← Latest brief

Security news.

·Afternoon Brief

Threat actors continue targeting identity and edge infrastructure, underscored by massive cryptocurrency theft and fresh active exploitation warnings from federal agencies. CISA has added several actively abused flaws across SharePoint, MikroTik, WSO2, and WordPress to its Known Exploited Vulnerabilities catalog. Meanwhile, emerging attack vectors around autonomous AI agents and cloud service principals are creating new challenges for enterprise defenders.

THNNATION-STATE
11h agoREAD

Suspected North Korean Hackers Steal $351.6M from Bitget

Cryptocurrency exchange Bitget reported unauthorized transfers siphoning $351.6 million from its hot and warm wallets in an attack attributed to North Korean threat actors.

CISAKEV
10h agoREAD

CISA Adds SharePoint and MikroTik Flaws to KEV Catalog

CISA warned of active exploitation involving a Microsoft SharePoint code injection bug (CVE-2026-65660) and a MikroTik RouterOS workflow enforcement flaw (CVE-2026-67279), mandating swift federal remediation.

CISAKEV
10h agoREAD

WordPress Core Remote File Inclusion Added to CISA KEV

CISA added an actively exploited WordPress Core vulnerability (CVE-2026-87902) allowing remote file inclusion to its Known Exploited Vulnerabilities catalog.

THNEXPLOIT
17h agoREAD

WSO2 and Adobe Commerce Vulnerabilities Under Active Attack

Federal agencies flagged critical flaws under in-the-wild exploitation, including a CVSS 9.8 path traversal vulnerability in WSO2 products (CVE-2026-5430) and an authorization bypass in Adobe Commerce (CVE-2026-71362).

THNEXPLOIT
11h agoREAD

Roundcube Pre-Auth SQL Injection Exploited in the Wild

Canadian cybersecurity authorities warned that attackers are actively exploiting CVE-2026-48842, an unauthenticated SQL injection vulnerability affecting Roundcube Webmail's virtuser_query plugin.

BLEEPINGVULN
3h agoREAD

Elementor WordPress Plugin Flaw Enables Rogue Admin Creation

A cross-site request forgery vulnerability discovered in the widely used Elementor WordPress plugin allows unauthenticated attackers to trick authenticated users into creating rogue administrator accounts.

SECURITYWEEKBREACH
12h agoREAD

Salesforce Agentforce 'SalesBleed' Flaws Allowed Zero-Click Data Theft

Security researchers detailed three vulnerabilities dubbed SalesBleed that allowed attackers to hijack trusted autonomous AI agents to exfiltrate enterprise data and conduct targeted phishing.

MICROSOFT SECURITY BLOGBREACH
6h agoREAD

Storm-3168 Conducts Agentic Cloud Attacks via Compromised Service Principals

Microsoft revealed attack campaigns abusing compromised Azure service principals for automated cloud reconnaissance, resource deletion, and credential harvesting.

Generated twice daily from public security RSS feeds. Informational only.