← Latest brief

Security news.

·Morning Brief

Today's cybersecurity news is dominated by critical vulnerabilities, with multiple zero-days actively exploited across various platforms including Arista VeloCloud, F5 BIG-IP APM, and Check Point Management Servers. Patches have been released for several high-impact flaws, while a new cPanel vulnerability allows root access, and an unpatched Ubuntu kernel flaw enables container escapes. The pervasive theme of AI also continues, with new AI-powered malware and ongoing discussions about AI safety and autonomous agents.

BLEEPINGZERO-DAY
2h agoREAD

Arista Patches Actively Exploited VeloCloud Orchestrator Zero-Day

Arista Networks has released patches for an actively exploited zero-day flaw affecting VeloCloud Orchestrator (VCO) On-Prem deployments.

THNVULN
3h agoREAD

New cPanel Flaw Lets Hosting Account Run Code as Root

A critical flaw in cPanel's CalDAV and CardDAV service allows any hosting account to run code as root and take full server control, with fixes released.

THNEXPLOIT
4h agoREAD

Exploit Released for Unpatched Ubuntu Linux Flaw

An exploit has been released for CVE-2026-80521, a use-after-free flaw in the Linux kernel's AF_UNIX socket subsystem, allowing container escapes to gain root on the host, which remains unpatched in several Ubuntu LTS releases.

THNZERO-DAY
6h agoREAD

F5 Patches Critical BIG-IP APM Zero-Day Exploited for RCE

F5 has released hotfixes for CVE-2026-94127, a critical flaw in BIG-IP Access Policy Manager (APM) being actively exploited for unauthenticated remote code execution on OAuth authorization servers.

THNZERO-DAY
6h agoREAD

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP

A Chinese threat actor (UTA0565) exploited a zero-day chain involving Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) and a Windows flaw (CVE-2026-85880) to deploy CLEANGULP malware.

SECURITYWEEKZERO-DAY
9h agoREAD

Check Point Patches Exploited Management Server Zero-Day

Check Point has released a fix for CVE-2026-93616, a critical-severity zero-day in its Security Management Server that allowed unauthenticated attackers to upload and execute arbitrary scripts in targeted attacks.

SECURITYWEEKPATCH
3h agoREAD

Adobe Patches Critical Flaws in Connect, AEM Forms

Adobe has released patches addressing nine critical security defects in Connect and AEM Forms that could lead to arbitrary code execution and privilege escalation.

SECURITYWEEKPHISHING
4h agoREAD

AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

Microsoft has disrupted EvilTokens, a cybercrime platform that leveraged AI at every step of the attack chain, from generating social engineering messages to selecting targets.

Generated twice daily from public security RSS feeds. Informational only.