Latest Briefings
Accenture Confirms Breach After Hacker Lists 35 GB of Stolen Data
A threat actor known as '888' claims to have exfiltrated 35 GB of source code, credentials, and configuration files from Accenture, and…
CISA Orders Federal Agencies to Patch Actively Exploited Langflow Auth Bypass
CISA has added a Langflow authorization bypass flaw to its KEV catalog and given federal civilian agencies until Friday to apply patches,…
Supreme Court Lets Texas App Age Verification Law Take Effect
The Supreme Court declined to block the Texas App Store Accountability Act, allowing enforcement to proceed while a federal appeals court considers…
RedWing MaaS Brings Android Bank Fraud to Telegram as a Rental Service
A newly discovered Android malware operation called RedWing is being offered on Telegram as a turnkey bank-fraud service, lowering the bar for…
Critical Gitea Auth Bypass Flaw Under Active Exploitation
A critical vulnerability in Gitea's Docker images allows attackers to impersonate any user with a single HTTP header. Exploitation began just 13…
Ohio County Paid $1M Ransom to Kairos Extortion Group After Data Theft
Union County, Ohio reportedly paid $1 million in Bitcoin to prevent the release of 2 terabytes of stolen data, following a May…
UAT-7810 Deploys LONGLEASH Malware to Expand China-Linked ORB Network
Cisco Talos has uncovered a new malware family called LONGLEASH, along with three supporting tools, being used by the Chinese threat group…
Januscape: 16-Year-Old Linux KVM Flaw Enables VM Escape on Intel and AMD
A use-after-free bug in the Linux kernel's KVM shadow MMU lets an attacker with guest root access execute code on the host,…
Hidden Backdoor in Tenda Router Firmware Grants Admin Access
A hardcoded secondary authentication mechanism in multiple Tenda router firmware versions allows any attacker who knows the backdoor password to gain full…
Microsoft to Enable Windows Settings Backup by Default in Windows 11 26H2
Microsoft is shifting its enterprise Windows settings backup tool from opt-in to enabled by default for Entra-joined devices starting with Windows 11…
BeyondTrust Patches Critical Auth Bypass Flaws in RS and PRA Software
BeyondTrust has disclosed two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access products, urging self-hosted customers to apply…
PoC Exploit Released for Linux ‘Bad Epoll’ Root Privilege Escalation Bug
A public proof-of-concept exploit now targets a race-condition use-after-free flaw in the Linux kernel's epoll subsystem, enabling unprivileged local attackers to gain…