← Latest brief

Security news.

·Morning Brief

Today's security landscape is dominated by active exploitation targeting perimeter network devices and critical infrastructure. U.S. authorities and CISA have taken major disruption and directive actions against Chinese state-sponsored threat actors exploiting critical flaws, while vendors urgently push patches for severe edge appliance vulnerabilities. Concurrently, zero-day research milestones highlight ongoing software supply chain and device security risks.

BLEEPINGZERO-DAY
2h agoREAD

SonicWall SMA1000 Zero-Day Under Active Exploitation

Attackers are actively targeting a maximum-severity flaw (CVE-2026-102255) in SonicWall SMA1000 appliances just days after vendor patches were made available.

THNPATCH
2h agoREAD

CISA Orders Agencies to Patch Vulnerabilities Abused by Flax Typhoon

CISA added five security flaws, including maximum-severity ProFTPD vulnerability CVE-2015-3306, to its Known Exploited Vulnerabilities catalog after widespread abuse by China-linked threat actors.

SECURITYWEEKEXPLOIT
4h agoREAD

Unpatched Zero-Days in AhsayCBS Exploited in the Wild

Threat actors are actively chaining CVE-2026-105133 and CVE-2026-105134 to bypass authentication and execute remote operating system commands on AhsayCBS backup software.

BLEEPINGRCE
6h agoREAD

Citrix Urges Immediate Patching of Critical NetScaler RCE Flaw

Citrix has issued an urgent advisory for a memory overflow defect (CVE-2026-107406) affecting NetScaler ADC and Gateway appliances configured for SAML deployments.

THNPOLICY
8h agoREAD

FBI Disrupts Chinese Hacking Tools MicroScan and FishHub

U.S. law enforcement seized seven malicious domains operated by Flax Typhoon and associated state-sponsored groups targeting critical infrastructure and government entities.

THNBREACH
6h agoREAD

Researchers Remotely Compromise Google Pixel 10 at Pwn2Own

Three separate research teams demonstrated remote zero-day execution on fully patched Google Pixel 10 devices, claiming more than half a million dollars in bounties.

SECURITYWEEKMALWARE
5h agoREAD

Pre-Installed Android Firmware Malware Detected in 150+ Countries

The 'Midnight Mimosa' campaign has infected low-cost Android smartphones with factory-firmware trojans, enabling covert ad fraud and routing malicious residential proxy traffic.

SECURITYWEEKBREACH
3h agoREAD

Google Domains Targeted via Hijacked ccTLD Registries

Attackers compromised top-level country-code domains including .gh, .sl, and .as, allowing them to illicitly generate valid HTTPS certificates for core Google domains.

Generated twice daily from public security RSS feeds. Informational only.