Latest Briefings
Windows 11 KB5124008 Update Breaks Domain Trust for Enterprise Devices
Microsoft is investigating reports that the KB5124008 security update severs the secure channel between domain-joined Windows 11 PCs and Active Directory, locking…
House Committee Chair Signals FRONTIER Act AI Safety Bill Could Slip to 2027
Energy and Commerce Chairman Brett Guthrie declined to commit to a 2026 committee vote on the bipartisan FRONTIER Act, even as AI…
Windows Server 2022 Mainstream Support Ends October 13, 2026
Microsoft is reminding administrators that Windows Server 2022 exits mainstream support next month, shifting to extended security-only updates through October 2031.
Attackers Exploit WooCommerce Plugin Flaw to Plant PHP Web Shells
A critical unauthenticated file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin is being actively exploited to drop PHP backdoors on WordPress…
BambooToken Malware Abuses MQTT Protocol to Control Windows and Linux Hosts
A cross-platform malware family active since 2023 is using the IoT messaging protocol MQTT for stealthy command-and-control, hitting mobile app backends, law…
CenterPoint Energy Confirms Breach After Hacker Leaks 7.5M Customer Records
The Houston-based utility confirmed an unauthorized party accessed customer data through an external-facing system, days after a threat actor leaked an archive…
Microsoft Drafts AI Code of Conduct Barring Models From Building Attack Tools
Microsoft's proposed 'Humanist AI Code of Conduct' for its MAI Models sets hard limits on offensive cyber capabilities, agent autonomy, and rogue…
Five Alleged Black Axe Leaders Extradited to US on Fraud Charges
US prosecutors say the men ran a decade-long romance scam and advance fee fraud operation from Cape Town, part of the notorious…
DDRop Attack Defeats Intel TDX and AMD SEV-SNP Memory Encryption
A newly disclosed hardware attack called DDRop can silently drop memory writes in confidential computing environments, tricking processors into trusting stale encrypted…
Japan’s Digital Agency: VPN Flaw Breach Exposed 246,000 Personnel Records
An attacker exploited a medium-severity, non-zero-day VPN vulnerability to access Japan's Government Solution Service, potentially exposing names, emails, phone numbers, and addresses…
Telus Notifies Customers of Account Takeovers Tied to Compromised Credentials
Canadian telecom giant Telus is warning consumer customers that attackers used stolen credentials to access accounts and personal data, then tried to…
CISA Confirms Active Exploitation of Max-Severity GitLab Flaw
Attackers are exploiting a critical unauthenticated path traversal bug in GitLab's repository commits API just days after a patch shipped, prompting CISA…