← Latest brief

Security news.

·Morning Brief

Critical enterprise infrastructure is under heavy pressure today, led by active zero-day exploitation against Fortinet edge appliances and high-severity access flaws in Dell and GitLab services. State-aligned actors are also aggressively weaponising compromised enterprise tools, with China-linked groups hitting critical infrastructure via SharePoint vulnerabilities and deploying novel backdoors. Meanwhile, federal agencies have mandated emergency fixes as active exploitation catalogs continue to expand.

THNZERO-DAY
1d agoREAD

Critical Fortinet FortiMail Zero-Day Exploited in Attacks

CISA has added CVE-2026-104286 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog following active in-the-wild exploitation that allows unauthenticated attackers to write arbitrary files.

THNVULN
22h agoREAD

Dell CSM Vulnerabilities Grant Root on Kubernetes Nodes

Dell patched multiple critical security flaws in its Container Storage Modules, including CVE-2026-63688 (CVSS 10.0), which permits unauthenticated admin access and complete node takeover.

THNAI
22h agoREAD

GitLab AI Gateway Flaw Enables Remote Command Execution

A critical vulnerability (CVSS 9.9) in GitLab's self-hosted AI Gateway could allow authenticated users with Duo Agent Platform access to execute arbitrary commands on the host server.

BLEEPINGRANSOMWARE
21h agoREAD

Warlock Ransomware Targets Utilities via SharePoint Flaws

China-linked threat group Warlock breached a water provider, telecom operator, and government body by leveraging unpatched Microsoft SharePoint vulnerabilities for initial entry.

CISAEXPLOIT
1d agoREAD

CISA Orders Patches for Exploited Zammad Helpdesk Vulnerabilities

CISA added two actively exploited Zammad vulnerabilities (CVE-2026-102489 and CVE-2026-102490) to the KEV catalog, warning of widespread session fixation and improper privilege management risks.

SECURITYWEEKPATCH
4h agoREAD

Fortra Patches Critical Authentication Bypass Flaws in BoKS

Fortra addressed high-severity security bugs in its BoKS Server product that allow unauthenticated attackers to bypass authentication, corrupt memory, and execute shell commands.

THNMALWARE
22h agoREAD

Antino Backdoor Targets Asian Governments via Microsoft Services

A China-nexus espionage campaign tracked as UAT-11587 is deploying a newly discovered backdoor across government entities, abusing Outlook and OneDrive infrastructure for stealth command-and-control.

Generated twice daily from public security RSS feeds. Informational only.