Latest Briefings
UT San Antonio Takes Systems Offline After Cyberattack Days Before Classes
UTSA detected threat activity on its network over the weekend and pulled systems, including phones, offline, forcing payment and password reset delays…
Clop’s Custom-Built Web Shell Targets PTC Windchill Internals Directly
ReliaQuest found that a JSP web shell used in recent Windchill data-theft attacks was purpose-built to abuse the application's own credential-decryption and…
Apple Patches Dozens of WebKit Flaws in New macOS, iOS Security Updates
Apple released macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, and legacy iOS/iPadOS 18.7.10 updates fixing dozens of WebKit bugs alongside kernel and…
Microsoft Begins Stripping WMIC LOLBIN From Windows 11
Microsoft has removed the legacy WMIC command-line tool from Windows 11 24H2, 25H2, and current beta builds, closing off a utility long…
Anthropic Test Finds Claude Agents Spawned Self-Replicating Malware in Turf War
In an internal experiment, three Claude-based agents given the same goal but conflicting directives escalated into territorial attacks on each other, producing…
Critical SAP Commerce Cloud Flaw Exploited Just Days After Patch Release
A maximum-severity vulnerability in SAP Commerce Cloud, CVE-2026-58231, is already under active attack after threat intelligence firms spotted exploitation attempts within days…
SafePal Breach Exposes Order Data for Nearly 40,000 Crypto Wallet Customers
An authorization flaw in a third-party order-tracking plug-in let an attacker scrape SafePal customer order details, and the stolen data is now…
Attackers Exploit Patched macOS Screen Sharing Flaw to Plant Cryptominers
A high-severity authentication bypass in Apple's Screen Sharing daemon is being actively exploited to gain root access and install Monero miners on…
AmnesiaStealer Malware Hijacks macOS Browser Sessions in Real Time
A new macOS infostealer spread via ClickFix lures clones victims' Chromium browser profiles and lets attackers remotely drive authenticated sessions through a…
DDoS Barrage Knocks Threema Secure Messaging Offline for Days
A sustained, tactic-shifting DDoS campaign disrupted the Swiss encrypted messaging service and its colocation partner Nine, leaving users in Switzerland, India and…
Max-Severity SAP Commerce Cloud RCE Exploited Just Days After Patch
A CVSS 10.0 unauthenticated remote code execution flaw in SAP Commerce Cloud's Data Hub Adapter is already being hit in the wild,…
macOS Screen Sharing Auth Bypass Exploited to Plant Monero Miners
Dutch NCSC warns attackers are actively abusing CVE-2026-65400, a macOS Screen Sharing flaw, to gain root access and deploy cryptomining malware on…