LIVE FEED
Subscribe
//

Latest Briefings

Research HelloNet Campaign Hijacks ViPNet Updates to Hit Russian Government Networks
HIGH Research

HelloNet Campaign Hijacks ViPNet Updates to Hit Russian Government Networks

A threat actor tracked as HelloNet has been sideloading malicious code into Russia's widely certified ViPNet networking suite since May, deploying a…

by Robbie · 2 months ago
Vulnerabilities Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse
CRITICAL Vulnerabilities

Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse

F5 has patched a critical heap buffer overflow in nginx that lets unauthenticated attackers crash worker processes with crafted HTTP requests, with…

by Robbie · 2 months ago
AI Security EU Forces Google to Give Rival AI Assistants Same Android Access as Gemini
MEDIUM AI Security

EU Forces Google to Give Rival AI Assistants Same Android Access as Gemini

The European Commission has ordered Google to open Android's camera, microphone, screen contents and background app control to competing AI assistants, with…

by Robbie · 2 months ago
AI Security Podcast: ICS Security Veteran Reveals Open-Source Agentic AI Project MindStone
AI Security

Podcast: ICS Security Veteran Reveals Open-Source Agentic AI Project MindStone

In a SecurityWeek interview, industrial cybersecurity expert Clint Bodungen discusses failures in traditional security governance and unveils MindStone Agent, an open-source project…

by Robbie · 2 months ago
AI Security Google Cloud Folds Wiz Capabilities Into Agentic Defense Platform
AI Security

Google Cloud Folds Wiz Capabilities Into Agentic Defense Platform

Google Cloud is betting that autonomous, AI-driven defense tools can detect and remediate threats faster than human-led security operations, folding Wiz's cloud…

by Robbie · 2 months ago
Research Carders Move Beyond Residential Proxies as ‘Clean’ IPs Become Scarce
Research

Carders Move Beyond Residential Proxies as ‘Clean’ IPs Become Scarce

Analysis of nearly 2,900 underground forum posts shows carding actors treating residential proxies as one fragile layer in a broader identity-simulation stack,…

by Robbie · 2 months ago
Research DigiCert Breach Tied to CylindricalCanine, a GoldenEyeDog Subgroup
HIGH Research

DigiCert Breach Tied to CylindricalCanine, a GoldenEyeDog Subgroup

Researchers at Expel have attributed the April 2026 DigiCert security incident to CylindricalCanine, a newly identified subgroup of the Chinese cybercrime cluster…

by Robbie · 2 months ago
Vulnerabilities 7-Zip 26.02 Patches Heap Overflow RCE Flaw in XZ Archive Handling
HIGH Vulnerabilities

7-Zip 26.02 Patches Heap Overflow RCE Flaw in XZ Archive Handling

7-Zip has fixed a remote code execution vulnerability in its XZ decompression code that can be triggered by opening a maliciously crafted…

by Robbie · 2 months ago
Exploits Microsoft Flags Surge in ACR Stealer Attacks Using ClickFix and WebDAV Tricks
HIGH Exploits

Microsoft Flags Surge in ACR Stealer Attacks Using ClickFix and WebDAV Tricks

Microsoft says attackers ramped up ACR Stealer campaigns between late April and mid-June, using ClickFix social engineering, WebDAV shares, and MSHTA to…

by Robbie · 2 months ago
Vulnerabilities WordPress Core wp2shell RCE Chain Gets Public Exploits, Patch Immediately
CRITICAL Vulnerabilities

WordPress Core wp2shell RCE Chain Gets Public Exploits, Patch Immediately

Two chained flaws in WordPress Core allow unauthenticated remote code execution against stock installs, and public proof-of-concept exploits are now circulating with…

by Robbie · 2 months ago
AI Security New NadMesh Botnet Scans for Exposed AI Tools to Steal Cloud Keys
HIGH AI Security

New NadMesh Botnet Scans for Exposed AI Tools to Steal Cloud Keys

A Go-based botnet dubbed NadMesh is scanning the internet for unsecured AI services like ComfyUI, Ollama, and Open WebUI, harvesting AWS keys…

by Robbie · 2 months ago
Exploits Abbott Investigates Two Separate Breaches Amid ShinyHunters Extortion Threat
HIGH Exploits

Abbott Investigates Two Separate Breaches Amid ShinyHunters Extortion Threat

Abbott Laboratories is probing unauthorized access to legacy Exact Sciences systems claimed by ShinyHunters, plus a second alleged breach of its LabCentral…

by Robbie · 2 months ago
1 … 20 21 22 … 49

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.