LIVE FEED
Subscribe
//

Latest Briefings

Vulnerabilities ChainDrop Worm Infects 400+ NPM Packages in New Shai-Hulud Wave
HIGH Vulnerabilities

ChainDrop Worm Infects 400+ NPM Packages in New Shai-Hulud Wave

A compromised maintainer account touched off a self-propagating supply chain attack that republished over 2,200 malicious package versions across the NPM ecosystem,…

by Robbie · 1 week ago
Vulnerabilities CISA Flags Active Exploitation of Langflow, N-central, and Tomcat Bugs
CRITICAL Vulnerabilities

CISA Flags Active Exploitation of Langflow, N-central, and Tomcat Bugs

CISA has added four actively exploited vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat to its Known Exploited Vulnerabilities catalog,…

by Robbie · 1 week ago
Exploits N-able Patches Second Auth Bypass Flaw Under Active Attack on N-central Servers
CRITICAL Exploits

N-able Patches Second Auth Bypass Flaw Under Active Attack on N-central Servers

N-able rushed out a hotfix after discovering that attackers were exploiting an incomplete patch for a prior authentication bypass, granting administrator access…

by Robbie · 1 week ago
Research DOUBLECUP LaaS Hides Malware in Cached PNGs via ClickFix Prompts
MEDIUM Research

DOUBLECUP LaaS Hides Malware in Cached PNGs via ClickFix Prompts

A new Russian loader-as-a-service called DOUBLECUP uses fake CAPTCHA lures to stash steganographic payloads in browser cache, delivering an updated CountLoader and…

by Robbie · 1 week ago
Research Liechtenstein Breach Exposes 31,000 Beneficial Ownership Records
HIGH Research

Liechtenstein Breach Exposes 31,000 Beneficial Ownership Records

Attackers accessed Liechtenstein's Register of Beneficial Owners for two days in late July, exfiltrating data tied to companies, foundations, and trusts before…

by Robbie · 1 week ago
Research New York Puts $9 Million Toward Securing 153 Water and Wastewater Systems
MEDIUM Research

New York Puts $9 Million Toward Securing 153 Water and Wastewater Systems

Governor Kathy Hochul announced the SECURE grant funding days after a coordinated attack campaign hit operational technology at water utilities across at…

by Robbie · 1 week ago
Exploits Coldcard Maker Destroys Vulnerable Inventory After $88M Bitcoin Theft
HIGH Exploits

Coldcard Maker Destroys Vulnerable Inventory After $88M Bitcoin Theft

Coinkite has scrapped remaining stock of its Coldcard hardware wallets after attackers exploited a years-old firmware flaw to drain more than $88…

by Robbie · 2 weeks ago
AI Security Anthropic Says Recent Claude Breaches Stemmed From Over-Permissioning, Not Model Flaws
MEDIUM AI Security

Anthropic Says Recent Claude Breaches Stemmed From Over-Permissioning, Not Model Flaws

Anthropic attributes last month's real-world security incidents involving its Claude models to excessive system permissions, particularly unrestricted internet access, rather than weaknesses…

by Robbie · 2 weeks ago
Vulnerabilities N-able N-central Flaw Let Attackers Seize Servers After Patch Failed
CRITICAL Vulnerabilities

N-able N-central Flaw Let Attackers Seize Servers After Patch Failed

An authentication bypass in N-able's N-central remote monitoring platform allowed attackers to gain full administrative control and pivot into customer environments, and…

by Robbie · 2 weeks ago
Research Microsoft Ties Midnight Blizzard to Captive Portal Wi-Fi Credential Theft Campaign
HIGH Research

Microsoft Ties Midnight Blizzard to Captive Portal Wi-Fi Credential Theft Campaign

Microsoft attributes the CaptiveCrunch campaign, which hijacked hotel and conference Wi-Fi captive portals to steal Microsoft 365 credentials, to Storm-2945, a subgroup…

by Robbie · 2 weeks ago
Vulnerabilities Chrome Set to Block Policy-Abused New Tab Hijacker Extensions
LOW Vulnerabilities

Chrome Set to Block Policy-Abused New Tab Hijacker Extensions

Google is developing a Chromium feature that stops malware from abusing enterprise policy mechanisms to force-install extensions that hijack the New Tab…

by Robbie · 2 weeks ago
Vulnerabilities COLDCARD RNG Bug Tied to $88.6M Bitcoin Wallet Heist
CRITICAL Vulnerabilities

COLDCARD RNG Bug Tied to $88.6M Bitcoin Wallet Heist

A flawed random number generator in COLDCARD hardware wallet firmware let attackers predict private keys offline, enabling a wave of automated thefts…

by Robbie · 2 weeks ago
1 3 4 5 38

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.