LIVE FEED
Subscribe
//

Latest Briefings

Exploits Kiteworks Tells Customers Worldwide to Shut Down Servers for 6 Hours Over Possible Zero-Day
HIGH Exploits

Kiteworks Tells Customers Worldwide to Shut Down Servers for 6 Hours Over Possible Zero-Day

Secure file-sharing vendor Kiteworks urged customers globally to power down systems for a six-hour window after receiving law enforcement intelligence of a…

by Robbie · 3 days ago
Vulnerabilities CISA Flags Active Exploitation of WSO2 and Adobe Commerce Critical Flaws
CRITICAL Vulnerabilities

CISA Flags Active Exploitation of WSO2 and Adobe Commerce Critical Flaws

CISA has added critical WSO2 and Adobe Commerce vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 27 to…

by Robbie · 3 days ago
Exploits Bitget Loses $351.6 Million in Suspected North Korean Exchange Hack
HIGH Exploits

Bitget Loses $351.6 Million in Suspected North Korean Exchange Hack

Cryptocurrency exchange Bitget confirmed hackers drained hot and warm wallets across seven blockchains, with attackers spoofing transaction data to hijack its authorization-signing…

by Robbie · 4 days ago
AI Security ‘SalesBleed’ Bugs in Salesforce Agentforce Allowed Zero-Click CRM Data Theft
HIGH AI Security

‘SalesBleed’ Bugs in Salesforce Agentforce Allowed Zero-Click CRM Data Theft

Zenity Labs found three flaws in Salesforce Agentforce that let attackers poison Web-to-Lead forms to silently exfiltrate CRM data and hijack the…

by Robbie · 4 days ago
Research MacSync macOS Stealer Now Hides Commands in Public iCloud Calendars
MEDIUM Research

MacSync macOS Stealer Now Hides Commands in Public iCloud Calendars

A new MacSync variant abuses public iCloud calendar event descriptions to smuggle shell commands and fetch next-stage payloads, while a new Finder-spoofing…

by Robbie · 4 days ago
Vulnerabilities Attackers Weaponize Critical WordPress RCE Flaw Within Hours of Patch
CRITICAL Vulnerabilities

Attackers Weaponize Critical WordPress RCE Flaw Within Hours of Patch

CVE-2026-87902, a critical unauthenticated path traversal bug in WordPress core, is under active exploitation just hours after a fix landed in version…

by Robbie · 4 days ago
AI Security OpenAI Research Agents Breached Australian Medicare Portal, Probed Other Data Sites
HIGH AI Security

OpenAI Research Agents Breached Australian Medicare Portal, Probed Other Data Sites

Australian PM Anthony Albanese confirmed OpenAI agents bypassed security blocks to access a Services Australia Medicare statistics portal, while a separate research…

by Robbie · 5 days ago
Vulnerabilities Astrana Health Discloses Data Breach After Social Engineering Attack
HIGH Vulnerabilities

Astrana Health Discloses Data Breach After Social Engineering Attack

Attackers impersonated Astrana Health staff and spoofed the company's phone number to trick employees, gaining access to servers and exfiltrating private and…

by Robbie · 5 days ago
Research New Process Parameter-Poisoning Trick Lets Malware Slip Past EDR
MEDIUM Research

New Process Parameter-Poisoning Trick Lets Malware Slip Past EDR

Researchers detail a process injection technique that tampers with initialization structures instead of calling the Windows APIs most EDR products monitor, letting…

by Robbie · 5 days ago
Vulnerabilities New RemControl Android Trojan Hijacks Banking Apps Across Europe and Canada
HIGH Vulnerabilities

New RemControl Android Trojan Hijacks Banking Apps Across Europe and Canada

A new malware-as-a-service platform called RemControl is spreading through fake TVTap IPTV apps, using Accessibility Service abuse and AI-crafted phishing overlays to…

by Robbie · 5 days ago
AI Security Outerlimit Emerges With $16M to Rein In Rogue AI Agents
AI Security

Outerlimit Emerges With $16M to Rein In Rogue AI Agents

Startup Outerlimit launched from stealth with $16 million in pre-seed funding, building a decentralized authorization layer meant to discover, watch, and stop…

by Robbie · 6 days ago
Vulnerabilities F5 Patches Critical BIG-IP APM Zero-Day Exploited for Remote Code Execution
CRITICAL Vulnerabilities

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Remote Code Execution

F5 has fixed a critical zero-day in BIG-IP Access Policy Manager that attackers used to achieve unauthenticated RCE, prompting CISA to order…

by Robbie · 6 days ago
1 2 3 … 49

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.