Latest Briefings
Rails Patches Critical Active Storage Flaw That Enables Remote Code Execution
A critical arbitrary file read vulnerability in Rails' Active Storage component can expose secrets and escalate to RCE, with public proof-of-concept exploits…
Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service
Wiz researchers found a sandbox escape in Azure Cosmos DB's Gremlin API that led to a platform-wide master key, potentially granting full…
Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV
A static low-privilege credential baked into Cisco Secure Firewall Management Center software is being actively exploited, prompting hot fixes, IOC guidance, and…
Arista Patches Max-Severity VeloCloud Orchestrator Flaw Under Active Attack
CVE-2026-16812, an unauthenticated command injection flaw scoring a perfect 10.0, is being exploited against on-premises VeloCloud Orchestrator deployments. CISA has added it…
OpenAI Models Exploited Artifactory Zero-Days to Break Out of Test Sandbox
JFrog has confirmed that OpenAI's models found and chained previously unknown Artifactory vulnerabilities to escape an isolated evaluation environment, setting up a…
Russian APT ‘Laundry Bear’ Exploited Zimbra Zero-Day to Steal Email at Scale
A joint advisory from CISA, NSA, FBI and international partners details a Russian state-supported campaign that used a zero-click Zimbra Collaboration Suite…
Check Point Zero-Day Under Active Attack, CISA Sets July 25 Deadline
A critical authentication bypass in Check Point's Security Management and Multi-Domain Management products is being exploited against internet-exposed environments, prompting an emergency…
Attackers Mass-Exploit wp2shell WordPress Flaws to Plant Webshells
Threat actors are chaining two critical WordPress Core vulnerabilities dubbed wp2shell to deploy PHP webshells, install malicious plugins, and harvest credentials on…
Critical SharePoint RCE Flaw Under Active Exploitation, Attackers Stealing Machine Keys
Hackers began exploiting CVE-2026-50522 within hours of a public PoC release, stealing SharePoint machine keys to maintain persistent access even after servers…
ServiceNow Sandbox Escape Bug Exploited Days After Patch, Details Disputed
A critical unauthenticated remote code execution flaw in ServiceNow's AI platform, patched on July 14, is reportedly under active exploitation, though the…
Critical ServiceNow RCE Flaw (CVE-2026-6875) Now Under Active Exploitation
Threat intelligence firm Defused says attackers are exploiting a critical unauthenticated sandbox-escape vulnerability in the ServiceNow AI Platform, days after patches were…
Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse
F5 has patched a critical heap buffer overflow in nginx that lets unauthenticated attackers crash worker processes with crafted HTTP requests, with…