Latest Briefings
North Korean PolinRider Campaign Poisons Open Source Packages Across Ecosystems
A North Korean supply chain operation active since December 2025 has compromised over 100 open source packages across NPM, Packagist, Go modules,…
Max-Severity Adobe ColdFusion Flaw Exploited Within Hours of Disclosure
A critical remote code execution vulnerability in Adobe ColdFusion is under active attack, with exploitation observed less than two hours after Adobe…
Russian Hackers Make Ukrainian Media Outlets a Priority Target
Ukraine's SBU warns that Russian cyber operations against broadcasters are intensifying, combining phishing, DDoS, and propaganda injection attempts alongside physical missile strikes…
Armored Likho APT Hits Government and Power Sectors with Modular Malware
Kaspersky has detailed a newly identified APT group targeting government and electric power organizations in Russia, Brazil, and Kazakhstan using spear-phishing campaigns…
Exploit Attempts Hit Gitea Docker Flaw CVE-2026-20896 Within Two Weeks of Patch
Threat actors are actively probing a critical Gitea Docker vulnerability that allows unauthenticated clients to gain elevated access by spoofing a trusted…
Japanese Teen Arrested for Cyberattack That Canceled 46,000 Anime Subscriptions
A 15-year-old near Tokyo allegedly exploited a server vulnerability in Bandai Channel, using a ChatGPT-assisted tool to mass-cancel user accounts and force…
16-Year-Old Linux KVM Flaw Allows Guest VMs to Escape to Host
A use-after-free vulnerability in Linux's KVM hypervisor, present in shared shadow MMU code for both Intel and AMD x86 systems, can be…
Medtronic Notifies 3.8 Million Patients After ShinyHunters-Linked Breach
The world's largest medical device maker has begun notifying nearly 4 million people that hackers accessed sensitive personal and health-related data from…
Vietnam Arrests Seven Suspects Behind HiAnime Anime Piracy Network
Vietnamese authorities have charged seven individuals believed to operate HiAnime, once the world's largest anime piracy platform, with copyright infringement and money…
Pixel 10 Embeds C2PA Content Credentials at Highest Assurance Level
Google's Pixel 10 lineup becomes the first mobile platform to achieve C2PA Assurance Level 2, using hardware-backed security to attach verifiable provenance…
SkillCloak Technique Lets Malicious AI Agent Skills Bypass Static Scanners
Researchers at Hong Kong University of Science and Technology have demonstrated a self-extracting packing technique that evades static security scanners for AI…
Opera GX Flaw Allowed Malicious Sites to Silently Install Data-Stealing Mods
A vulnerability in the gaming-focused Opera GX browser let attacker-controlled websites auto-install a browser add-on and extract data from pages the victim…