← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity landscape is marked by widespread exploitation of critical vulnerabilities, particularly in AI-related tools and infrastructure, alongside significant data breaches impacting millions. Attackers are quickly leveraging newly disclosed flaws, while healthcare organizations continue to be a prime target for data exfiltration.

BLEEPINGAI
Sep 1READ

Critical Langflow Flaw Actively Exploited to Steal AI and Cloud Credentials

Threat actors are exploiting CVE-2026-0768, an unauthenticated remote code execution vulnerability in Langflow, to steal OpenAI and AWS keys and tokens.

THNEXPLOIT
Sep 1READ

Attackers Exploit Critical JFrog Artifactory Flaw Days After Disclosure

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory, leading to administrative access, is being actively exploited merely days after public disclosure.

BLEEPINGBREACH
Sep 1READ

Malicious Virtualizor Update Pushed via BGP Hijacking

Hackers delivered malicious updates to the Virtualizor VPS management software by hijacking BGP routing for its update infrastructure, redirecting requests to malicious servers.

BLEEPINGBREACH
Sep 1READ

Aesto Health Data Breach Impacts Over 9.5 Million Patients

Aesto LLC, operating as Aesto Health, disclosed a data breach that exposed the information of more than 9.5 million individuals.

BLEEPINGBREACH
Sep 1READ

PaperCut Zero-Days Now Used in Data Theft Attacks

Two recently patched zero-day vulnerabilities (CVE-2026-82078 and CVE-2026-81578) in PaperCut NG and MF print management software are being actively abused for data theft.

DARK READINGBREACH
Sep 1READ

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

A ClickFix campaign is actively compromising 31 organizations and using EtherHiding to dynamically update its command-and-control server by abusing the Polygon blockchain.

THNAI
Sep 1READ

Attackers Steal METR AI API Key, Consume $600,000 in Credits

METR, an AI research non-profit, disclosed security incidents where external actors stole an API key, leading to approximately $600,000 in unauthorized AI credit consumption.

BLEEPINGBREACH
Sep 1READ

Nearly 22,000 Microsoft Exchange Servers Vulnerable to Hijack Attacks

Approximately 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability, risking mailbox hijacking.

Generated twice daily from public security RSS feeds. Informational only.