← Latest brief

Security news.

·Morning Brief

Today's security news features a mix of critical vulnerabilities, active exploitation, and ongoing research into AI-driven threats. Multiple vendors, including D-Link and Zyxel, have released advisories for severe flaws, with some already under active attack by sophisticated threat actors. The cybersecurity community is also grappling with the implications of AI's role in both attack and defense strategies.

BLEEPINGZERO-DAY
2h agoREAD

D-Link Warns of Max Severity Zero-Day in DIR-822A Routers

D-Link has issued a warning regarding a critical, unpatched zero-day vulnerability (CVE-2026-86296) with public PoC exploit code affecting its legacy DIR-822A Wi-Fi routers.

THNVULN
3h agoREAD

New Linux Kernel Flaw Impacts ARM64 KVM Guests

A newly discovered flaw in the Linux kernel's KVM virtualization code (CVE-2026-89775) for ARM64 processors allows KVM guests to gain read-write access to host memory, potentially leading to guest escape and host code execution.

BLEEPINGZERO-DAY
5h agoREAD

New Windows Defender Zero-Day Blocks Antivirus Updates

A security researcher released a new Microsoft Defender zero-day exploit that prevents the antivirus from receiving updates, leaving systems vulnerable.

SECURITYWEEKNATION-STATE
3h agoREAD

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

A Chinese threat actor has actively exploited a vulnerability in nearly 1,000 ZyXEL switches, exfiltrating sensitive information. CISA has added this flaw (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog.

THNRCE
4h agoREAD

SharePoint Flaw Enables Authenticated RCE, Not Just Spoofing

A SharePoint Server vulnerability (CVE-2026-65660), initially downplayed by Microsoft as a spoofing flaw, has been revealed to enable authenticated remote code execution across SharePoint Server 2016, 2019, and Subscription Edition.

THNRCE
9h agoREAD

WordPress Patches 'Comment2Shell' RCE Vulnerability

WordPress has patched a critical "Comment2Shell" flaw (CVE-2026-93485) that could allow an anonymous attacker to achieve remote code execution on a site's server via a hidden script in a comment, triggered by an authenticated administrator.

CISCO TALOSAI
5h agoREAD

The Closed Quorum: Inside the First Autonomous AI C2 Implant

Cisco Talos has discovered CLOSEDQUORUM, a malware binary exhibiting fully autonomous command and control (C2), representing a significant shift towards AI-integrated malware that can execute attack chains without direct operator involvement.

SECURITYWEEKSUPPLY CHAIN
3h agoREAD

Malicious B-tree NPM Package Accumulates Millions of Downloads

The malicious npm package "indexed-btree" mimicked the legitimate "sorted-btree" and hid its malware trigger within a prototype method, accumulating millions of downloads before its removal.

Generated twice daily from public security RSS feeds. Informational only.