Latest Briefings
Google Project Zero Chains Pixel 9 Sandbox Escape via BigWave Kernel Driver
A Project Zero researcher found three bugs in the Pixel 9's BigWave AV1 hardware driver, one of which enables a full mediacodec…
JadePuffer: First Ransomware Campaign Run Entirely by an AI Agent
Cloud security firm Sysdig has documented what it believes is the first ransomware operation conducted end-to-end by a large language model agent,…
CISA Warns of Critical Auth Flaws in EVoke EV Charging Management System
CISA has published an advisory detailing multiple vulnerabilities in EVoke Systems' Charging Station Management System, with the most severe carrying a CVSS…
CISA Warns of Critical Flaws in Daktronics Controller Firmware
Three vulnerabilities in Daktronics DMP and VFC-DMP controller firmware, including hard-coded credentials and unrestricted file upload, could give unauthenticated attackers full root-level…
Bad Epoll Linux Kernel Flaw Grants Root to Unprivileged Users, Affects Android
A newly disclosed Linux kernel vulnerability tracked as CVE-2026-46242 allows an ordinary unprivileged user to gain full root control. The flaw affects…
Delta Electronics DVP12SE PLC Exposes Critical Unauthenticated Modbus Flaws
Two critical vulnerabilities in Delta Electronics DVP12SE PLCs allow unauthenticated remote attackers to manipulate control logic and flood the device into unavailability.…
Agentic AI Drives Real Ransomware Attack Through Langflow Flaw
A threat actor exploited a critical Langflow vulnerability to deploy an LLM agent that autonomously performed reconnaissance, lateral movement, and ransomware encryption…
Critical Cursor AI Editor Flaws Enable OS-Level Remote Code Execution
Two vulnerabilities in the Cursor AI code editor, collectively dubbed DuneSlide, allow attackers to escape the IDE sandbox and execute arbitrary code…
Medtronic Data Breach Exposes 3.8 Million Patients via ShinyHunters Attack
Medical device maker Medtronic is notifying nearly 3.84 million individuals after the ShinyHunters extortion group accessed corporate IT systems in April 2026,…
Progress Kemp LoadMaster Pre-Auth RCE Flaw Under Active Exploitation
A critical OS command injection vulnerability in Progress Kemp LoadMaster is being actively targeted, with exploitation attempts identified by eSentire's Threat Response…
Critical Cursor AI Editor Flaws Allow Prompt Injection to Escape Sandbox
Two near-perfect-severity vulnerabilities in the Cursor AI code editor, dubbed DuneSlide, can be triggered by a single malicious prompt to break out…
CISA Warns of Critical Hardcoded Credential Flaw in Gardyn IoT Hub
Three vulnerabilities in Gardyn's IoT Hub platform, including a CVSS 10 hardcoded credential bug, could let unauthenticated attackers access and control connected…