LIVE FEED
Subscribe
//

Latest Briefings

Research Fake ShinyHunters Sextortion Emails Exploit Old Breach Data for $2,000 Bitcoin Demands
LOW Research

Fake ShinyHunters Sextortion Emails Exploit Old Breach Data for $2,000 Bitcoin Demands

Scammers are recycling email addresses from ShinyHunters' published data leaks to send fraudulent sextortion emails, falsely claiming device compromise to pressure victims…

by Robbie · 2 months ago
Research Malvertising Campaign Builds Malware Inside the Browser, Never Touches the Network
MEDIUM Research

Malvertising Campaign Builds Malware Inside the Browser, Never Touches the Network

A crypto and trading themed malvertising operation dubbed SourTrade uses service workers and shared workers to assemble malicious executables locally in browser…

by Robbie · 2 months ago
Vulnerabilities UK PM Burnham Keeps Cyber Minister in Place Despite Ministry Shakeup
Vulnerabilities

UK PM Burnham Keeps Cyber Minister in Place Despite Ministry Shakeup

New Prime Minister Andy Burnham reappointed Liz Lloyd to steer cyber policy even as he dismantled the department that housed it, preserving…

by Robbie · 2 months ago
Vulnerabilities Rockwell Patches Four Code Execution Flaws in Arena Simulation Software
HIGH Vulnerabilities

Rockwell Patches Four Code Execution Flaws in Arena Simulation Software

Rockwell Automation has fixed four high-severity memory corruption vulnerabilities in Arena Simulation that could let an attacker execute arbitrary code via a…

by Robbie · 2 months ago
Exploits Hackers Hijack Hotel and Conference Wi-Fi to Steal Microsoft 365 Logins
HIGH Exploits

Hackers Hijack Hotel and Conference Wi-Fi to Steal Microsoft 365 Logins

A DNS hijacking campaign targeting Wi-Fi gateways at hotels and conference centers is redirecting traveling employees to fake Microsoft 365 login pages,…

by Robbie · 2 months ago
Vulnerabilities OnTrac Discloses Data Breach After Network Intrusion
MEDIUM Vulnerabilities

OnTrac Discloses Data Breach After Network Intrusion

The last-mile delivery firm says an attacker accessed files over a three-day span in March, and its response language hints at a…

by Robbie · 2 months ago
AI Security AI Guardrails Falter Across Europe’s Many Languages, Researchers Warn
MEDIUM AI Security

AI Guardrails Falter Across Europe’s Many Languages, Researchers Warn

Security testing shows that jailbreak protections built into AI products are inconsistent across languages, leaving gaps that attackers can exploit in Europe's…

by Robbie · 2 months ago
Vulnerabilities NodeBB Patches Eight High-Severity Flaws Found by AI Pentest Agents
HIGH Vulnerabilities

NodeBB Patches Eight High-Severity Flaws Found by AI Pentest Agents

Aikido Security says its AI-driven code review uncovered eight high-severity vulnerabilities in the NodeBB forum platform in just six hours, exposing admin…

by Robbie · 2 months ago
Vulnerabilities RefluXFS: Nine-Year-Old Linux Kernel Flaw Grants Root via XFS Race Condition
HIGH Vulnerabilities

RefluXFS: Nine-Year-Old Linux Kernel Flaw Grants Root via XFS Race Condition

A race condition in the XFS filesystem's reflink copy-on-write path, present since kernel 4.11, lets unprivileged local users overwrite root-owned files and…

by Robbie · 2 months ago
Vulnerabilities Russian APT ‘Laundry Bear’ Exploited Zimbra Zero-Day to Steal Email at Scale
CRITICAL Vulnerabilities

Russian APT ‘Laundry Bear’ Exploited Zimbra Zero-Day to Steal Email at Scale

A joint advisory from CISA, NSA, FBI and international partners details a Russian state-supported campaign that used a zero-click Zimbra Collaboration Suite…

by Robbie · 2 months ago
Vulnerabilities Stadler Rail Refuses $12.3M Everest Ransom After Supplier Data Breach
MEDIUM Vulnerabilities

Stadler Rail Refuses $12.3M Everest Ransom After Supplier Data Breach

Swiss rail manufacturer Stadler says a breach at a third-party file-sharing platform exposed technical supplier documents, but the company is refusing Everest's…

by Robbie · 2 months ago
Vulnerabilities Check Point Zero-Day Under Active Attack, CISA Sets July 25 Deadline
CRITICAL Vulnerabilities

Check Point Zero-Day Under Active Attack, CISA Sets July 25 Deadline

A critical authentication bypass in Check Point's Security Management and Multi-Domain Management products is being exploited against internet-exposed environments, prompting an emergency…

by Robbie · 2 months ago
1 … 18 19 20 … 49

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.