← Latest brief

Security news.

·Morning Brief

Today's security brief highlights a surge in data breaches and active exploitation of critical vulnerabilities, with several services impacted. We also see continued concerns and observations regarding the use of AI in cyberattacks, from automated exploitation to sophisticated phishing campaigns.

CHECK POINT RESEARCHBREACH
3h agoREAD

Identity Verification Provider IDScan.net Discloses Data Breach

US identity verification provider IDScan.net announced a data breach affecting names and government identification numbers after unauthorized access was detected on September 1.

BLEEPINGBREACH
6h agoREAD

Revolut Discloses Data Breach Exposing Financial Information

Fintech company Revolut has disclosed a data breach where customer financial information and passports were exposed to a threat actor impersonating a government agency.

SECURITYWEEKBREACH
5h agoREAD

Telus Warns Customers of Account Breaches via Stolen Credentials

Canadian telecom giant Telus has warned customers of a multi-month campaign where stolen credentials were used to access subscriber personal data and billing records.

BLEEPINGEXPLOIT
8h agoREAD

CISA Warns of Active Exploitation of Maximum-Severity GitLab Flaw

CISA has added a critical GitLab vulnerability (CVE-2026-85706) to its KEV catalog, warning that hackers are actively exploiting this path traversal flaw that allows unauthenticated users to read arbitrary files.

SECURITYWEEKNATION-STATE
3h agoREAD

Chinese Hackers Exploit Critical Tencent Sogou Input Method Flaw

Chinese state-linked threat actors are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to achieve one-click code execution and deploy GrayRabbit malware.

SECURITYWEEKMALWARE
5h agoREAD

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Multiple vulnerabilities in JFrog Artifactory, including authentication bypass and privilege escalation flaws (CVE-2026-42016, CVE-2026-42018), are being actively exploited to deploy backdoors.

SECURITYWEEKMALWARE
7h agoREAD

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

ConnectWise has patched a vulnerability (CVE-2026-84869) in ScreenConnect that allows attackers to send and execute files without authorization through an active remote session, which has been exploited in worm-like attacks.

BLEEPING
5h agoREAD

Microsoft Confirms September Updates Cause RDS Failures on Windows Server

Microsoft has acknowledged that its September 2026 security updates are leading to Remote Desktop Services (RDS) failures on Windows Server systems, in addition to breaking audio for some Windows PCs.

Generated twice daily from public security RSS feeds. Informational only.