impacting its annotation feature, which could allow a meeting participant to execute code on another participant’s machine.

THNRCE
5d agoREAD

AI-Assisted Exploit Chain Achieves Unauthenticated RCE in SharePoint

Security researchers, with the help of an AI agent, discovered an unauthenticated Remote Code Execution (RCE) chain (CVE-2026-55040) in Microsoft SharePoint Server Subscription Edition, 2019, and 2016.

Generated twice daily from public security RSS feeds. Informational only.