
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.

CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.

Previously undocumented Brazilian banking malware KREMLIN installs malicious extensions on Chrome and Edge, bypassing security checks to steal credentials and

North Korean Jade Sleet group compromised an Indian IT services firm using FLATROOF and ROOFDECK backdoors, targeting developers for supply

npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree

Security researchers broke out of OpenAI’s Codex sandbox using two methods and chained vulnerabilities to compromise ChatGPT and Codex staff

BragJack proof-of-concept uses a single malicious extension and Prompt Forcing to hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity,

North Korean WaterPlum hackers compromised 30,000 devices globally in eight-month campaign, stealing over $10.7 million in cryptocurrency traced to Pyongyang.

ShinyHunters extortion gang compromised Clop’s Tor leak site, claiming to have stolen server data and private keys, threatening to extort

Tilly Norwood’s Talking Tilly video call service scans every caller’s face for age verification and monitors emotions before shutdown on

Russian threat actor deployed hundreds of AI agents to exploit PaperCut vulnerabilities, compromising 395-440+ organizations between August 15 and September
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.