Latest Briefings
Bitget Restarts Bitcoin Withdrawals After $387.5 Million North Korea-Linked Heist
The crypto exchange has resumed BTC withdrawals following a suspected North Korean breach that drained hot and warm wallets across seven blockchains,…
Two Unpatched Citrix NetScaler Zero-Days Under Active RCE Exploitation
Security firm watchTowr says attackers are actively exploiting two unpatched remote code execution flaws in Citrix NetScaler ADC and Gateway appliances, with…
ShinyHunters Bypasses WAFs to Revive Oracle PeopleSoft Attacks
Google's Mandiant says the extortion gang UNC6240 is using percent-encoded URL paths to slip past web application firewalls and reach the vulnerable…
CISA Confirms Active Exploitation of SharePoint and MikroTik RouterOS Flaws
A critical SharePoint code injection bug and a MikroTik RouterOS vulnerability have both been added to CISA's Known Exploited Vulnerabilities catalog after…
CISA Flags Active Exploitation of WSO2 and Adobe Commerce Critical Flaws
CISA has added critical WSO2 and Adobe Commerce vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 27 to…
Attackers Weaponize Critical WordPress RCE Flaw Within Hours of Patch
CVE-2026-87902, a critical unauthenticated path traversal bug in WordPress core, is under active exploitation just hours after a fix landed in version…
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Remote Code Execution
F5 has fixed a critical zero-day in BIG-IP Access Policy Manager that attackers used to achieve unauthenticated RCE, prompting CISA to order…
CISA: Three Linux Kernel Flaws Under Active Attack, One Critical
CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, including a 14-year-old race condition and a critical TLS flaw,…
Critical Pre-Auth RCE in Orkes Conductor Exploited in the Wild
Fortinet warns that a critical unauthenticated remote code execution flaw in the Orkes Conductor workflow platform is being actively exploited, putting unpatched…
Maximum-Severity Cisco ISE Auth Bypass Added to CISA’s Exploited Vulnerability List
A perfect 10.0 CVSS flaw in Cisco Identity Services Engine is being actively exploited in the wild, prompting CISA to order federal…
Cisco Patches Max-Severity ISE Zero-Day Under Active Exploitation
A CVSS 10.0 authentication bypass in Cisco Identity Services Engine and ISE-PIC is being actively exploited, letting unauthenticated attackers gain root-level access…
Check Point Patches Critical Root RCE Flaw in Management Servers
An unauthenticated attacker could exploit a buffer overflow in the login process of Check Point's Security Management and Log Servers to gain…