Latest Briefings
Google Loses Final EU Appeal, Owes €4.1 Billion in Android Antitrust Fine
The Court of Justice of the European Union has dismissed Google's last appeal against a €4.1 billion antitrust fine, affirming that Android…
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe released security updates for ColdFusion and Campaign Classic addressing 12 vulnerabilities, including seven rated at maximum severity with CVSS scores of…
Supreme Court Ruling Puts EU-US Data Privacy Framework at Risk
A U.S. Supreme Court decision allowing presidents to fire FTC commissioners at will has triggered legal threats against the EU-US Data Privacy…
SimpleHelp Auth Bypass Exploited to Drop TaskWeaver and Djinn Stealer
Attackers are actively exploiting a maximum-severity authentication bypass in SimpleHelp to deliver two newly identified malware families, with the infostealer component targeting…
CISA Adds Exploited SharePoint RCE Flaw to KEV, Orders Federal Patch
A high-severity deserialization vulnerability in Microsoft SharePoint is now actively exploited, prompting CISA to mandate federal agencies patch within three days under…
Defending Against Prompt Injection in AI Applications
Prompt injection is the top security risk for tool-using AI systems. Here is how attacks work, why they are so dangerous in…
Quest NetVault Backup SQL Injection Flaw Enables Remote Code Execution
A high-severity SQL injection vulnerability in Quest NetVault Backup allows authenticated attackers to execute arbitrary code remotely, with the added complication that…
Unraid File Upload Flaw Enables Authenticated RCE, Patched in 7.3.0
A command injection vulnerability in Unraid's FileUpload.php allows authenticated remote attackers to execute arbitrary code. A fix is available in Unraid version…
X.Org Server Use-After-Free Bug Enables Local Privilege Escalation to Root
A use-after-free vulnerability in X.Org Server's SyncAwait object handling allows a local attacker with low privileges to escalate to root. A patch…
FBI Seizes NetNut Proxy Platform and Popa Botnet Infrastructure
The FBI, working with Google, Lumen, and Shadowserver, seized hundreds of domains tied to NetNut and the Popa botnet, a network of…
UK National Cyber Action Plan Delayed by Labour Leadership Crisis
Britain's forthcoming cybersecurity strategy has been postponed again following Prime Minister Keir Starmer's resignation, raising fresh concerns about the country's commitment to…
How Unit 42 Built WebAuthn Redirection Into a Browser-Based RDP Client
Palo Alto Networks' Unit 42 engineered WebAuthn virtual channel support directly into a browser-native RDP client, a feat that required reverse-engineering undocumented…