← Latest brief

Security news.

·Morning Brief

Active exploitation of enterprise edge infrastructure and open-source supply chains headlines today's security briefing, with attackers actively weaponizing recent flaws in SonicWall and AhsayCBS platforms. Concurrently, law enforcement actions intensify against the ShinyHunters extortion group alongside major disruptions to state-sponsored Chinese tooling. Software teams should also take note of weaponized GitHub Actions workflows targeting open-source repositories and critical pre-auth vulnerabilities in PaperCut.

BLEEPINGEXPLOIT
2d agoREAD

Max-Severity SonicWall SMA1000 Flaw Under Active Exploitation

Attackers are actively exploiting CVE-2026-102255, a maximum-severity flaw in SonicWall SMA1000 appliances patched just days ago. Administrators should verify appliance firmware immediately to prevent unauthorized access.

BLEEPINGPATCH
1d agoREAD

Unpatched AhsayCBS Flaws Targeted to Drop Webshells and Miners

Threat actors are actively exploiting unpatched vulnerabilities CVE-2026-105133 and CVE-2026-105134 in the AhsayCBS backup management suite. The flaws permit authentication bypass and OS command injection, enabling deployment of web shells and cryptocurrency miners.

THNKEV
2d agoREAD

CISA Adds Five Flax Typhoon Exploits to KEV Catalog

CISA issued a binding directive adding five vulnerabilities exploited by the China-linked threat actor Flax Typhoon to its Known Exploited Vulnerabilities catalog. The exploited flaws include legacy issues like ProFTPD flaw CVE-2015-3306 alongside other network-facing bugs.

THNBREACH
1d agoREAD

Malicious GitHub Actions Workflows Compromise Hundreds of Repositories

Attackers compromised high-profile open-source maintainer accounts to inject credential-stealing GitHub Actions workflows into over 340 repositories. Engineering teams should audit CI/CD workflow files and restrict build secret permissions across their dependency tree.

WATCHTOWR LABSRCE
1d agoREAD

PaperCut Discloses Pre-Auth RCE Vulnerability Chain and Bypasses

Security researchers released technical details regarding a pre-authentication remote code execution chain and multiple patch bypasses affecting PaperCut servers (tracked under CVE-2026-82077, CVE-2026-82078, and CVE-2026-81578). Administrators are urged to update to the latest patched releases.

BLEEPINGPOLICY
1d agoREAD

Cyber Executive Arrested in Crackdown on ShinyHunters Group

A Canadian cybersecurity executive has been arrested in the U.S. in connection with extortion operations tied to the ShinyHunters hacking ring. The arrest comes amidst a wider law enforcement push following the group's compromise of FBI personnel data.

THNEXPLOIT
10h agoREAD

New P7 DarkSword iOS Exploit Kit Targets Crypto Wallets

Researchers identified an updated P7 variant of the DarkSword iOS exploit kit featuring a reduced on-device footprint, bidirectional C2 communication, and automated theft of keychain and cryptocurrency wallet credentials.

Generated twice daily from public security RSS feeds. Informational only.