Latest Briefings
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe released security updates for ColdFusion and Campaign Classic addressing 12 vulnerabilities, including seven rated at maximum severity with CVSS scores of…
SimpleHelp Auth Bypass Exploited to Drop TaskWeaver and Djinn Stealer
Attackers are actively exploiting a maximum-severity authentication bypass in SimpleHelp to deliver two newly identified malware families, with the infostealer component targeting…
FBI Seizes NetNut Proxy Platform and Popa Botnet Infrastructure
The FBI, working with Google, Lumen, and Shadowserver, seized hundreds of domains tied to NetNut and the Popa botnet, a network of…
AI Agent Runs Autonomous Ransomware Attack Against Production Database
Sysdig researchers say they have identified what may be the first ransomware attack executed end-to-end by an AI agent, with a large…
FortiBleed Credential Theft Operation Tied to INC and Lynx Ransomware Groups
Researchers at SOCRadar have linked the large-scale FortiBleed FortiGate credential theft campaign to operators of the INC and Lynx ransomware-as-a-service platforms, with…
Google Patches 382 Vulnerabilities in Chrome 151, 15 Rated Critical
The Chrome 151 release addresses a record-setting batch of security flaws, with 358 of them discovered internally, likely aided by AI-assisted vulnerability…
Langflow RCE Flaw Exploited to Drop Monero Miner on AI Endpoints
Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability in Langflow to deploy Monero cryptocurrency mining malware on exposed AI…
Oracle PeopleSoft SSRF Flaw Requires No Auth, Scores 9.3 CVSS
A server-side request forgery vulnerability in Oracle PeopleSoft's HttpListeningConnector can be exploited by unauthenticated remote attackers and chained with other bugs to…
Critical libssh2 Flaw Gets Public PoC, Clients at Risk of Code Execution
A proof-of-concept exploit is now public for CVE-2026-55200, a critical memory corruption bug in libssh2 that allows a malicious SSH server to…
Critical Oracle E-Business Suite Flaw Under Active Exploitation
Attackers are actively exploiting CVE-2026-46817, a critical unauthenticated takeover vulnerability in Oracle E-Business Suite, weeks after Oracle shipped a patch in its…
Nissan Employee Data Breach Tied to Oracle PeopleSoft Zero-Day Attacks
Nissan has disclosed a breach of current and former employee records after ShinyHunters exploited a critical zero-day in Oracle PeopleSoft, part of…
SimpleHelp Auth Bypass Exploited to Deploy Djinn Stealer and TaskWeaver
Attackers are actively exploiting a critical authentication bypass in SimpleHelp RMM software to install two previously undocumented malware families targeting developer credentials,…