Latest Briefings
Trump Administration Launches AI-Driven ‘Gold Eagle’ Vulnerability Clearinghouse
A new Treasury-housed initiative uses artificial intelligence, including closed-source models, to detect, validate and coordinate patching of software vulnerabilities across government and…
Zoom Patches Critical Windows Flaw That Allows Unauthenticated Account Takeover
Zoom has disclosed a critical, internally discovered vulnerability in its Windows desktop client, VDI client, and Meeting SDK that could let an…
Threat Actor Turns Google Gemini CLI Into a Botnet Operator
Researchers found a Russian-speaking attacker using Gemini CLI as an autonomous hacking agent, tasking it to run C2 infrastructure, migrate servers, and…
Researcher Drops Second Windows Zero-Day PoC in a Month
A security researcher who previously published a Windows Defender exploit has now released a proof-of-concept for a User Profile Service privilege escalation…
ICS Patch Tuesday: Siemens, Schneider, Rockwell Fix Critical Flaws in July 2026
Siemens leads July's ICS Patch Tuesday with a maximum-severity authentication bypass in Opencenter X, while Rockwell and Schneider Electric address critical and…
Progress Confirms Zero-Day Behind ShareFile Outage, Restores Access
Progress Software says a path traversal zero-day in ShareFile Storage Zones Controller prompted an emergency shutdown of customer servers, with patched access…
Nearly 300 Fake GitHub Repos Used to Push BoryptGrab Infostealer
A Russia-linked campaign impersonated legitimate security, crypto, and developer tools across 292 GitHub repositories to trick users into downloading a memory-resident infostealer.
US Unseals Indictment, Offers $10M Bounty Over Russian Bulletproof Hosting Ring
Federal prosecutors have unsealed charges against three Russian nationals accused of running Media Land and ML Cloud, bulletproof hosting services that allegedly…
SAP Patches Critical CVSS 9.9 NetWeaver Flaw Among 16 July Fixes
SAP's July 2026 patch batch closes three critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud, headlined by a near-maximum-severity memory corruption bug…
SonicWall SMA1000 Zero-Days Under Active Attack, CISA Sets Federal Patch Deadline
SonicWall confirms two SMA1000 vulnerabilities, including a maximum-severity SSRF flaw, are being exploited in the wild. CISA has added both to its…
Microsoft Ships Windows 10 KB5099539, Bundling Record July Patch Tuesday Fixes
The extended security update patches July 2026's record-breaking 570 vulnerabilities for ESU-enrolled and LTSC devices, while adding networking hardening and RDP certificate…
Microsoft’s July Patch Tuesday Sets Record With 622 Fixes, Two Zero-Days Under Attack
Microsoft's largest security update on record addresses 622 vulnerabilities this month, including actively exploited flaws in Active Directory Federation Services and SharePoint…