← Latest brief

Security news.

·Morning Brief

Critical software flaws take center stage today, led by active exploitation targeting Fortinet FortiMail and active ransomware campaigns striking Microsoft SharePoint environments. Meanwhile, administrators face urgent patching requirements for critical flaws in Dell Container Storage Modules and self-hosted GitLab AI Gateways, alongside notable law enforcement crackdowns on the ShinyHunters extortion ring.

SECURITYWEEKZERO-DAY
2d agoREAD

Exploited Fortinet FortiMail Zero-Day Demands Immediate Action

A critical path traversal flaw (CVE-2026-104286) in Fortinet FortiMail is being actively exploited in the wild to write arbitrary files and compromise systems, prompting emergency patching warnings and a rapid addition to CISA's KEV catalog.

THNRANSOMWARE
1d agoREAD

Warlock Exploits SharePoint Flaws in Ransomware Campaigns

China-linked threat actor Warlock is actively weaponizing Microsoft SharePoint vulnerabilities to disable endpoint defenses and deploy ransomware across government, telecom, and critical infrastructure sectors.

THNVULN
2d agoREAD

Critical Dell CSM Vulnerabilities Grant Kubernetes Node Takeover

Dell released updates fixing two maximum-severity flaws (including CVSS 10.0 CVE-2026-63688) in Dell Container Storage Modules that permit unauthenticated remote attackers to gain root access on underlying Kubernetes hosts.

THNRCE
2d agoREAD

GitLab Fixes Critical AI Gateway Remote Code Execution Flaw

Self-hosted GitLab deployments face risk from a critical 9.9-severity vulnerability that allows authenticated users with Duo Agent Platform access to execute arbitrary commands directly on the AI Gateway server.

CISAKEV
2d agoREAD

CISA Adds Two Actively Exploited Zammad Bugs to KEV Catalog

Federal agencies have been ordered to remediate session fixation (CVE-2026-102489) and improper privilege management (CVE-2026-102490) vulnerabilities in Zammad after confirmed weaponization in malicious campaigns.

THN
23h agoREAD

ShinyHunters Extortion Member Detained in Jordan

Authorities have apprehended suspected ShinyHunters hacker "Rey" (Saif al-Din Khader) in Jordan, who is reportedly cooperating with the FBI to identify other members of the notorious data breach and extortion group.

THNPHISHING
23h agoREAD

Chinese APT TA419 Targets AI Policy Experts via AitM Phishing

Espionage actors aligned with China are launching Adversary-in-the-Middle credential-phishing operations by impersonating prominent AI policymakers and Anthropic staff to target researchers at U.S. think tanks and academic institutions.

SECURITYWEEKPATCH
1d agoREAD

Fortra Patches Critical Flaws in BoKS Server Software

Fortra addressed multiple high-impact vulnerabilities in its BoKS privileged access management platform that could enable unauthenticated attackers to bypass authentication, trigger shell execution, or corrupt memory.

Generated twice daily from public security RSS feeds. Informational only.