← Latest brief

Security news.

·Morning Brief

Threat actors are actively leveraging zero-day flaws across enterprise appliances and collaboration tools, prompting emergency updates and federal warnings. Significant infrastructure attacks have hit cryptocurrency services and defense systems, alongside the weaponization of zero-day exploits in network edge devices. Defenders are urged to prioritize patching critical vulnerabilities in Cisco, Zimbra, and Citrix appliances immediately.

THNZERO-DAY
3h agoREAD

CISA Adds Cisco Catalyst SD-WAN Zero-Day to KEV Catalog

CISA has added CVE-2026-76504 (CVSS 9.8), an actively exploited authentication bypass vulnerability allowing remote attackers administrative access, to its Known Exploited Vulnerabilities catalog.

SECURITYWEEKEXPLOIT
Just nowREAD

Zimbra Flaw CVE-2026-73570 Exploited Prior to Disclosure

An unauthenticated command injection bug in Zimbra Collaboration Suite was exploited in the wild via malicious emails to deploy web shells and harvest mailbox data.

THNZERO-DAY
8h agoREAD

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Heist

Cryptocurrency exchange Bitget revealed that a zero-day vulnerability in third-party security software enabled the massive theft of digital assets.

BLEEPINGBREACH
4h agoREAD

Pentagon Personnel Data of Over 3 Million People Stolen in Breach

The Defense Manpower Data Center is notifying service members after hackers breached the Pentagon's human resources database.

SECURITYWEEKEXPLOIT
3h agoREAD

Zammad Zero-Days Exploited in Attack Against DIVD

Attackers chained two zero-day flaws in the open-source Zammad ticketing system to achieve remote code execution and root privilege escalation on the Dutch Institute for Vulnerability Disclosure's network.

BLEEPING
6h agoREAD

MetaMask Responds to Ongoing Infrastructure Security Incident

Crypto wallet provider MetaMask disclosed an infrastructure security incident that prompted the targeted exit of affected Ethereum validators, though no user wallets have been compromised.

THNEXPLOIT
7h agoREAD

PoC Released for Actively Exploited Apple CoreGraphics Vulnerability

Researchers published a proof-of-concept for CVE-2026-86950, a flaw triggered by crafted fonts in PDF files that has been used in targeted attacks against macOS and iOS devices.

THNEXPLOIT
9h agoREAD

Citrix NetScaler Flaws Weaponized for Superuser Persistence

Threat actors are actively exploiting recent command injection flaws (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and Gateway appliances to drop web shells disguised as CSS files.

Generated twice daily from public security RSS feeds. Informational only.