LIVE FEED
Subscribe
//

Latest Briefings

Exploits Medtronic Data Breach Exposes 3.8 Million Patients via ShinyHunters Attack
CRITICAL Exploits

Medtronic Data Breach Exposes 3.8 Million Patients via ShinyHunters Attack

Medical device maker Medtronic is notifying nearly 3.84 million individuals after the ShinyHunters extortion group accessed corporate IT systems in April 2026,…

by Robbie · 1 month ago
Exploits Progress Kemp LoadMaster Pre-Auth RCE Flaw Under Active Exploitation
CRITICAL Exploits

Progress Kemp LoadMaster Pre-Auth RCE Flaw Under Active Exploitation

A critical OS command injection vulnerability in Progress Kemp LoadMaster is being actively targeted, with exploitation attempts identified by eSentire's Threat Response…

by Robbie · 1 month ago
Vulnerabilities Critical Cursor AI Editor Flaws Allow Prompt Injection to Escape Sandbox
CRITICAL Vulnerabilities

Critical Cursor AI Editor Flaws Allow Prompt Injection to Escape Sandbox

Two near-perfect-severity vulnerabilities in the Cursor AI code editor, dubbed DuneSlide, can be triggered by a single malicious prompt to break out…

by Robbie · 1 month ago
Vulnerabilities CISA Warns of Critical Hardcoded Credential Flaw in Gardyn IoT Hub
CRITICAL Vulnerabilities

CISA Warns of Critical Hardcoded Credential Flaw in Gardyn IoT Hub

Three vulnerabilities in Gardyn's IoT Hub platform, including a CVSS 10 hardcoded credential bug, could let unauthenticated attackers access and control connected…

by Robbie · 1 month ago
Vulnerabilities Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
CRITICAL Vulnerabilities

Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe released security updates for ColdFusion and Campaign Classic addressing 12 vulnerabilities, including seven rated at maximum severity with CVSS scores of…

by Robbie · 1 month ago
Exploits SimpleHelp Auth Bypass Exploited to Drop TaskWeaver and Djinn Stealer
CRITICAL Exploits

SimpleHelp Auth Bypass Exploited to Drop TaskWeaver and Djinn Stealer

Attackers are actively exploiting a maximum-severity authentication bypass in SimpleHelp to deliver two newly identified malware families, with the infostealer component targeting…

by Robbie · 1 month ago
Research FBI Seizes NetNut Proxy Platform and Popa Botnet Infrastructure
CRITICAL Research

FBI Seizes NetNut Proxy Platform and Popa Botnet Infrastructure

The FBI, working with Google, Lumen, and Shadowserver, seized hundreds of domains tied to NetNut and the Popa botnet, a network of…

by Robbie · 1 month ago
AI Security AI Agent Runs Autonomous Ransomware Attack Against Production Database
CRITICAL AI Security

AI Agent Runs Autonomous Ransomware Attack Against Production Database

Sysdig researchers say they have identified what may be the first ransomware attack executed end-to-end by an AI agent, with a large…

by Robbie · 1 month ago
Research FortiBleed Credential Theft Operation Tied to INC and Lynx Ransomware Groups
CRITICAL Research

FortiBleed Credential Theft Operation Tied to INC and Lynx Ransomware Groups

Researchers at SOCRadar have linked the large-scale FortiBleed FortiGate credential theft campaign to operators of the INC and Lynx ransomware-as-a-service platforms, with…

by Robbie · 1 month ago
Vulnerabilities Google Patches 382 Vulnerabilities in Chrome 151, 15 Rated Critical
CRITICAL Vulnerabilities

Google Patches 382 Vulnerabilities in Chrome 151, 15 Rated Critical

The Chrome 151 release addresses a record-setting batch of security flaws, with 358 of them discovered internally, likely aided by AI-assisted vulnerability…

by Robbie · 1 month ago
Exploits Langflow RCE Flaw Exploited to Drop Monero Miner on AI Endpoints
CRITICAL Exploits

Langflow RCE Flaw Exploited to Drop Monero Miner on AI Endpoints

Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability in Langflow to deploy Monero cryptocurrency mining malware on exposed AI…

by Robbie · 1 month ago
Vulnerabilities Oracle PeopleSoft SSRF Flaw Requires No Auth, Scores 9.3 CVSS
CRITICAL Vulnerabilities

Oracle PeopleSoft SSRF Flaw Requires No Auth, Scores 9.3 CVSS

A server-side request forgery vulnerability in Oracle PeopleSoft's HttpListeningConnector can be exploited by unauthenticated remote attackers and chained with other bugs to…

by Robbie · 2 months ago
1 5 6 7

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.