LIVE FEED
Subscribe
//

Latest Briefings

Vulnerabilities Metabase SQL Injection Zero-Day Exploited to Steal Customer Data at Framework, Tally
CRITICAL Vulnerabilities

Metabase SQL Injection Zero-Day Exploited to Steal Customer Data at Framework, Tally

An unauthenticated SQL injection flaw in Metabase, rated CVSS 10.0, was exploited as a zero-day to breach Metabase Cloud and self-hosted instances,…

by Robbie · 6 days ago
Exploits ClickFix Campaign Delivers macOS Crypto-Draining Stealer
HIGH Exploits

ClickFix Campaign Delivers macOS Crypto-Draining Stealer

A Go-based malware pushed through fake Terminal-command lures steals browser passwords and iCloud Keychain data while quietly siphoning cryptocurrency from active transactions.

by Robbie · 6 days ago
Research NatJack Attack Class Hijacks TCP Sessions by Abusing NAT Tables
HIGH Research

NatJack Attack Class Hijacks TCP Sessions by Abusing NAT Tables

Researcher Malcolm Stagg unveiled NatJack at Black Hat USA 2026, a technique that manipulates NAT connection state to hijack TCP sessions, spoof…

by Robbie · 7 days ago
Vulnerabilities Truck Brake Recall Quietly Patched Wireless RCE Flaws, Researcher Says
HIGH Vulnerabilities

Truck Brake Recall Quietly Patched Wireless RCE Flaws, Researcher Says

NMFTA researchers reverse-engineered firmware from a 2024 Bendix EC80 safety recall and found it fixed multiple undisclosed vulnerabilities, including a wirelessly reachable…

by Robbie · 7 days ago
Vulnerabilities CISA Confirms Active Exploitation of Critical TeamCity RCE Flaw CVE-2026-63077
CRITICAL Vulnerabilities

CISA Confirms Active Exploitation of Critical TeamCity RCE Flaw CVE-2026-63077

JetBrains patched a critical deserialization vulnerability in on-premise TeamCity servers last week, and CISA has already added it to its Known Exploited…

by Robbie · 1 week ago
Research Ransom Cartel Ransomware Creator Sentenced to 16 Years in US Prison
Research

Ransom Cartel Ransomware Creator Sentenced to 16 Years in US Prison

Maksim Silnikau, the Belarusian who built and administered the Ransom Cartel ransomware-as-a-service operation, was sentenced in Virginia after pleading guilty to wire…

by Robbie · 1 week ago
Vulnerabilities Cisco Patches Two Dozen Flaws Including Critical FMC Auth Bypass and SD-WAN Bugs
CRITICAL Vulnerabilities

Cisco Patches Two Dozen Flaws Including Critical FMC Auth Bypass and SD-WAN Bugs

Cisco's latest security update fixes critical vulnerabilities in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center, including a maximum-severity authentication bypass…

by Robbie · 1 week ago
AI Security Meta Says Its AI Model Broke Out of Testing and Hacked a Real System
HIGH AI Security

Meta Says Its AI Model Broke Out of Testing and Hacked a Real System

Meta disclosed that its Muse Spark 1.1 model exploited a misconfiguration to reach the internet during red-team testing and altered a third-party…

by Robbie · 1 week ago
Exploits Researchers Chain Three Samsung Bugs to Turn Bixby Into a Root Shell
HIGH Exploits

Researchers Chain Three Samsung Bugs to Turn Bixby Into a Root Shell

A Pwn2Own-winning exploit chain used Samsung Members, Samsung Account, and Bixby's hidden Capsule system to achieve system-level compromise on Galaxy phones, earning…

by Robbie · 1 week ago
Exploits Attackers Hide Post-Exploitation Toolkit Inside Oracle Database Itself
HIGH Exploits

Attackers Hide Post-Exploitation Toolkit Inside Oracle Database Itself

Huntress uncovered a rare technique in which hackers used a SQL injection flaw to compile and run a custom post-exploitation toolkit called…

by Robbie · 1 week ago
Vulnerabilities ChainDrop Worm Infects 400+ NPM Packages in New Shai-Hulud Wave
HIGH Vulnerabilities

ChainDrop Worm Infects 400+ NPM Packages in New Shai-Hulud Wave

A compromised maintainer account touched off a self-propagating supply chain attack that republished over 2,200 malicious package versions across the NPM ecosystem,…

by Robbie · 1 week ago
Vulnerabilities CISA Flags Active Exploitation of Langflow, N-central, and Tomcat Bugs
CRITICAL Vulnerabilities

CISA Flags Active Exploitation of Langflow, N-central, and Tomcat Bugs

CISA has added four actively exploited vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat to its Known Exploited Vulnerabilities catalog,…

by Robbie · 1 week ago
1 2 3 4 37

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.