Latest Briefings
Mozilla Rotates Firefox GPG Signing Key After Accidental GitHub Exposure
Mozilla revoked and replaced a GPG signing subkey used for Firefox and Thunderbird Linux artifacts after finding an unencrypted copy in a…
OpenAI Launches GPT-5.6-Cyber, a Purpose-Built Offensive Security Model
OpenAI's new GPT-5.6-Cyber model sharply lowers refusal rates for exploit development and vulnerability research, and will be restricted to vetted partners under…
CISA Confirms Active Exploitation of Critical Kemp LoadMaster RCE Flaw
A command injection bug in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is being actively exploited in the wild, prompting CISA to add…
Former Medusa Affiliate Deploys New StormEncryptor Ransomware
Microsoft says China-linked threat actor Storm-1175 has pivoted from Medusa to a new C++ ransomware strain, likely exploiting an authentication-bypass flaw in…
Critical Flaws in Belgian eID Software Exposed 2 Million Users to Identity Theft
A researcher at DEF CON detailed now-patched vulnerabilities in Connective's digital identity browser extension that let malicious websites steal eID PINs, forge…
CISA Orders Federal Patch on Actively Exploited LoadMaster Flaw
A critical unauthenticated command injection bug in Progress Kemp LoadMaster is being exploited in the wild after researchers published proof-of-concept code, prompting…
New Mexico Judge Orders Meta to Pay $567 Million Over Youth Safety Failures
A Santa Fe judge ruled Meta must fund harm-mitigation efforts and overhaul how minors use Facebook and Instagram, calling the platforms a…
NRWA Teams With DEF CON Franklin to Shield Small Water Utilities
The National Rural Water Association has launched the Water Watch Center with DEF CON Franklin and five managed security providers to bring…
N-able Ships Second N-central Hotfix as Attackers Reach Managed Endpoints
N-able has issued a new hotfix for its N-central RMM platform after observing threat actors evolve their techniques and reach systems managed…
Atlassian Rovo AI Assistant Can Be Tricked Into Leaking Jira and Confluence Data
Researchers found that hidden instructions embedded in content Rovo reads can hijack the assistant into pulling a user's accessible Jira and Confluence…
One-Click Flaw in Atlassian’s Rovo AI Let Attackers Hijack Sessions and Exfiltrate Data
Varonis researchers found that a single crafted link could seed attacker instructions into Rovo's chat window, letting the AI assistant's own research…
Head Mare Hackers Trojanize TrueConf Installers to Spread Backdoors
A hacktivist group is exploiting unpatched TrueConf video conferencing servers to plant web shells and swap legitimate client installers with backdoored versions,…