Latest Briefings
Firefox 154 and Chrome 151 Patch Dozens of High and Critical Severity Bugs
Mozilla and Google shipped major browser updates this week, fixing 58 vulnerabilities in Firefox and 15 in Chrome, including several memory safety…
Windows 11 24H2 Home and Pro Lose Security Updates in Two Months
Microsoft is warning that Windows 11 24H2 Home and Pro editions, along with Windows 10 Enterprise LTSB 2016, will stop receiving updates…
UT San Antonio Takes Systems Offline After Cyberattack Days Before Classes
UTSA detected threat activity on its network over the weekend and pulled systems, including phones, offline, forcing payment and password reset delays…
Clop’s Custom-Built Web Shell Targets PTC Windchill Internals Directly
ReliaQuest found that a JSP web shell used in recent Windchill data-theft attacks was purpose-built to abuse the application's own credential-decryption and…
Apple Patches Dozens of WebKit Flaws in New macOS, iOS Security Updates
Apple released macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, and legacy iOS/iPadOS 18.7.10 updates fixing dozens of WebKit bugs alongside kernel and…
Microsoft Begins Stripping WMIC LOLBIN From Windows 11
Microsoft has removed the legacy WMIC command-line tool from Windows 11 24H2, 25H2, and current beta builds, closing off a utility long…
Anthropic Test Finds Claude Agents Spawned Self-Replicating Malware in Turf War
In an internal experiment, three Claude-based agents given the same goal but conflicting directives escalated into territorial attacks on each other, producing…
Critical SAP Commerce Cloud Flaw Exploited Just Days After Patch Release
A maximum-severity vulnerability in SAP Commerce Cloud, CVE-2026-58231, is already under active attack after threat intelligence firms spotted exploitation attempts within days…
SafePal Breach Exposes Order Data for Nearly 40,000 Crypto Wallet Customers
An authorization flaw in a third-party order-tracking plug-in let an attacker scrape SafePal customer order details, and the stolen data is now…
Attackers Exploit Patched macOS Screen Sharing Flaw to Plant Cryptominers
A high-severity authentication bypass in Apple's Screen Sharing daemon is being actively exploited to gain root access and install Monero miners on…
AmnesiaStealer Malware Hijacks macOS Browser Sessions in Real Time
A new macOS infostealer spread via ClickFix lures clones victims' Chromium browser profiles and lets attackers remotely drive authenticated sessions through a…
DDoS Barrage Knocks Threema Secure Messaging Offline for Days
A sustained, tactic-shifting DDoS campaign disrupted the Swiss encrypted messaging service and its colocation partner Nine, leaving users in Switzerland, India and…