← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity landscape is dominated by critical vulnerabilities and the increasing use of AI in attacks. CISA has added five new actively exploited flaws to its KEV catalog, while major vendors scramble to patch high-severity issues. The pervasive influence of AI is evident, with threat actors leveraging it for everything from advanced exploit kits to large-scale data theft and even weapons development, posing new challenges for defenders.

THNKEV
11h agoREAD

CISA Adds 5 Actively Exploited Flaws to KEV Catalog

CISA has added five security flaws affecting JFrog Artifactory (CVE-2026-42016), ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation.

BLEEPINGEXPLOIT
13h agoREAD

Imminent Exploitation of Critical Check Point VPN Flaws Warned

The Dutch NCSC is warning of imminent exploitation of two critical vulnerabilities (CVE-2026-85102, CVE-2026-85103) in Check Point VPN products.

SECURITYWEEKEXPLOIT
16h agoREAD

BlueMoon Exploit Kit Chaining Recent Chrome, Windows Zero-Days

Espionage-motivated threat actors are reportedly using the BlueMoon exploit kit to chain recent zero-day vulnerabilities in Chrome and Windows for opportunistic, rushed deployments.

THNRCE
18h agoREAD

OpenAI Agents Linked to RubyGems RCE Attack

A "major malicious attack" on RubyGems in May 2026, which gained RCE on RubyDoc servers, has been linked to a swarm of OpenAI agents, highlighting the evolving threat landscape with AI.

THNEXPLOIT
1d agoREAD

GitLab Critical File-Read Flaw (CVSS 10) Exploited After Disclosure

GitLab has patched a maximum-severity path traversal vulnerability (CVE-2026-85706, CVSS 10.0) that allows unauthenticated users to read arbitrary files and was probed in-the-wild hours after disclosure.

BLEEPINGBREACH
1d agoREAD

Florida DMV Database Breached via Stolen Police Account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach of its DAVID driver database, where attackers gained access using stolen credentials of a police department employee.

BLEEPINGPHISHING
1d agoREAD

Passkey-Themed Phishing Leads to Microsoft 365 Data Theft

Threat actors, including groups like ShinyHunters and Helix, are using passkey and single sign-on themed social engineering to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.

BLEEPINGMALWARE
1d agoREAD

Artifactory Flaws Chained to Deploy Backdoor Malware

Threat actors are actively exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.

Generated twice daily from public security RSS feeds. Informational only.