← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is marked by urgent patch requirements and active exploitation of critical vulnerabilities, particularly in widely used platforms like WordPress and JFrog Artifactory. We're also seeing significant activity in AI security, with new tools and initiatives emerging to combat AI-assisted threats and secure AI development, alongside ongoing challenges from sophisticated phishing campaigns and supply chain attacks.

BLEEPINGVULN
Sep 2READ

Hackers Exploiting Critical JFrog Artifactory Flaw

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is actively being exploited to forge administrator tokens, granting attackers full control.

BLEEPINGVULN
Sep 2READ

WordPress Backup Plugin Flaw Exposes Millions to Takeover Attacks

An SQL injection vulnerability in the popular All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to execute remote code and compromise millions of WordPress sites.

BLEEPINGZERO-DAY
Sep 2READ

SonicWall Warns of Actively Exploited SMA1000 Zero-Day Flaws

SonicWall has released updates for two zero-day vulnerabilities (CVE-2026-83548, CVE-2026-83549) in its Secure Mobile Access (SMA) 1000 series VPN appliances, which are being chained for remote code execution in active attacks.

CISAKEV
Sep 2READ

CISA Adds Seven New Actively Exploited Vulnerabilities to KEV Catalog

CISA has added seven vulnerabilities to its Known Exploited Vulnerabilities Catalog, including SQL Injection, HTTP Request Smuggling, and OS Command Injection flaws in various products like Sangoma Switchvox and Kestra OSS.

THNBREACH
Sep 2READ

BGP Hijack Delivers Malicious Virtualizor Update for Root Access

Hackers used a BGP hijack to divert Softaculous traffic, delivering a malicious Virtualizor package that led to root-level compromise on some hypervisors.

DARK READINGPHISHING
Sep 2READ

"Spring Ring" Vishing Attacks Target Microsoft Teams Users

The "Spring Ring" operation is conducting vishing attacks to compromise Microsoft Teams users, aiming to remotely access sessions, spread malware, and potentially take over infrastructure.

THN
Sep 2READ

Fake Software Installers Disable Windows Update, Weaken Microsoft Defender

An active malware campaign is using bogus software download websites to distribute malicious installers that disable Windows Update and weaken Microsoft Defender, primarily targeting organizations and users in China.

THNAI
Sep 2READ

Google, Anthropic, and OpenAI Unveil Cyber AI Models and Safeguards

Major AI developers have announced new cybersecurity-focused AI models and safeguards, with Google introducing Gemini 3.8 Flash Cyber for trusted defenders and OpenAI's Astra model demonstrating the ability to find and exploit zero-days.

Generated twice daily from public security RSS feeds. Informational only.