← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is heavily influenced by the escalating use of AI by threat actors, from generating hyper-personalized phishing emails to automating malware development and exploitation. Critical vulnerabilities in widely used software like GitLab and JFrog Artifactory are under active exploitation, highlighting the need for rapid patching and robust defense strategies as CISA adds more flaws to its KEV catalog.

THNRCE
1d agoREAD

GitLab Critical RCE Actively Exploited

A maximum-severity path traversal flaw (CVE-2026-85706) in GitLab's repository commits API is being actively probed and exploited, allowing unauthenticated users to read arbitrary files from affected servers.

CISAKEV
1d agoREAD

CISA Adds JFrog Artifactory, ScreenConnect Flaws to KEV Catalog

CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including two in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018) and one in ConnectWise ScreenConnect (CVE-2026-84869).

BLEEPINGMALWARE
1d agoREAD

JFrog Artifactory Flaws Chained to Deploy Backdoors

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain admin privileges, and install Rust backdoor malware on self-hosted servers.

THNRANSOMWARE
1d agoREAD

Cisco FMC Flaws Exploited by Ransomware and State Actors

Cisco reports that three distinct threat clusters, including ransomware gangs and state-sponsored groups, are exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities, including a critical authentication bypass (CVE-2026-20079).

BLEEPINGPHISHING
1d agoREAD

Passkey-Themed Phishing Leads to Microsoft 365 Data Theft

Threat actors linked to groups like ShinyHunters are using social engineering attacks with passkey and single sign-on themes to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.

SECURITYWEEKAI
1d agoREAD

PaperCut Flaws Exploited in AI-Powered Attacks

A Russian threat actor has leveraged AI to develop, test, and deploy exploits against PaperCut vulnerabilities in hundreds of organizations globally, leading PaperCut to release new security maintenance releases.

BLEEPINGBREACH
1d agoREAD

Florida DMV Database Breached via Stolen Police Account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach of its DAVID driver database, where attackers gained access using credentials stolen from a police department employee.

SECURITYWEEKPHISHING
1d agoREAD

Trezor Reports 347,000 Users Targeted in Phishing After Brevo Hack

Hardware wallet provider Trezor announced that 347,000 users were targeted in phishing attacks, with 2,500 clicking malicious links, following the compromise of its marketing platform, Brevo.

Generated twice daily from public security RSS feeds. Informational only.