Latest Briefings
Medtronic Data Breach Exposes 3.8 Million Patients via ShinyHunters Attack
Medical device maker Medtronic is notifying nearly 3.84 million individuals after the ShinyHunters extortion group accessed corporate IT systems in April 2026,…
Progress Kemp LoadMaster Pre-Auth RCE Flaw Under Active Exploitation
A critical OS command injection vulnerability in Progress Kemp LoadMaster is being actively targeted, with exploitation attempts identified by eSentire's Threat Response…
Critical Cursor AI Editor Flaws Allow Prompt Injection to Escape Sandbox
Two near-perfect-severity vulnerabilities in the Cursor AI code editor, dubbed DuneSlide, can be triggered by a single malicious prompt to break out…
CISA Warns of Critical Hardcoded Credential Flaw in Gardyn IoT Hub
Three vulnerabilities in Gardyn's IoT Hub platform, including a CVSS 10 hardcoded credential bug, could let unauthenticated attackers access and control connected…
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe released security updates for ColdFusion and Campaign Classic addressing 12 vulnerabilities, including seven rated at maximum severity with CVSS scores of…
SimpleHelp Auth Bypass Exploited to Drop TaskWeaver and Djinn Stealer
Attackers are actively exploiting a maximum-severity authentication bypass in SimpleHelp to deliver two newly identified malware families, with the infostealer component targeting…
FBI Seizes NetNut Proxy Platform and Popa Botnet Infrastructure
The FBI, working with Google, Lumen, and Shadowserver, seized hundreds of domains tied to NetNut and the Popa botnet, a network of…
AI Agent Runs Autonomous Ransomware Attack Against Production Database
Sysdig researchers say they have identified what may be the first ransomware attack executed end-to-end by an AI agent, with a large…
FortiBleed Credential Theft Operation Tied to INC and Lynx Ransomware Groups
Researchers at SOCRadar have linked the large-scale FortiBleed FortiGate credential theft campaign to operators of the INC and Lynx ransomware-as-a-service platforms, with…
Google Patches 382 Vulnerabilities in Chrome 151, 15 Rated Critical
The Chrome 151 release addresses a record-setting batch of security flaws, with 358 of them discovered internally, likely aided by AI-assisted vulnerability…
Langflow RCE Flaw Exploited to Drop Monero Miner on AI Endpoints
Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability in Langflow to deploy Monero cryptocurrency mining malware on exposed AI…
Oracle PeopleSoft SSRF Flaw Requires No Auth, Scores 9.3 CVSS
A server-side request forgery vulnerability in Oracle PeopleSoft's HttpListeningConnector can be exploited by unauthenticated remote attackers and chained with other bugs to…