Latest Briefings
Keio Corporation Confirms Ransomware Attack Disrupted Hospitality Systems
The Japanese railway and hotel operator shut down its network after a weekend ransomware attack hit servers tied to its hospitality business,…
Carbonato Botnet Weaponizes AI Agent Framework on Hacked Docker Hosts
A new botnet called Carbonato compromises exposed Docker daemons to install the open source Hermes Agent AI framework, letting attackers issue commands…
US Army Soldier Sentenced to 70 Months for Extorting Telecom Giants
Cameron John Wagenius, known online as 'kiberphant0m,' used a self-built SSH brute-forcing tool to steal credentials and extort at least 10 tech…
Bitget Restarts Bitcoin Withdrawals After $387.5 Million North Korea-Linked Heist
The crypto exchange has resumed BTC withdrawals following a suspected North Korean breach that drained hot and warm wallets across seven blockchains,…
Claude Opus 5.5 Cuts Em Dash Use by 95%, But Answers Grow Longer
New analysis from AI benchmarking tool Arena shows Anthropic's Claude Opus 5.5 is shedding telltale AI writing patterns like em dashes and…
Cloudflare Patches Cross-Tenant Data Leak Bug in Containers Service
A flaw in Cloudflare's shared storage pool let Workers Paid customers recover residual data, including credentials and databases, left behind by other…
Microsoft Pauses KB5002907 After Update Deactivates Perpetual Office Installs
An optional Microsoft 365 update meant to refresh out-of-date installations instead deactivated, and in some cases completely removed, perpetual Office 2016 and…
Two Unpatched Citrix NetScaler Zero-Days Under Active RCE Exploitation
Security firm watchTowr says attackers are actively exploiting two unpatched remote code execution flaws in Citrix NetScaler ADC and Gateway appliances, with…
US and China Agree to Set Up AI Incident Communication Channel
Following a summit between Presidents Trump and Xi, Washington and Beijing agreed to establish a mechanism for coordinating on AI-related incidents and…
ShinyHunters Bypasses WAFs to Revive Oracle PeopleSoft Attacks
Google's Mandiant says the extortion gang UNC6240 is using percent-encoded URL paths to slip past web application firewalls and reach the vulnerable…
ShinyHunters Breached Clop’s Own Leak Site via Unpatched Grav CMS Flaw
An unauthenticated path traversal bug in Grav CMS 1.7 let ShinyHunters deface and steal data from Clop's Tor leak site, prompting Clop…
CISA Confirms Active Exploitation of SharePoint and MikroTik RouterOS Flaws
A critical SharePoint code injection bug and a MikroTik RouterOS vulnerability have both been added to CISA's Known Exploited Vulnerabilities catalog after…