← Latest brief

Security news.

·Morning Brief

Today's cybersecurity landscape is marked by widespread exploitation of critical vulnerabilities in popular software like Oracle WebLogic and Zimbra. Threat actors are also actively employing sophisticated phishing campaigns and novel malware techniques, highlighting the persistent need for rapid patching and robust security measures.

SECURITYWEEKEXPLOIT
6h agoREAD

CISA Warns of Actively Exploited Oracle WebLogic Vulnerability

CISA has added a maximum-severity flaw, CVE-2026-21962, in Oracle HTTP Server and WebLogic Server to its KEV catalog due to widespread active exploitation, allowing unauthenticated attackers to access critical data.

BLEEPINGBREACH
2h agoREAD

Hackers Breached Over 270 Zimbra Servers in Ongoing Attacks

Threat actors have compromised over 270 Zimbra instances by exploiting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability, CVE-2026-73570, which CISA has ordered federal agencies to patch urgently.

THNPHISHING
2h agoREAD

Mirage2FA Phishing Campaign Hits 4,500 US and EU Companies

The Mirage2FA phishing-as-a-service toolkit is abusing Microsoft 365 login flows to bypass two-factor authentication, potentially compromising 48% of targeted email addresses, primarily in the US.

THNVULN
5h agoREAD

Attackers Target miniOrange SAML Flaws for WordPress Admin Access

Bad actors are actively attempting to exploit two severe unauthenticated authentication bypasses (CVE-2026-61979 and CVE-2026-61980) in the miniOrange SAML 2.0 Single Sign On plugin, allowing login as any WordPress user, including administrators.

SECURITYWEEKMALWARE
3h agoREAD

First Malware Built Specifically for Car Head Units Fuels Botnet

Kaspersky researchers have identified the first malware specifically designed for car head units, linking it to the BadBox botnet which has compromised millions of devices.

THNMALWARE
2h agoREAD

E4del and PINHOLE RATs Use FTP Banners as Dead Drops for Malware Commands

A new campaign is employing FTP banners as dead drop resolvers to deliver two previously unreported remote access trojans, E4del and PINHOLE, showcasing a novel method for command-and-control infrastructure.

SECURITYWEEK
1h agoREAD

WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update

WhatsApp is enhancing its account security by introducing support for multiple passkeys and stronger two-step verification, aiming to provide users with more robust protection against unauthorized access.

BLEEPINGPOLICY
3h agoREAD

Police Arrest Dozens of Suspects in Global Cybercrime Crackdown

Law enforcement agencies from 22 countries collaborated to identify 263 suspects and arrest 58 individuals linked to cybercrime networks coordinated by African crime groups.

Generated twice daily from public security RSS feeds. Informational only.