Latest Briefings
Spur Lands $200 Million from Insight Partners to Scale IP Intelligence Platform
Bootstrapped bot-detection and IP intelligence firm Spur Intelligence takes its first outside investment, aiming to help security and fraud teams unmask traffic…
Arista Patches Max-Severity VeloCloud Orchestrator Flaw Under Active Attack
CVE-2026-16812, an unauthenticated command injection flaw scoring a perfect 10.0, is being exploited against on-premises VeloCloud Orchestrator deployments. CISA has added it…
CISA and Australia Urge Critical Infrastructure to Pre-Plan OT Isolation
New joint guidance from CISA, the ACSC, the FBI and international partners lays out how operators of water, energy, transportation and telecom…
OpenAI Models Exploited Artifactory Zero-Days to Break Out of Test Sandbox
JFrog has confirmed that OpenAI's models found and chained previously unknown Artifactory vulnerabilities to escape an isolated evaluation environment, setting up a…
Google Overhauls Threat Actor Naming With New Cryptonym System
Google Threat Intelligence Group is retiring its old sequential APT numbering in favor of two-word cryptonyms that pair a memorable identifier with…
Autonomous AI Agent in “YOLO Mode” Used to Spy on Thailand’s Finance Ministry
Researchers found an open-source AI agent operating without human oversight to conduct reconnaissance and credential theft inside Thailand's Ministry of Finance, after…
Certighost PoC Exploit Lets Low-Privileged Users Hijack Windows Domains via AD CS
Researchers released a working exploit for CVE-2026-54121, an Active Directory Certificate Services flaw that lets an authenticated attacker impersonate a domain controller…
Dysphoria Botnet Grows to 200,000 Devices Using Blockchain-Based C2
Researchers at QiAnXin XLab have tracked a rapidly evolving DDoS botnet called Dysphoria that hides its command infrastructure inside Ethereum and Solana…
DentaQuest Breach Tied to ShinyHunters Exposes Data on Over 23 Million People
Dental and vision benefits administrator DentaQuest is notifying millions after attackers accessed sensitive health and identity data over a four-day window in…
Anthropic’s Opus 5 Nearly Matches Mythos 5 at Finding Bugs, Lags on Exploits
Anthropic's new cheaper Claude Opus 5 model rivals its top-tier Mythos 5 system at spotting vulnerabilities, but a deliberate lack of offensive-task…
GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git
A researcher has published working exploit code for a GitLab vulnerability patched six weeks ago, showing how any authenticated user with push…
GitHub and PyPI Roll Out Time-Delay Defenses Against Supply Chain Attacks
GitHub's Dependabot now enforces a default 72-hour cooldown before adopting new package versions, while PyPI blocks file additions to releases older than…