Latest Briefings
Researchers Use Claude Opus 5 to Chain Flaws, Hijack OpenAI Staff Accounts
Security firm Hacktron used Anthropic's Claude Opus 5 to chain a help forum bug with an OpenAI login weakness, taking over employee…
BragJack: Malicious Extension Hijacks AI Browser Agents in Chrome, Edge, Comet, Opera Neon
Researcher Gal Weizman demonstrated how a single browser extension can seize control of built-in AI assistants across five Chromium based browsers, earning…
Critical Pre-Auth RCE in Orkes Conductor Exploited in the Wild
Fortinet warns that a critical unauthenticated remote code execution flaw in the Orkes Conductor workflow platform is being actively exploited, putting unpatched…
Maximum-Severity Cisco ISE Auth Bypass Added to CISA’s Exploited Vulnerability List
A perfect 10.0 CVSS flaw in Cisco Identity Services Engine is being actively exploited in the wild, prompting CISA to order federal…
Public Exploits Released for Four Linux Kernel Local Root Flaws
A researcher has published working exploit code for four separate Linux kernel vulnerabilities that allow a local user to escalate to root,…
Gyazo Breach Exposes 23.6 Million User Records After Server Flaw Exploited
Attackers exploited a vulnerability in Gyazo's image upload server to access a database containing tens of millions of user records and hundreds…
Cisco Patches Max-Severity ISE Zero-Day Under Active Exploitation
A CVSS 10.0 authentication bypass in Cisco Identity Services Engine and ISE-PIC is being actively exploited, letting unauthenticated attackers gain root-level access…
Check Point Patches Critical Root RCE Flaw in Management Servers
An unauthenticated attacker could exploit a buffer overflow in the login process of Check Point's Security Management and Log Servers to gain…
UN Launches Open-Source Data Commons Platform Built on Google’s AI-Ready Knowledge Graph
The UN System Data Commons unifies previously siloed statistics from across UN agencies into a single searchable, natural-language platform, with AI agents…
CISA Issues Guidance on Using Cyber Decoys to Catch Attackers Early
The agency's new playbook shows critical infrastructure operators how to deploy honeypots, honeytokens, and other decoy systems to detect intruders using legitimate…
FamousSparrow’s New SparroWocky Backdoor Hits Latin American Governments
ESET researchers tracked the China-linked espionage group deploying a heavily obfuscated new backdoor against government targets across Latin America for over a…
Google Patches Actively Exploited Pixel Modem Zero-Day, CISA Mandates Fix
A high-severity, zero-click flaw in the Pixel's cellular modem was exploited in targeted attacks before Google shipped a fix, prompting CISA to…