← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is dominated by multiple critical vulnerabilities and active exploitation, including a Windows zero-day leveraged by the Lazarus Group and a SharePoint flaw quickly exploited after a PoC release. Additionally, a new wave of fake Chrome VPN extensions highlights ongoing threats to user privacy and browser security.

THNZERO-DAY
4d agoREAD

Lazarus Group Exploits Windows Zero-Day (CVE-2026-68820) in Operation Dream Job

The North Korean Lazarus Group is actively exploiting a newly patched Windows zero-day vulnerability to deploy a novel backdoor, targeting defense and aerospace companies globally.

BLEEPINGEXPLOIT
4d agoREAD

SharePoint Vulnerability Actively Exploited After PoC Release

Hackers have quickly begun exploiting a critical Microsoft SharePoint vulnerability (patched in July) after a proof-of-concept exploit was publicly released.

BLEEPING
4d agoREAD

"Plug and Pwn" Attacks Gain Windows SYSTEM Access via Fake USBs

New "Plug and Pwn" attacks abuse the Windows Plug and Play feature to trick systems into installing vulnerable vendor software, allowing attackers to achieve SYSTEM privileges.

BLEEPING
4d agoREAD

737 Fake Chrome VPN Extensions Route User Traffic Through Proxies

Hundreds of browser extensions on the Chrome Web Store impersonated legitimate VPN services to route users' traffic through SOCKS5 proxies operated by a single provider, primarily targeting Russian-speaking users.

THNVULN
4d agoREAD

Attackers Exploiting VMware vCenter Vulnerability for Persistent Remote Access

Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter, to execute arbitrary code and gain persistent remote access.

BLEEPINGZERO-DAY
4d agoREAD

New Microsoft Defender "ShieldBreak" Zero-Day Grants SYSTEM Privileges

A new Microsoft Defender zero-day exploit, "ShieldBreak," has been released, demonstrating a patch bypass for CVE-2026-50656 ("RoguePlanet") and granting SYSTEM privileges.

DARK READINGRANSOMWARE
4d agoREAD

Colombian Justice Ministry Hit by Ransomware

The Ministry of Justice in Colombia suffered a ransomware attack just days before a presidential transition, impacting government operations and mirroring increased cyberattack activity across Latin America.

SECURITYWEEKPATCH
4d agoREAD

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe released critical updates addressing multiple vulnerabilities, including three CVSS 10.0 flaws in ColdFusion and Campaign Classic that could lead to arbitrary code execution and privilege escalation.

Generated twice daily from public security RSS feeds. Informational only.