← Latest brief

Security news.

·Afternoon Brief

Critical zero-day exploitation against network edge devices and mobile platforms dominates today's security landscape, led by ongoing attacks targeting Citrix NetScaler and actively exploited flaws in Apple's CoreGraphics engine. Simultaneously, researchers have revealed a new Spectre-v2 hardware attack variant capable of rapidly leaking memory across major CPU architectures, while major data breaches and high-impact infrastructure bugs demand immediate defensive attention.

BLEEPINGZERO-DAY
3h agoREAD

Citrix NetScaler Zero-Day Exploited to Drop Web Shells

Threat actors are actively exploiting a critical flaw in Citrix NetScaler (CVE-2026-88772) to obtain root access, drop web shells, and pivot into enterprise networks.

BLEEPINGZERO-DAY
14h agoREAD

Apple Patches CoreGraphics Zero-Day Flaw (CVE-2026-86950)

Apple issued emergency updates to address an actively exploited out-of-bounds write flaw affecting older iOS and macOS releases, now also added to CISA's Known Exploited Vulnerabilities catalog.

THNBREACH
4h agoREAD

New Spectre-v2 'BTR' Attack Leaks Linux Memory Across CPUs

Researchers unveiled a Branch Target Reuse attack against JIT compilers and OS kernels that bypasses modern hardware defenses and extracts root password hashes in minutes.

SECURITYWEEKBREACH
9h agoREAD

Pentagon Personnel Agency Breach Exposes 3 Million Records

A data security incident at the Defense Manpower Data Center (DMDC) has compromised the personnel files of approximately three million Department of Defense affiliates.

CISARCE
10h agoREAD

CISA Flags Critical RCE Vulnerability in MikroTik RouterOS

CISA issued an advisory for an integer underflow flaw (CVE-2026-84411, CVSS 9.8) in MikroTik RouterOS versions prior to 7.24 that allows unauthenticated remote code execution.

BLEEPINGVULN
13h agoREAD

Kiteworks Resolves Critical Flaw Following Emergency Shutdown

Kiteworks lifted an advisory instructing customers to isolate systems after deploying a fix for a severe vulnerability discovered in an enterprise file-sharing feature.

THNBREACH
16h agoREAD

Official MCP Python SDK Vulnerability Leaks OAuth Credentials

Applications using vulnerable versions of the Model Context Protocol Python SDK inadvertently transmit client secrets, authorization codes, and PKCE keys to attacker-controlled servers.

Generated twice daily from public security RSS feeds. Informational only.