Latest Briefings
Akira Affiliate Rebooted a Victim Into Safe Mode to Kill EDR, Ransomware Still Failed
An Akira ransomware operator disabled endpoint defenses by forcing a compromised host into Safe Mode with Networking, but the encryption payload crashed…
Ukraine Takes Down 94 Fraudulent Call Centers in Nationwide Sweep
A joint operation by Ukrainian police, security services, and German law enforcement dismantled dozens of scam call centers running fake investment platforms…
Attackers Exploit Critical VMware vCenter Flaw CVE-2026-59310 Within Days of Patch
An APT actor is exploiting a critical directory traversal and RCE bug in VMware vCenter's Syslog server, hitting over 360 IP addresses…
‘Jewelbug’ Hackers-for-Hire Mix State Espionage With Crypto Theft
Researchers say a threat group tracked as Jewelbug ran both nation-state espionage operations and financially motivated cryptocurrency heists through the same web-based…
City-Forum Campaign Targets Salesforce, ServiceNow in Long-Running Data Theft Operation
A data theft campaign dubbed City-Forum has been quietly targeting Salesforce and ServiceNow environments across multiple industries since at least March 2025,…
ShieldBreak Zero-Day Bypasses Microsoft Defender Patch, Grants SYSTEM Access
A new PoC dubbed ShieldBreak sidesteps Microsoft's fix for the RoguePlanet Defender flaw, letting attackers escalate to SYSTEM on fully patched Windows…
US and South Korea Warn of Gunra Ransomware Hitting Government Networks
A joint advisory details how the Conti-derived Gunra ransomware group is exploiting Fortinet flaws and VPN weaknesses to breach critical infrastructure, now…
Cisco Warns of Actively Exploited ASA/FTD VPN Flaw Causing Device Crashes
A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software is being exploited to remotely crash devices via crafted HTTP requests…
Microsoft Fixes 398 Flaws, Patches Actively Exploited Windows Kernel Driver Zero-Day
August's Patch Tuesday closes 398 vulnerabilities, including a zero-day in a core Windows networking driver that attackers are already using to gain…
Microsoft’s August Patch Tuesday Fixes Nearly 400 Flaws, One Under Active Attack
Microsoft's latest security update addresses 398 vulnerabilities, including an actively exploited Windows privilege escalation bug, as AI-assisted discovery continues to drive record…
Mozilla Rotates Firefox GPG Signing Key After Accidental GitHub Exposure
Mozilla revoked and replaced a GPG signing subkey used for Firefox and Thunderbird Linux artifacts after finding an unencrypted copy in a…
OpenAI Launches GPT-5.6-Cyber, a Purpose-Built Offensive Security Model
OpenAI's new GPT-5.6-Cyber model sharply lowers refusal rates for exploit development and vulnerability research, and will be restricted to vetted partners under…