Latest Briefings
North Korean Hackers Hide OtterCookie Malware Inside SVG Flag Images
The Contagious Interview campaign is using steganography in SVG files to sneak a four-stage payload past victims lured by fake job postings…
Weekly Roundup: Iran Tracks US Troops via Ad Data, CrashStealer Hits macOS, New CVD Blueprint
This week's cybersecurity digest covers Iran-linked tracking of US military phones through ad tech and roaming data, a stealthy new macOS infostealer,…
Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access
The Inc ransomware group is exploiting two previously unknown vulnerabilities in SonicWall's Secure Mobile Access appliances, chaining the flaws to achieve root-level…
Unauthenticated RCE Flaw in WordPress Core Patched via Forced Updates
A critical WordPress core vulnerability, dubbed wp2shell, allowed unauthenticated attackers to execute code on any 6.9 or 7.0 site with a single…
Ernst & Young Discloses Breach Tied to Third-Party Support Ticket System
A compromised support platform used by EY's IT staff exposed client documents containing tax and financial information, with unauthorized access dating back…
HollowByte: 11-Byte Payload Can Bloat OpenSSL Server Memory to Exhaustion
An unauthenticated denial-of-service flaw dubbed HollowByte lets attackers exploit how OpenSSL handles TLS handshake length headers, forcing servers to allocate memory that…
Supply Chain Security Startup Risk Ledger Lands $32M Series B
UK-based Risk Ledger closed a £24 million Series B led by Axiom Equity to expand its supplier risk network, add AI-driven review…
CISA Adds Actively Exploited SharePoint RCE Flaw CVE-2026-58644 to KEV Catalog
A critical deserialization bug in on-premises SharePoint Server has joined at least three other actively exploited flaws under active attack, with CISA…
Ukrainians Protest Ouster of Drone-Focused Defense Minister Fedorov
Thousands rallied across Ukraine after President Zelensky abruptly dismissed Defense Minister Mykhailo Fedorov, the former digital transformation chief credited with accelerating drone…
Agentic AI Is Untamable: Security Teams Need New Questions, Not New Tools
Dark Reading argues that agentic AI's core risk isn't external attackers exploiting it, but the technology's own autonomous behavior, demanding a fundamental…
Ransomware Attack on Coca-Cola’s Fairlife Halts US Dairy Production
Coca-Cola disclosed in an SEC filing that a ransomware intrusion at its Fairlife dairy subsidiary forced a temporary suspension of US production,…
New ClickLock macOS Malware Locks Out Users Until They Type Their Password
Group-IB has identified a new macOS stealer called ClickLock that freezes the system and repeatedly kills processes to coerce victims into typing…