← Latest brief

Security news.

·Morning Brief

Critical enterprise infrastructure is under heavy pressure today, highlighted by active exploitation of a zero-day flaw in Fortinet FortiMail and emergency patches for Dell's Kubernetes enterprise storage modules. Meanwhile, major supply-chain and breach developments continue to unfold with the takedown of the KillSec ransomware operation and a massive legacy Pentagon personnel leak. Security teams also face new attack methods as autonomous AI agents weaponize SQL injection against government portals.

THNZERO-DAY
9h agoREAD

CISA Adds Actively Exploited Fortinet FortiMail Zero-Day to KEV

A critical path traversal flaw tracked as CVE-2026-104286 (CVSS 9.8) is being targeted in the wild to execute unauthenticated arbitrary file writes and system commands.

BLEEPINGPATCH
2h agoREAD

Dell Issues Urgent Fixes for Max-Severity Flaws in Container Storage Modules

Dell has addressed two maximum-severity vulnerabilities in its Container Storage Modules (CSM) connecting enterprise storage arrays to Kubernetes environments.

BLEEPINGBREACH
1d agoREAD

Pentagon Warns 3 Million Personnel Impacted by HR Database Breach

The Defense Manpower Data Center is alerting millions of service members that sensitive personnel records were stolen during an intrusion into its human resources management platform.

BLEEPINGRANSOMWARE
1d agoREAD

International Police Disrupt KillSec Ransomware Operation

"Operation KillSwitch" led to the seizure of KillSec's servers and leak site, securing 110TB of stolen data and resulting in three arrests, including the group's alleged 16-year-old leader.

SECURITYWEEKAI
6h agoREAD

Autonomous AI Agents Target US and Canadian Agencies with SQL Injection

Researchers observed automated AI agents launching aggressive SQL injection attacks against portals for the US Department of Education and Library and Archives Canada.

THNEXPLOIT
1d agoREAD

Cisco Catalyst SD-WAN Manager Flaw Under Active Exploitation

CISA has added CVE-2026-76504 (CVSS 9.8), an authentication bypass flaw allowing unauthenticated remote access, to its Known Exploited Vulnerabilities catalog.

BLEEPINGVULN
1d agoREAD

Kiteworks Resolves Max-Severity Flaw in Email Protection Gateway

A security update addressed 126 vulnerabilities across Kiteworks products, prominently featuring a maximum-severity code injection vulnerability affecting its Email Protection Gateway.

SECURITYWEEKICS/OT
5h agoREAD

China-Nexus 'Warlock' Group Targets Critical Infrastructure via SharePoint

Threat actors linked to China have intensified targeted intrusions against critical infrastructure by exploiting SharePoint vulnerabilities for long-term access and ransomware deployment.

Generated twice daily from public security RSS feeds. Informational only.