← Latest brief

Security news.

·Afternoon Brief

Active exploitation of perimeter devices and backup infrastructure dominates today's security landscape, with urgent warnings issued for SonicWall SMA1000 and AhsayCBS platforms. Law enforcement continues its aggressive sweep against the ShinyHunters extortion ring following high-profile executive arrests, while major supply-chain intrusions hit open-source software and corporate databases.

BLEEPINGEXPLOIT
2d agoREAD

SonicWall SMA1000 Flaw Exploited in Attacks

Threat actors are actively exploiting a maximum-severity flaw (CVE-2026-102255) affecting SMA1000 appliances just days after security patches were issued.

BLEEPINGPATCH
2d agoREAD

Unpatched AhsayCBS Vulnerabilities Targeted for Crypto Mining

Attackers are exploiting unpatched flaws (including CVE-2026-105133) in the AhsayCBS backup management platform to deploy webshells and XMRig miners.

SECURITYWEEKVULN
2d agoREAD

Citrix Urges Immediate Action for Critical NetScaler Flaw

Citrix has issued an urgent advisory warning administrators to patch a critical remote code execution and denial-of-service vulnerability tracked as CVE-2026-107406.

THNMALWARE
2d agoREAD

Credential Stealers Planted Across Hundreds of GitHub Repositories

A supply-chain campaign hijacked high-profile open-source developer accounts to push malicious credential-stealing GitHub Actions workflows into over 340 projects.

BLEEPINGPOLICY
1d agoREAD

Cybersecurity Executive Arrested Over ShinyHunters Extortion Ties

The FBI has arrested a Canadian security firm co-founder in connection with ongoing extortion activity tied to the ShinyHunters cybercrime operation.

BLEEPINGBREACH
6h agoREAD

Malware Breach at Nippon Columbia Exposes 8.6M Records

Entertainment system maker Daiichi Kosho confirmed that a malware infection at contractor Nippon Columbia compromised over 8.6 million customer and employee records.

THNBREACH
16h agoREAD

P7 DarkSword iOS Exploit Kit Steals Crypto Wallets

A newly discovered variant of the DarkSword iOS exploit kit features a reduced footprint, C2 communication, and automated extraction of keychain and cryptocurrency wallet secrets.

THNEXPLOIT
2d agoREAD

Working Root Exploit Released for Pre-Auth AnyDesk Flaw

Security researchers released a functional exploit targeting a pre-authentication vulnerability in AnyDesk Linux that grants attackers root privileges prior to session approval.

Generated twice daily from public security RSS feeds. Informational only.