LIVE FEED
Subscribe
//

Category: Exploits

Exploits SimpleHelp Auth Bypass Exploited to Drop TaskWeaver and Djinn Stealer
CRITICAL Exploits

SimpleHelp Auth Bypass Exploited to Drop TaskWeaver and Djinn Stealer

Attackers are actively exploiting a maximum-severity authentication bypass in SimpleHelp to deliver two newly identified malware families, with the infostealer component targeting…

by Robbie · 3 months ago
Exploits Scattered Spider Suspect, 19, Extradited from Finland to Face U.S. Charges
HIGH Exploits

Scattered Spider Suspect, 19, Extradited from Finland to Face U.S. Charges

Peter Stokes, a dual U.S.-Estonian citizen, has been extradited from Finland and appeared in a Chicago federal court on charges of conspiracy,…

by Robbie · 3 months ago
Exploits ChocoPoC RAT Targets Security Researchers via Trojanized GitHub PoCs
HIGH Exploits

ChocoPoC RAT Targets Security Researchers via Trojanized GitHub PoCs

A Python-based remote access trojan named ChocoPoC is being distributed through weaponized proof-of-concept exploit repositories on GitHub, targeting cybersecurity researchers who test…

by Robbie · 3 months ago
Exploits Scattered Spider Suspect Extradited to US After Finnish Arrest
HIGH Exploits

Scattered Spider Suspect Extradited to US After Finnish Arrest

A 19-year-old dual US-Estonian citizen faces federal charges tied to a luxury retailer breach and an $8 million ransom demand, after being…

by Robbie · 3 months ago
Exploits Alleged Scattered Spider Member Extradited to US After Finland Arrest
HIGH Exploits

Alleged Scattered Spider Member Extradited to US After Finland Arrest

Peter Stokes, a 19-year-old dual US-Estonian citizen, has been extradited to the United States to face fraud, conspiracy, and computer intrusion charges…

by Robbie · 3 months ago
Exploits BlueHammer Flaw in Microsoft Defender Now Linked to Ransomware Campaigns
HIGH Exploits

BlueHammer Flaw in Microsoft Defender Now Linked to Ransomware Campaigns

CISA has updated its Known Exploited Vulnerabilities catalog to confirm that CVE-2026-33825, a privilege escalation flaw in Microsoft Defender, is being actively…

by Robbie · 3 months ago
Exploits Azure CLI Password Spray Campaign Hits 78+ Microsoft Accounts in 81M Attempts
HIGH Exploits

Azure CLI Password Spray Campaign Hits 78+ Microsoft Accounts in 81M Attempts

A large-scale, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 accounts across a two-week window, researchers at Huntress…

by Robbie · 3 months ago
Exploits 81 Million Login Attempts Hit Azure CLI in Massive Password Spray Campaign
HIGH Exploits

81 Million Login Attempts Hit Azure CLI in Massive Password Spray Campaign

Huntress tracked over 81 million credential spray attempts against Microsoft 365 environments between June 12 and 21, with attackers abusing the OAuth…

by Robbie · 3 months ago
Exploits Langflow RCE Flaw Exploited to Drop Monero Miner on AI Endpoints
CRITICAL Exploits

Langflow RCE Flaw Exploited to Drop Monero Miner on AI Endpoints

Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability in Langflow to deploy Monero cryptocurrency mining malware on exposed AI…

by Robbie · 3 months ago
Exploits Critical Oracle E-Business Suite Flaw Under Active Exploitation
CRITICAL Exploits

Critical Oracle E-Business Suite Flaw Under Active Exploitation

Attackers are actively exploiting CVE-2026-46817, a critical unauthenticated takeover vulnerability in Oracle E-Business Suite, weeks after Oracle shipped a patch in its…

by Robbie · 3 months ago
Exploits US Offers $10M Reward for Russian Hackers Targeting Signal and WhatsApp Accounts
HIGH Exploits

US Offers $10M Reward for Russian Hackers Targeting Signal and WhatsApp Accounts

The State Department's Rewards for Justice program is offering up to $10 million for information on two FSB- and GRU-linked groups that…

by Robbie · 3 months ago
Exploits Nissan Employee Data Breach Tied to Oracle PeopleSoft Zero-Day Attacks
CRITICAL Exploits

Nissan Employee Data Breach Tied to Oracle PeopleSoft Zero-Day Attacks

Nissan has disclosed a breach of current and former employee records after ShinyHunters exploited a critical zero-day in Oracle PeopleSoft, part of…

by Robbie · 3 months ago
1 … 5 6 7

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.