← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is marked by multiple data breaches affecting major companies and government entities, alongside ongoing exploitation of critical vulnerabilities. Attackers are leveraging compromised credentials for cloud breaches and weaponizing recently disclosed flaws, highlighting the persistent need for rapid patching and robust access controls.

BLEEPINGBREACH
3h agoREAD

Hacker Claims 3.6 Million Azure Account Records Stolen

A threat actor is allegedly selling employee databases stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies, including McDonald’s, TCS, and Vodafone, after gaining access using compromised credentials.

SECURITYWEEKBREACH
15h agoREAD

Fortune 500 Companies Hit in Azure Data Theft Campaign

This campaign involves the alleged exfiltration of millions of records from various large organizations, underscoring the severe impact of compromised credentials on cloud environments.

CISAKEV
10h agoREAD

CISA Adds Ray-Project Ray Code Injection to KEV Catalog

CISA has added CVE-2025-62593, a Ray-Project Ray Code Injection Vulnerability, to its Known Exploited Vulnerabilities Catalog, urging immediate remediation for federal agencies due to active exploitation.

BLEEPINGZERO-DAY
13h agoREAD

Microsoft Working on Defender Patch for ShieldBreak Zero-Day

Microsoft is actively developing a security patch for the "ShieldBreak" zero-day vulnerability (CVE-2026-69414), publicly disclosed last week and now under active investigation.

THNRCE
4h agoREAD

Critical Forminator WordPress Plugin Flaw Allows Unauthenticated RCE

A critical vulnerability, CVE-2026-15748 (CVSS 9.8), in the Forminator Forms WordPress plugin (600,000+ installs) could allow unauthenticated remote code execution via malicious PHP uploads.

SECURITYWEEKEXPLOIT
14h agoREAD

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

CVE-2026-58231, a critical flaw in SAP Commerce Cloud allowing arbitrary code execution, was exploited just three days after its disclosure, highlighting the speed of threat actors.

THNRANSOMWARE
15h agoREAD

China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

A suspected China-nexus APT group is exploiting CVE-2026-59310, a severe directory-traversal vulnerability in VMware vCenter, to execute arbitrary code and deploy Babuk-derived ransomware.

BLEEPINGBREACH
12h agoREAD

French Tax Authority Data Breach Affects 678,000 Individuals

The French Ministry of the Economy and Finance disclosed a data breach at the General Directorate of Public Finances (DGFiP), where an attacker accessed and stole data belonging to 678,000 individuals using compromised credentials.

Generated twice daily from public security RSS feeds. Informational only.