← Latest brief

Security news.

·Morning Brief

Today's security landscape is dominated by critical vulnerabilities, with several zero-days and actively exploited flaws requiring immediate attention. Microsoft, VMware, and Adobe have released patches for high-severity issues, while the activity of sophisticated threat actors and ongoing ransomware campaigns remain significant concerns.

SECURITYWEEKZERO-DAY
3d agoREAD

Windows Zero-Day Exploit "ShieldBreak" Released

A new Windows zero-day exploit, "ShieldBreak," dropped on Patch Tuesday, allows any user to gain System privileges by bypassing a Microsoft Defender patch.

SECURITYWEEKEXPLOIT
3d agoREAD

Critical VMware vCenter Vulnerability Actively Exploited

A critical directory traversal bug (CVE-2026–59310) in VMware vCenter is now in attackers' crosshairs, allowing remote attackers to execute arbitrary code.

THN
3d agoREAD

Attackers Exploiting SharePoint Authentication Bypass

Threat actors are actively exploiting CVE-2026-55040, a critical Microsoft SharePoint authentication bypass vulnerability, following the public release of a proof-of-concept.

DARK READINGPATCH
4d agoREAD

Microsoft Patches 421 Vulnerabilities in August Update

Microsoft released its August Patch Tuesday updates addressing 421 vulnerabilities, including 62 critical flaws, one actively exploited zero-day (CVE-2026-68820), and two publicly disclosed zero-days.

SECURITYWEEKRCE
3d agoREAD

WordPress 7.0.4 Patches RCE Vulnerability

WordPress 7.0.4 addresses a remote code execution vulnerability that could be exploited by authenticated attackers with Author-level or higher permissions via malicious Postscript files.

SECURITYWEEKPATCH
3d agoREAD

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Fortinet has released patches for authentication vulnerabilities in FortiWeb and FortiManager that could allow attackers to log in with arbitrary credentials or impersonate FortiGate appliances.

DARK READINGNATION-STATE
3d agoREAD

'Jewelbug' APT Engages in Both State Espionage and Crypto Theft

Researchers have uncovered the "Jewelbug" APT group balancing nation-state cyber espionage with financially motivated cryptocurrency heists using the same command and control infrastructure.

CISCO TALOSPHISHING
3d agoREAD

Cisco Talos Dissects JWR Phishing Framework

Cisco Talos identified an undocumented phishing framework, "JWR," designed to create highly convincing impersonations of checkout and login pages for major payment and shopping platforms.

Generated twice daily from public security RSS feeds. Informational only.