Latest Briefings
Chrome 152 Fixes Over 300 Bugs, Most Found by Google’s AI Tools
Google's latest Chrome release patches 327 vulnerabilities, including 10 critical use-after-free flaws, with the vast majority uncovered internally through AI-assisted vulnerability research.
Attackers Chain miniOrange SAML Bugs for WordPress Admin Takeover
Two unauthenticated auth bypass flaws in the Xecurify miniOrange SAML SSO plugin are being actively exploited to forge signatures and hijack WordPress…
Microsoft Warns of Max-Severity Entra ID RCE Flaw Exploited in the Wild
Microsoft disclosed a CVSS 10.0 remote code execution vulnerability in Entra ID that has already been exploited, though it says customers do…
Critical Elementor Pro Flaw Lets Attackers Upload PHP and Execute Code
A CVSS 9.0 vulnerability in Elementor Pro's File Upload module lets attackers smuggle malicious PHP past validation and execute it on WordPress…
Citrix Patches Critical NetScaler Auth Bypass, Exploitation Expected Soon
A critical authentication bypass flaw in NetScaler ADC and Gateway lets unauthenticated attackers slip past login controls, and Rapid7 warns active exploitation…
Clop’s Custom-Built Web Shell Targets PTC Windchill Internals Directly
ReliaQuest found that a JSP web shell used in recent Windchill data-theft attacks was purpose-built to abuse the application's own credential-decryption and…
Critical SAP Commerce Cloud Flaw Exploited Just Days After Patch Release
A maximum-severity vulnerability in SAP Commerce Cloud, CVE-2026-58231, is already under active attack after threat intelligence firms spotted exploitation attempts within days…
Max-Severity SAP Commerce Cloud RCE Exploited Just Days After Patch
A CVSS 10.0 unauthenticated remote code execution flaw in SAP Commerce Cloud's Data Hub Adapter is already being hit in the wild,…
Attackers Exploit Critical VMware vCenter Flaw CVE-2026-59310 Within Days of Patch
An APT actor is exploiting a critical directory traversal and RCE bug in VMware vCenter's Syslog server, hitting over 360 IP addresses…
Microsoft’s August Patch Tuesday Fixes Nearly 400 Flaws, One Under Active Attack
Microsoft's latest security update addresses 398 vulnerabilities, including an actively exploited Windows privilege escalation bug, as AI-assisted discovery continues to drive record…
CISA Confirms Active Exploitation of Critical Kemp LoadMaster RCE Flaw
A command injection bug in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is being actively exploited in the wild, prompting CISA to add…
Critical Flaws in Belgian eID Software Exposed 2 Million Users to Identity Theft
A researcher at DEF CON detailed now-patched vulnerabilities in Connective's digital identity browser extension that let malicious websites steal eID PINs, forge…