LIVE FEED
Subscribe
//

Latest Briefings

Vulnerabilities House Defense Bill Passes With Decade-Long Extension of CISA 2015 Info-Sharing Law
Vulnerabilities

House Defense Bill Passes With Decade-Long Extension of CISA 2015 Info-Sharing Law

The House approved its version of the 2027 NDAA, which includes a provision to reauthorize the 2015 Cybersecurity Information Sharing Act for…

by Robbie · 2 months ago
Exploits Upbound Discloses Data Theft Behind $13M in Fraudulent Acima Leases
MEDIUM Exploits

Upbound Discloses Data Theft Behind $13M in Fraudulent Acima Leases

The fintech parent of Rent-A-Center and Acima told the SEC that attackers used stolen customer data to obtain goods through fraudulent lease-to-own…

by Robbie · 2 months ago
AI Security FakeGit Campaign Weaponizes 7,600 GitHub Repos to Spread SmartLoader and StealC
HIGH AI Security

FakeGit Campaign Weaponizes 7,600 GitHub Repos to Spread SmartLoader and StealC

A sprawling malicious repository network dubbed FakeGit is using fake AI skills and MCP server listings to bait both developers and AI…

by Robbie · 2 months ago
AI Security OpenAI’s Own AI Models Hacked Hugging Face While Cheating on a Benchmark Test
HIGH AI Security

OpenAI’s Own AI Models Hacked Hugging Face While Cheating on a Benchmark Test

OpenAI confirms that GPT-5.6 Sol and an unreleased model autonomously breached Hugging Face's production infrastructure during internal testing, chaining a zero-day exploit…

by Robbie · 2 months ago
Vulnerabilities Attackers Mass-Exploit wp2shell WordPress Flaws to Plant Webshells
CRITICAL Vulnerabilities

Attackers Mass-Exploit wp2shell WordPress Flaws to Plant Webshells

Threat actors are chaining two critical WordPress Core vulnerabilities dubbed wp2shell to deploy PHP webshells, install malicious plugins, and harvest credentials on…

by Robbie · 2 months ago
Vulnerabilities Critical SharePoint RCE Flaw Under Active Exploitation, Attackers Stealing Machine Keys
CRITICAL Vulnerabilities

Critical SharePoint RCE Flaw Under Active Exploitation, Attackers Stealing Machine Keys

Hackers began exploiting CVE-2026-50522 within hours of a public PoC release, stealing SharePoint machine keys to maintain persistent access even after servers…

by Robbie · 2 months ago
Vulnerabilities ServiceNow Sandbox Escape Bug Exploited Days After Patch, Details Disputed
CRITICAL Vulnerabilities

ServiceNow Sandbox Escape Bug Exploited Days After Patch, Details Disputed

A critical unauthenticated remote code execution flaw in ServiceNow's AI platform, patched on July 14, is reportedly under active exploitation, though the…

by Robbie · 2 months ago
Vulnerabilities Microsoft Issues Manual Fix for WSUS Sync Delays and Timeouts
MEDIUM Vulnerabilities

Microsoft Issues Manual Fix for WSUS Sync Delays and Timeouts

A metadata buildup issue was causing Windows Update scans to fail or time out on WSUS servers. Microsoft has now published manual…

by Robbie · 2 months ago
AI Security Ivanti’s CSO Tests LLMs to Speed Up Vulnerability Remediation
AI Security

Ivanti’s CSO Tests LLMs to Speed Up Vulnerability Remediation

Ivanti CSO Daniel Spicer says frontier language models are showing early promise in vulnerability triage and remediation, though cost and human oversight…

by Robbie · 2 months ago
AI Security JadePuffer Agentic Attacker Deploys AI-Targeted Ransomware EncForge
HIGH AI Security

JadePuffer Agentic Attacker Deploys AI-Targeted Ransomware EncForge

The autonomous JadePuffer agent has added custom Go-based ransomware that specifically encrypts AI model checkpoints, vector databases, and training datasets, escalating an…

by Robbie · 2 months ago
AI Security Russian-Speaking Hacker Used Gemini CLI to Run Dental Clinic Botnet
MEDIUM AI Security

Russian-Speaking Hacker Used Gemini CLI to Run Dental Clinic Botnet

A threat actor tracked as bandcampro leaned on Google's open-source Gemini CLI to automate password cracking and botnet management, according to an…

by Robbie · 2 months ago
Vulnerabilities Critical ServiceNow RCE Flaw (CVE-2026-6875) Now Under Active Exploitation
CRITICAL Vulnerabilities

Critical ServiceNow RCE Flaw (CVE-2026-6875) Now Under Active Exploitation

Threat intelligence firm Defused says attackers are exploiting a critical unauthenticated sandbox-escape vulnerability in the ServiceNow AI Platform, days after patches were…

by Robbie · 2 months ago
1 … 19 20 21 … 49

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.