Latest Briefings
European Parliament Revives CSAM Scanning Law Amid Procedural Controversy
A last-minute vote using an unusual absolute-majority procedure has extended legal cover for voluntary CSAM scanning by tech platforms through 2028, even…
Ghostcommit: Researchers Hide Prompt Injection in Images to Loot Secrets via AI Agents
A proof-of-concept attack from UMKC's ASSET Research Group buries data-exfiltration instructions inside a PNG that AI code reviewers never open, then waits…
Australia Warns of Global Webshell Campaign Hitting Vulnerable CMS Platforms
The Australian Cyber Security Centre says a large-scale exploitation campaign is deploying webshells across WordPress, Craft CMS, Joomla and other platforms worldwide,…
Dormant GitHub Ghost Accounts Fuel Mass Reconnaissance Campaign
Datadog researchers say over 50 dormant GitHub accounts, some registered years ago, are being used to systematically enumerate organizations, repositories, and users…
Balochistan Police Portal Compromised in Multi-Group Espionage Campaign
Researchers say suspected China- and India-aligned threat actors breached servers tied to a Pakistani police portal over more than two years, exposing…
Malicious jscrambler npm Package Drops Rust Infostealer at Install Time
A compromised 8.14.0 release of the jscrambler npm package used a preinstall hook to silently execute native infostealer binaries on Windows, macOS,…
Six U-Boot Flaws Could Let Attackers Hijack Devices Before the OS Even Loads
Firmware security firm Binarly has disclosed six vulnerabilities in U-Boot's image signature verification code, two of which allow arbitrary code execution during…
Critical Zimbra Classic Web Client Flaw Lets Emails Execute Malicious Code
Zimbra is pushing urgent updates for a critical stored XSS vulnerability in its Classic Web Client that lets specially crafted emails run…
Zimbra Patches Critical XSS Flaw in Classic Web Client After Google TAG Report
Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, flagged by Google's Threat Analysis…
Unpatched XRING Bug in Alibaba’s XQUIC Lets Remote Clients Crash HTTP/3 Servers
A single-line variable error in Alibaba's XQUIC library allows unauthenticated attackers to crash HTTP/3 servers with a short burst of valid QPACK…
China and India Linked Hackers Both Breached Pakistan’s Balochistan Police
SentinelLabs uncovered more than two years of overlapping espionage inside Pakistani law enforcement networks, with China linked and India linked groups independently…
Third Ex-Security Pro Sentenced for Feeding Data to BlackCat Ransomware Gang
Florida-based negotiator Angelo Martino received 70 months in prison for secretly helping BlackCat/Alphv extort at least five victims, marking the third such…