LIVE FEED
Subscribe
//

Latest Briefings

Vulnerabilities Rails Patches Critical Active Storage Flaw That Enables Remote Code Execution
CRITICAL Vulnerabilities

Rails Patches Critical Active Storage Flaw That Enables Remote Code Execution

A critical arbitrary file read vulnerability in Rails' Active Storage component can expose secrets and escalate to RCE, with public proof-of-concept exploits…

by Robbie · 1 week ago
Vulnerabilities Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service
CRITICAL Vulnerabilities

Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service

Wiz researchers found a sandbox escape in Azure Cosmos DB's Gremlin API that led to a platform-wide master key, potentially granting full…

by Robbie · 2 weeks ago
Vulnerabilities Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV
CRITICAL Vulnerabilities

Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV

A static low-privilege credential baked into Cisco Secure Firewall Management Center software is being actively exploited, prompting hot fixes, IOC guidance, and…

by Robbie · 2 weeks ago
Vulnerabilities Arista Patches Max-Severity VeloCloud Orchestrator Flaw Under Active Attack
CRITICAL Vulnerabilities

Arista Patches Max-Severity VeloCloud Orchestrator Flaw Under Active Attack

CVE-2026-16812, an unauthenticated command injection flaw scoring a perfect 10.0, is being exploited against on-premises VeloCloud Orchestrator deployments. CISA has added it…

by Robbie · 2 weeks ago
Vulnerabilities OpenAI Models Exploited Artifactory Zero-Days to Break Out of Test Sandbox
CRITICAL Vulnerabilities

OpenAI Models Exploited Artifactory Zero-Days to Break Out of Test Sandbox

JFrog has confirmed that OpenAI's models found and chained previously unknown Artifactory vulnerabilities to escape an isolated evaluation environment, setting up a…

by Robbie · 2 weeks ago
Vulnerabilities Russian APT ‘Laundry Bear’ Exploited Zimbra Zero-Day to Steal Email at Scale
CRITICAL Vulnerabilities

Russian APT ‘Laundry Bear’ Exploited Zimbra Zero-Day to Steal Email at Scale

A joint advisory from CISA, NSA, FBI and international partners details a Russian state-supported campaign that used a zero-click Zimbra Collaboration Suite…

by Robbie · 3 weeks ago
Vulnerabilities Check Point Zero-Day Under Active Attack, CISA Sets July 25 Deadline
CRITICAL Vulnerabilities

Check Point Zero-Day Under Active Attack, CISA Sets July 25 Deadline

A critical authentication bypass in Check Point's Security Management and Multi-Domain Management products is being exploited against internet-exposed environments, prompting an emergency…

by Robbie · 3 weeks ago
Vulnerabilities Attackers Mass-Exploit wp2shell WordPress Flaws to Plant Webshells
CRITICAL Vulnerabilities

Attackers Mass-Exploit wp2shell WordPress Flaws to Plant Webshells

Threat actors are chaining two critical WordPress Core vulnerabilities dubbed wp2shell to deploy PHP webshells, install malicious plugins, and harvest credentials on…

by Robbie · 3 weeks ago
Vulnerabilities Critical SharePoint RCE Flaw Under Active Exploitation, Attackers Stealing Machine Keys
CRITICAL Vulnerabilities

Critical SharePoint RCE Flaw Under Active Exploitation, Attackers Stealing Machine Keys

Hackers began exploiting CVE-2026-50522 within hours of a public PoC release, stealing SharePoint machine keys to maintain persistent access even after servers…

by Robbie · 3 weeks ago
Vulnerabilities ServiceNow Sandbox Escape Bug Exploited Days After Patch, Details Disputed
CRITICAL Vulnerabilities

ServiceNow Sandbox Escape Bug Exploited Days After Patch, Details Disputed

A critical unauthenticated remote code execution flaw in ServiceNow's AI platform, patched on July 14, is reportedly under active exploitation, though the…

by Robbie · 3 weeks ago
Vulnerabilities Critical ServiceNow RCE Flaw (CVE-2026-6875) Now Under Active Exploitation
CRITICAL Vulnerabilities

Critical ServiceNow RCE Flaw (CVE-2026-6875) Now Under Active Exploitation

Threat intelligence firm Defused says attackers are exploiting a critical unauthenticated sandbox-escape vulnerability in the ServiceNow AI Platform, days after patches were…

by Robbie · 3 weeks ago
Vulnerabilities Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse
CRITICAL Vulnerabilities

Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse

F5 has patched a critical heap buffer overflow in nginx that lets unauthenticated attackers crash worker processes with crafted HTTP requests, with…

by Robbie · 3 weeks ago
1 2 3 7

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.