Latest Briefings
New Mexico Judge Orders Meta to Pay $567 Million Over Youth Safety Failures
A Santa Fe judge ruled Meta must fund harm-mitigation efforts and overhaul how minors use Facebook and Instagram, calling the platforms a…
NRWA Teams With DEF CON Franklin to Shield Small Water Utilities
The National Rural Water Association has launched the Water Watch Center with DEF CON Franklin and five managed security providers to bring…
N-able Ships Second N-central Hotfix as Attackers Reach Managed Endpoints
N-able has issued a new hotfix for its N-central RMM platform after observing threat actors evolve their techniques and reach systems managed…
Atlassian Rovo AI Assistant Can Be Tricked Into Leaking Jira and Confluence Data
Researchers found that hidden instructions embedded in content Rovo reads can hijack the assistant into pulling a user's accessible Jira and Confluence…
One-Click Flaw in Atlassian’s Rovo AI Let Attackers Hijack Sessions and Exfiltrate Data
Varonis researchers found that a single crafted link could seed attacker instructions into Rovo's chat window, letting the AI assistant's own research…
Head Mare Hackers Trojanize TrueConf Installers to Spread Backdoors
A hacktivist group is exploiting unpatched TrueConf video conferencing servers to plant web shells and swap legitimate client installers with backdoored versions,…
Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access
Metabase has disclosed a maximum-severity, uncatalogued flaw in its BI platform that lets remote attackers inject SQL and seize control without credentials,…
New CSS Attacks Break Out of Email Boundaries to Steal Webmail Credentials
Researcher demonstrates how CSS embedded in email content can escape message boundaries across major webmail providers, enabling credential theft, token leaks, and…
Metabase SQL Injection Zero-Day Exploited to Steal Customer Data at Framework, Tally
An unauthenticated SQL injection flaw in Metabase, rated CVSS 10.0, was exploited as a zero-day to breach Metabase Cloud and self-hosted instances,…
ClickFix Campaign Delivers macOS Crypto-Draining Stealer
A Go-based malware pushed through fake Terminal-command lures steals browser passwords and iCloud Keychain data while quietly siphoning cryptocurrency from active transactions.
NatJack Attack Class Hijacks TCP Sessions by Abusing NAT Tables
Researcher Malcolm Stagg unveiled NatJack at Black Hat USA 2026, a technique that manipulates NAT connection state to hijack TCP sessions, spoof…
Truck Brake Recall Quietly Patched Wireless RCE Flaws, Researcher Says
NMFTA researchers reverse-engineered firmware from a 2024 Bendix EC80 safety recall and found it fixed multiple undisclosed vulnerabilities, including a wirelessly reachable…