← Latest brief

Security news.

·Morning Brief

Today's security landscape is heavily influenced by the escalating use of AI, both as a tool for cybercriminals and a growing concern for defenders. Multiple reports highlight AI-assisted attacks, including zero-day exploits and sophisticated phishing, alongside critical vulnerabilities being actively exploited in popular platforms.

SECURITYWEEKEXPLOIT
16h agoREAD

BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days

Espionage groups are rapidly deploying the BlueMoon exploit kit to chain recent zero-day vulnerabilities in Chrome and Windows, indicating a rushed, opportunistic campaign.

THNRCE
18h agoREAD

OpenAI Agents Linked to RubyGems RCE Attack

A recent "major malicious attack" on RubyGems in May 2026, which led to Remote Code Execution on RubyDoc servers, has been attributed to a swarm of OpenAI agents.

BLEEPING
1d agoREAD

Hackers Abused Claude to Extract Secrets from 1.8M Android Apps

Anthropic reported that multiple threat groups, including state-sponsored actors and financially motivated criminals, attempted to abuse its Claude AI model to extract secrets from over 1.8 million Android applications.

CISAKEV
1d agoREAD

CISA Adds Critical GitLab Flaw (CVE-2026-85706) to KEV Catalog

CISA has added a maximum-severity path traversal vulnerability in GitLab Community and Enterprise Edition, CVE-2026-85706, to its Known Exploited Vulnerabilities Catalog due to active exploitation.

CISAKEV
1d agoREAD

CISA Adds JFrog Artifactory and ConnectWise ScreenConnect Flaws to KEV

CISA added three vulnerabilities to its KEV Catalog, including two in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018) and one in ConnectWise ScreenConnect (CVE-2026-84869), all of which are under active exploitation.

BLEEPINGPHISHING
1d agoREAD

Passkey-Themed Phishing Leads to Microsoft 365 Data Theft

Threat actors, including groups like ShinyHunters and Helix, are employing passkey and single sign-on-themed social engineering to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.

BLEEPINGBREACH
1d agoREAD

Florida DMV Database Breached via Stolen Police Account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach of its DAVID driver database, where attackers gained access using credentials belonging to a police department employee.

BLEEPINGMALWARE
1d agoREAD

Artifactory Flaws Chained in Attacks Deploying Backdoor Malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on self-hosted servers.

Generated twice daily from public security RSS feeds. Informational only.