← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is marked by critical vulnerability exploits and the growing complexity introduced by AI. Several zero-day flaws are under active attack, alongside ongoing sophisticated espionage and financial fraud campaigns by threat groups. Organizations are urged to prioritize patching and bolster defenses against these evolving threats.

BLEEPINGZERO-DAY
3d agoREAD

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released emergency patches for "LegacyHive," a Windows zero-day actively exploited to gain SYSTEM access, following its public disclosure post-July Patch Tuesday.

BLEEPINGRCE
3d agoREAD

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical VMware vCenter Syslog Server vulnerability (CVE-2026-59310) allowing remote code execution is being actively exploited to deploy reverse SSH tools for persistence.

THNEXPLOIT
3d agoREAD

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors are actively exploiting CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, following the release of proof-of-concept code.

BLEEPINGBREACH
3d agoREAD

Hackers breach govt webmail while running parallel crypto fraud

The Jewelbug hacker group is performing espionage operations against governments and militaries while simultaneously engaging in cryptocurrency fraud, using shared infrastructure.

BLEEPINGBREACH
3d agoREAD

Trezor discloses data breach affecting nearly 14,000 customers

Hardware wallet manufacturer Trezor reported a data breach impacting nearly 14,000 customers due to a hack at its shipping provider, ShipMonk.

BLEEPINGBREACH
3d agoREAD

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing campaign named "City-Forum" is using custom tools to steal data exposed to anonymous users via Salesforce Experience Cloud and ServiceNow customer portals.

THNAI
4d agoREAD

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

A newly disclosed flaw in AI API calls from OpenAI, Anthropic, and Google allowed researchers to recover internal reasoning and secrets like API keys and passwords from session logs.

SECURITYWEEKPATCH
3d agoREAD

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Fortinet has released patches for vulnerabilities in FortiWeb and FortiManager that could allow attackers to log in with random credentials or impersonate FortiGate appliances.

Generated twice daily from public security RSS feeds. Informational only.