← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity news is dominated by a record-breaking Patch Tuesday from Microsoft and a stark warning about China's industrial-scale AI model "distillation" efforts. Multiple critical vulnerabilities are under active exploitation, highlighting the ongoing threat landscape for IT teams and developers.

KREBSEXPLOIT
4d agoREAD

Microsoft Patches a Record 974 Security Holes, Including Actively Exploited Zero-Days

Microsoft released its largest-ever Patch Tuesday, addressing 974 vulnerabilities across its products, with two actively exploited zero-days and 113 critical flaws.

THNZERO-DAY
3d agoREAD

Google Chrome V8 Zero-Day (CVE-2026-87491) Actively Exploited

Google patched 230 vulnerabilities in Chrome, including a critical out-of-bounds write flaw in the V8 JavaScript engine (CVE-2026-87491) that is currently under active exploitation.

CISAKEV
3d agoREAD

CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog

CISA updated its Known Exploited Vulnerabilities (KEV) Catalog with four new entries, including critical flaws in Fortinet, Citrix NetScaler (CVE-2026-19490), Google Chromium V8 (CVE-2026-87491), and Microsoft Windows.

CISCO TALOSEXPLOIT
3d agoREAD

Active Exploitation of Cisco Secure Firewall Management Center Vulnerabilities

Cisco Talos is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) software, urging users to apply patches immediately.

THNEXPLOIT
3d agoREAD

Four Spy Groups Used BlueMoon Exploit Kit for Chrome and Windows

Multiple state-sponsored espionage groups, including China-aligned APT31, have been observed deploying a new exploit kit named "BlueMoon" that chains vulnerabilities in Microsoft Windows and Google Chrome.

THNAI
3d agoREAD

US Accuses Chinese AI Firms of "Industrial-Scale Distillation" of Frontier AI Models

U.S. cybersecurity and intelligence agencies accuse China-based AI companies of systematically extracting proprietary functionalities and capabilities from American frontier models like Claude, GPT, Gemini, and Grok through "distillation attacks."

MICROSOFT SECURITY BLOGPHISHING
3d agoREAD

Passkey-Themed Social Engineering Leads to Identity and Cloud Compromise

Threat actors are leveraging passkey-themed social engineering to compromise user identities, establish MFA persistence, and abuse Microsoft Graph for reconnaissance, ultimately accessing SharePoint, OneDrive, and email data.

THNVULN
3d agoREAD

Critical cPanel Flaw (CVE-2026-41940) Allows Root Code Execution

cPanel has patched a critical vulnerability (CVE-2026-41940) that could allow an authenticated hosting account with mail-related privileges to create arbitrary files and execute code as the root user, compromising the entire server.

Generated twice daily from public security RSS feeds. Informational only.