← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is dominated by a surge in active exploitation, with multiple critical vulnerabilities added to CISA's KEV catalog. Major vendors like Apple and Microsoft have released extensive patches, while AI continues to feature prominently in both offensive and defensive cybersecurity discussions, highlighting evolving threats and the race for control over this technology.

BLEEPINGEXPLOIT
14h agoREAD

CISA Warns of Active Exploitation of Maximum-Severity GitLab Flaw

CISA has added a critical GitLab vulnerability (CVE-2026-85706) to its Known Exploited Vulnerabilities Catalog, urging immediate patching due to active attacks.

THNKEV
2d agoREAD

CISA Adds Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

Five security vulnerabilities affecting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018), ConnectWise ScreenConnect (CVE-2026-84869), and MikroTik RouterOS (CVE-2026-67277, CVE-2026-86060) have been added to CISA's KEV catalog due to active exploitation.

THNRCE
4h agoREAD

Red Heron Exploits Gitea RCE to Compromise 13 Organizations

A suspected Chinese threat actor, Red Heron, is rapidly exploiting a recently disclosed Gitea vulnerability to compromise internet-facing instances across six countries, with a focus on Taiwan-based systems.

SANS INTERNET STORM CENTERPATCH
2h agoREAD

Apple Releases Annual Updates, Patches Record 261 Vulnerabilities

Apple has released its annual operating system updates, addressing a record 261 vulnerabilities across iOS/iPadOS, macOS, tvOS, and watchOS, bringing new features and crucial security fixes.

KREBSPATCH
5d agoREAD

Microsoft Plugs Nearly 1,000 Security Holes in Record Patch Tuesday

Microsoft's September Patch Tuesday includes fixes for a record 974 security vulnerabilities, with 113 rated critical, highlighting the escalating volume of discovered flaws, partly attributed to AI-assisted discovery.

BLEEPINGBREACH
2h agoREAD

Hackers Hijack HBO Max Reddit Account to Push ClickFix Malware

The official HBO Max Reddit account was compromised and used to spread malicious ads leading to ClickFix attacks, infecting Windows and macOS devices with information-stealing malware.

BLEEPING
2h agoREAD

Twitch Extension with 30K Installs Exposes Users’ OAuth Tokens

A malicious browser extension named "Twitch Enhanced Viewer | JeetBot" has been found sending users' Twitch OAuth session tokens to a commercial bot service, affecting nearly 31,000 users.

THN
3h agoREAD

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Researchers have revealed "DDRop," a new hardware attack that bypasses memory protection in Intel and AMD's confidential computing technologies by silently dropping memory writes, leading to the use of stale encrypted data.

Generated twice daily from public security RSS feeds. Informational only.