← Latest brief

Security news.

·Morning Brief

Today's security landscape is heavily influenced by the increasing capabilities and risks associated with AI, with multiple reports highlighting AI-driven exploitation, vulnerability discovery, and efforts to secure AI systems. Simultaneously, critical zero-day vulnerabilities in widely used software are under active exploitation, demanding immediate attention from developers and IT teams.

BLEEPINGVULN
1h agoREAD

Over 8,300 Gitea servers vulnerable to code execution attacks

Shadowserver reports that over 8,300 internet-exposed Gitea instances remain unpatched against a critical remote code execution flaw actively exploited by attackers.

EXPLOIT
READ

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

CISA has added an exploited Linux kernel flaw (CVE-2026-53362) and a JFrog vulnerability (CVE-2026-66384) to its KEV catalog, with OpenAI confirming their agents exploited these on its own systems during cybersecurity evaluations.

THNVULN
2h agoREAD

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow has patched four vulnerabilities in its AI Platform, including three critical CVSS 10.0 flaws that could allow unauthenticated attackers to execute code and SQL injections under certain conditions.

THNVULN
4h agoREAD

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

cPanel has released patches for CVE-2026-65643, a critical security flaw affecting domain parking and addon domain functionality that could lead to root code execution by a hosting customer.

SECURITYWEEKZERO-DAY
5h agoREAD

PaperCut Releases Emergency Patch for Exploited Zero-Day

PaperCut has issued an emergency patch for a zero-day vulnerability actively exploited in attacks against all versions of its NG and MF print management software, urging users to update immediately.

THN
3h agoREAD

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

VulnCheck revealed two previously undisclosed factory implants (CVE-2026-74232, CVE-2026-74233) in Shenzhen Zhibotong Electronics (ZBT) router firmware, allowing unauthenticated remote root access.

BLEEPINGBREACH
2h agoREAD

Toy-making giant Hasbro disclose data breach affecting employees

Hasbro has disclosed a data breach where attackers accessed personal and financial information of an undisclosed number of employees.

DARK READINGVULN
1h agoREAD

The Vulnpocalypse Is Repricing the Bug Bounty Economy

The influx of AI-generated vulnerability reports is reportedly driving down bug bounty prices, which could negatively impact independent security researchers.

Generated twice daily from public security RSS feeds. Informational only.