Latest Briefings
Metabase SQL Injection Zero-Day Exploited to Steal Customer Data at Framework, Tally
An unauthenticated SQL injection flaw in Metabase, rated CVSS 10.0, was exploited as a zero-day to breach Metabase Cloud and self-hosted instances,…
ClickFix Campaign Delivers macOS Crypto-Draining Stealer
A Go-based malware pushed through fake Terminal-command lures steals browser passwords and iCloud Keychain data while quietly siphoning cryptocurrency from active transactions.
NatJack Attack Class Hijacks TCP Sessions by Abusing NAT Tables
Researcher Malcolm Stagg unveiled NatJack at Black Hat USA 2026, a technique that manipulates NAT connection state to hijack TCP sessions, spoof…
Truck Brake Recall Quietly Patched Wireless RCE Flaws, Researcher Says
NMFTA researchers reverse-engineered firmware from a 2024 Bendix EC80 safety recall and found it fixed multiple undisclosed vulnerabilities, including a wirelessly reachable…
CISA Confirms Active Exploitation of Critical TeamCity RCE Flaw CVE-2026-63077
JetBrains patched a critical deserialization vulnerability in on-premise TeamCity servers last week, and CISA has already added it to its Known Exploited…
Ransom Cartel Ransomware Creator Sentenced to 16 Years in US Prison
Maksim Silnikau, the Belarusian who built and administered the Ransom Cartel ransomware-as-a-service operation, was sentenced in Virginia after pleading guilty to wire…
Cisco Patches Two Dozen Flaws Including Critical FMC Auth Bypass and SD-WAN Bugs
Cisco's latest security update fixes critical vulnerabilities in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center, including a maximum-severity authentication bypass…
Meta Says Its AI Model Broke Out of Testing and Hacked a Real System
Meta disclosed that its Muse Spark 1.1 model exploited a misconfiguration to reach the internet during red-team testing and altered a third-party…
Researchers Chain Three Samsung Bugs to Turn Bixby Into a Root Shell
A Pwn2Own-winning exploit chain used Samsung Members, Samsung Account, and Bixby's hidden Capsule system to achieve system-level compromise on Galaxy phones, earning…
Attackers Hide Post-Exploitation Toolkit Inside Oracle Database Itself
Huntress uncovered a rare technique in which hackers used a SQL injection flaw to compile and run a custom post-exploitation toolkit called…
ChainDrop Worm Infects 400+ NPM Packages in New Shai-Hulud Wave
A compromised maintainer account touched off a self-propagating supply chain attack that republished over 2,200 malicious package versions across the NPM ecosystem,…
CISA Flags Active Exploitation of Langflow, N-central, and Tomcat Bugs
CISA has added four actively exploited vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat to its Known Exploited Vulnerabilities catalog,…