Latest Briefings
Certighost PoC Exploit Lets Low-Privileged Users Hijack Windows Domains via AD CS
Researchers released a working exploit for CVE-2026-54121, an Active Directory Certificate Services flaw that lets an authenticated attacker impersonate a domain controller…
Dysphoria Botnet Grows to 200,000 Devices Using Blockchain-Based C2
Researchers at QiAnXin XLab have tracked a rapidly evolving DDoS botnet called Dysphoria that hides its command infrastructure inside Ethereum and Solana…
DentaQuest Breach Tied to ShinyHunters Exposes Data on Over 23 Million People
Dental and vision benefits administrator DentaQuest is notifying millions after attackers accessed sensitive health and identity data over a four-day window in…
Anthropic’s Opus 5 Nearly Matches Mythos 5 at Finding Bugs, Lags on Exploits
Anthropic's new cheaper Claude Opus 5 model rivals its top-tier Mythos 5 system at spotting vulnerabilities, but a deliberate lack of offensive-task…
GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git
A researcher has published working exploit code for a GitLab vulnerability patched six weeks ago, showing how any authenticated user with push…
GitHub and PyPI Roll Out Time-Delay Defenses Against Supply Chain Attacks
GitHub's Dependabot now enforces a default 72-hour cooldown before adopting new package versions, while PyPI blocks file additions to releases older than…
SourTrade Malvertising Campaign Assembles Malware Inside the Browser
A malvertising operation dubbed SourTrade delivers malicious payloads in fragments and uses a legitimate Bun runtime to assemble the final Windows executable…
Steam Forum Scammers Trick Gamers Into Installing XMRig Cryptominers
Threat actors are posing as helpful forum members on Steam, tricking users into running PowerShell commands disguised as PC optimization fixes that…
Fake ShinyHunters Sextortion Emails Exploit Old Breach Data for $2,000 Bitcoin Demands
Scammers are recycling email addresses from ShinyHunters' published data leaks to send fraudulent sextortion emails, falsely claiming device compromise to pressure victims…
Malvertising Campaign Builds Malware Inside the Browser, Never Touches the Network
A crypto and trading themed malvertising operation dubbed SourTrade uses service workers and shared workers to assemble malicious executables locally in browser…
UK PM Burnham Keeps Cyber Minister in Place Despite Ministry Shakeup
New Prime Minister Andy Burnham reappointed Liz Lloyd to steer cyber policy even as he dismantled the department that housed it, preserving…
Rockwell Patches Four Code Execution Flaws in Arena Simulation Software
Rockwell Automation has fixed four high-severity memory corruption vulnerabilities in Arena Simulation that could let an attacker execute arbitrary code via a…