← Latest brief

Security news.

·Morning Brief

Major security developments include active attacks on critical enterprise infrastructure and an expansive breach of government registry data. In addition to widespread exploitation campaigns hitting Citrix and Rejetto appliances, administrators face high-severity flaws in self-hosted Atlassian and Microsoft Exchange deployments. Threat actors also continue to probe perimeter defenses using novel browser caching techniques and stealthy proxy backdoors.

CISAKEV
2d agoREAD

Citrix NetScaler Flaw Added to CISA KEV Under Active Exploitation

CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild attacks targeting memory buffer restrictions in NetScaler appliances.

THNVULN
9h agoREAD

Critical Atlassian Flaw Exposes Files Across 8 Data Center Products

Tracked as CVE-2026-21589 with a 9.3 CVSS rating, the vulnerability allows unauthenticated remote attackers to read known files directly from application root directories.

BLEEPINGRCE
20h agoREAD

Attackers Actively Scan for Rejetto HFS RCE Vulnerability

Scanners are actively hunting for CVE-2026-61500, a weak session-cookie signing key flaw that enables complete session forgery and arbitrary code execution.

THNPATCH
1d agoREAD

Microsoft Patches High-Severity Privilege Escalation Flaw in Exchange Server

An out-of-band update addresses CVE-2026-96940 (CVSS 8.8), an authorization weakness allowing authenticated attackers to access mailboxes belonging to other users.

SECURITYWEEKBREACH
7h agoREAD

Data Breach at Denmark CPR Exposes Records of 8.8 Million Citizens

Attackers abused a private organization's lawful query credentials to compromise personal registration data, impacting virtually the entire Danish population.

DARK READINGMALWARE
19h agoREAD

ClingSTUN Linux Backdoor Turns IoT Devices into Stealth Proxies

The malware leverages 24 known exploits to hijack IoT hardware and routes communications through public STUN servers to evade traffic inspection.

THNMALWARE
11h agoREAD

ClickFix Campaign Pre-Fetches Payloads via Browser Cache

Microsoft warns that attackers are disguising script payloads as PNG files within local browser caches to circumvent traditional execution boundaries.

THNVULN
4h agoREAD

LibreOffice and OpenOffice Flaw Enables Macro-Free Code Execution

Proof-of-concept research demonstrates that crafted spreadsheets can execute arbitrary code upon opening without user warnings if Java support is enabled.

Generated twice daily from public security RSS feeds. Informational only.