Latest Briefings
Microsoft’s August Patch Tuesday Fixes Nearly 400 Flaws, One Under Active Attack
Microsoft's latest security update addresses 398 vulnerabilities, including an actively exploited Windows privilege escalation bug, as AI-assisted discovery continues to drive record…
CISA Confirms Active Exploitation of Critical Kemp LoadMaster RCE Flaw
A command injection bug in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is being actively exploited in the wild, prompting CISA to add…
Critical Flaws in Belgian eID Software Exposed 2 Million Users to Identity Theft
A researcher at DEF CON detailed now-patched vulnerabilities in Connective's digital identity browser extension that let malicious websites steal eID PINs, forge…
CISA Orders Federal Patch on Actively Exploited LoadMaster Flaw
A critical unauthenticated command injection bug in Progress Kemp LoadMaster is being exploited in the wild after researchers published proof-of-concept code, prompting…
One-Click Flaw in Atlassian’s Rovo AI Let Attackers Hijack Sessions and Exfiltrate Data
Varonis researchers found that a single crafted link could seed attacker instructions into Rovo's chat window, letting the AI assistant's own research…
Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access
Metabase has disclosed a maximum-severity, uncatalogued flaw in its BI platform that lets remote attackers inject SQL and seize control without credentials,…
Metabase SQL Injection Zero-Day Exploited to Steal Customer Data at Framework, Tally
An unauthenticated SQL injection flaw in Metabase, rated CVSS 10.0, was exploited as a zero-day to breach Metabase Cloud and self-hosted instances,…
CISA Confirms Active Exploitation of Critical TeamCity RCE Flaw CVE-2026-63077
JetBrains patched a critical deserialization vulnerability in on-premise TeamCity servers last week, and CISA has already added it to its Known Exploited…
Cisco Patches Two Dozen Flaws Including Critical FMC Auth Bypass and SD-WAN Bugs
Cisco's latest security update fixes critical vulnerabilities in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center, including a maximum-severity authentication bypass…
CISA Flags Active Exploitation of Langflow, N-central, and Tomcat Bugs
CISA has added four actively exploited vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat to its Known Exploited Vulnerabilities catalog,…
N-able Patches Second Auth Bypass Flaw Under Active Attack on N-central Servers
N-able rushed out a hotfix after discovering that attackers were exploiting an incomplete patch for a prior authentication bypass, granting administrator access…
N-able N-central Flaw Let Attackers Seize Servers After Patch Failed
An authentication bypass in N-able's N-central remote monitoring platform allowed attackers to gain full administrative control and pivot into customer environments, and…