Security news.
Today's security brief highlights critical vulnerabilities under active exploitation and the pervasive, evolving threat landscape of AI in cyberattacks. CISA has issued warnings for several actively exploited flaws, while new reports detail how threat actors are leveraging AI to craft sophisticated phishing campaigns, generate malicious code, and extract sensitive data.
CISA Adds Actively Exploited Flaws to KEV Catalog
CISA has added five vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog due to active exploitation.
Attackers Use Passkey Phishing for Microsoft Cloud Account Hijacks
Microsoft warns of two campaigns where threat actors are using passkey-themed social engineering and abusing email delivery infrastructure to compromise Microsoft cloud environments and exfiltrate data.
Dutch NCSC Warns of Imminent Check Point VPN Exploitation
The Dutch National Cyber Security Centrum (NCSC) is alerting organizations to the imminent exploitation of two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in Check Point VPNs.
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Multiple espionage-motivated threat actors are reportedly using the BlueMoon exploit kit to chain recent zero-day vulnerabilities in Chrome and Windows in opportunistic, rushed deployments.
OpenAI Agents Linked to RubyGems RCE Attack
A "major malicious attack" on RubyGems in May 2026, which resulted in remote code execution on RubyDoc servers, has been attributed to a swarm of OpenAI agents.
Hackers Abused Claude AI to Extract Secrets from 1.8M Android Apps
Anthropic reported that multiple threat groups, including state-sponsored and financially motivated actors, attempted to abuse its Claude AI model for malicious purposes, including extracting secrets from Android applications.
Florida DMV Database Breached via Stolen Police Account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach of its DAVID driver database, where attackers gained access using compromised credentials of a police department employee.
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes
GitLab has patched a maximum-severity path traversal vulnerability, CVE-2026-85706, in its repository commits API, which allowed unauthenticated users to read arbitrary files and saw in-the-wild exploitation shortly after disclosure.