LIVE FEED
Subscribe
//

Latest Briefings

Vulnerabilities Certighost PoC Exploit Lets Low-Privileged Users Hijack Windows Domains via AD CS
HIGH Vulnerabilities

Certighost PoC Exploit Lets Low-Privileged Users Hijack Windows Domains via AD CS

Researchers released a working exploit for CVE-2026-54121, an Active Directory Certificate Services flaw that lets an authenticated attacker impersonate a domain controller…

by Robbie · 3 weeks ago
Exploits Dysphoria Botnet Grows to 200,000 Devices Using Blockchain-Based C2
HIGH Exploits

Dysphoria Botnet Grows to 200,000 Devices Using Blockchain-Based C2

Researchers at QiAnXin XLab have tracked a rapidly evolving DDoS botnet called Dysphoria that hides its command infrastructure inside Ethereum and Solana…

by Robbie · 3 weeks ago
Vulnerabilities DentaQuest Breach Tied to ShinyHunters Exposes Data on Over 23 Million People
HIGH Vulnerabilities

DentaQuest Breach Tied to ShinyHunters Exposes Data on Over 23 Million People

Dental and vision benefits administrator DentaQuest is notifying millions after attackers accessed sensitive health and identity data over a four-day window in…

by Robbie · 3 weeks ago
AI Security Anthropic’s Opus 5 Nearly Matches Mythos 5 at Finding Bugs, Lags on Exploits
AI Security

Anthropic’s Opus 5 Nearly Matches Mythos 5 at Finding Bugs, Lags on Exploits

Anthropic's new cheaper Claude Opus 5 model rivals its top-tier Mythos 5 system at spotting vulnerabilities, but a deliberate lack of offensive-task…

by Robbie · 3 weeks ago
Exploits GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git
HIGH Exploits

GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git

A researcher has published working exploit code for a GitLab vulnerability patched six weeks ago, showing how any authenticated user with push…

by Robbie · 3 weeks ago
Vulnerabilities GitHub and PyPI Roll Out Time-Delay Defenses Against Supply Chain Attacks
MEDIUM Vulnerabilities

GitHub and PyPI Roll Out Time-Delay Defenses Against Supply Chain Attacks

GitHub's Dependabot now enforces a default 72-hour cooldown before adopting new package versions, while PyPI blocks file additions to releases older than…

by Robbie · 3 weeks ago
Research SourTrade Malvertising Campaign Assembles Malware Inside the Browser
MEDIUM Research

SourTrade Malvertising Campaign Assembles Malware Inside the Browser

A malvertising operation dubbed SourTrade delivers malicious payloads in fragments and uses a legitimate Bun runtime to assemble the final Windows executable…

by Robbie · 3 weeks ago
Research Steam Forum Scammers Trick Gamers Into Installing XMRig Cryptominers
MEDIUM Research

Steam Forum Scammers Trick Gamers Into Installing XMRig Cryptominers

Threat actors are posing as helpful forum members on Steam, tricking users into running PowerShell commands disguised as PC optimization fixes that…

by Robbie · 3 weeks ago
Research Fake ShinyHunters Sextortion Emails Exploit Old Breach Data for $2,000 Bitcoin Demands
LOW Research

Fake ShinyHunters Sextortion Emails Exploit Old Breach Data for $2,000 Bitcoin Demands

Scammers are recycling email addresses from ShinyHunters' published data leaks to send fraudulent sextortion emails, falsely claiming device compromise to pressure victims…

by Robbie · 3 weeks ago
Research Malvertising Campaign Builds Malware Inside the Browser, Never Touches the Network
MEDIUM Research

Malvertising Campaign Builds Malware Inside the Browser, Never Touches the Network

A crypto and trading themed malvertising operation dubbed SourTrade uses service workers and shared workers to assemble malicious executables locally in browser…

by Robbie · 3 weeks ago
Vulnerabilities UK PM Burnham Keeps Cyber Minister in Place Despite Ministry Shakeup
Vulnerabilities

UK PM Burnham Keeps Cyber Minister in Place Despite Ministry Shakeup

New Prime Minister Andy Burnham reappointed Liz Lloyd to steer cyber policy even as he dismantled the department that housed it, preserving…

by Robbie · 3 weeks ago
Vulnerabilities Rockwell Patches Four Code Execution Flaws in Arena Simulation Software
HIGH Vulnerabilities

Rockwell Patches Four Code Execution Flaws in Arena Simulation Software

Rockwell Automation has fixed four high-severity memory corruption vulnerabilities in Arena Simulation that could let an attacker execute arbitrary code via a…

by Robbie · 3 weeks ago
1 6 7 8 38

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.