← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is marked by a flurry of critical vulnerabilities, including multiple zero-days actively exploited or with public PoCs, alongside significant data breaches and the continued evolution of AI-driven malware. Organizations are urged to prioritize patching and bolster defenses against sophisticated attacks leveraging novel techniques.

BLEEPINGZERO-DAY
2h agoREAD

ShinyHunters Claims FBI Hack via PeopleSoft Zero-Day

The ShinyHunters extortion gang alleges it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, reportedly accessing internal services and stealing sensitive employee and applicant data.

THNZERO-DAY
2h agoREAD

Check Point Warns of Actively Exploited Management Server Zero-Day (CVE-2026-93616)

Check Point has released a fix for a critical zero-day vulnerability in its Security Management Server (CVE-2026-93616) that allows unauthenticated script execution, which attackers exploited in targeted attacks.

THNPATCH
3h agoREAD

WordPress Patches Critical Code Execution Flaw

WordPress has released version 7.1.2 to fix a critical vulnerability that could allow an unauthenticated attacker to force a site to load external PHP files, potentially leading to remote code execution on some servers.

THNZERO-DAY
5h agoREAD

New Zero-Day PoC Blocks Microsoft Defender Updates

A security researcher released a proof-of-concept tool, "BigDiskBuster," that exploits a zero-day to fill disk space, preventing Microsoft Defender from installing platform and signature updates.

BLEEPINGAI
3h agoREAD

ClosedQuorum Windows Malware Uses AI for Attack Decisions

A novel Windows malware, ClosedQuorum, integrates Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously make decisions during the post-compromise stages of an attack.

THNPHISHING
4h agoREAD

Microsoft Disrupts EvilTokens AI-Assisted Phishing Service

Microsoft, in collaboration with industry partners, has dismantled the EvilTokens device-code phishing-as-a-service platform, which utilized AI at every stage and compromised over 12,000 Microsoft inboxes.

BLEEPINGZERO-DAY
8h agoREAD

D-Link Warns of Max Severity Zero-Day in DIR-822A Routers (CVE-2026-86296)

D-Link has issued a warning regarding a maximum-severity zero-day vulnerability (CVE-2026-86296) with public exploit code affecting its legacy DIR-822A Wi-Fi routers, with no patch currently available.

THNEXPLOIT
8h agoREAD

Critical VeloCloud Orchestrator Flaw (CVE-2026-93952) Actively Exploited

An unauthenticated remote command injection vulnerability (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) is being actively exploited, particularly affecting certificate-based setups.

Generated twice daily from public security RSS feeds. Informational only.