Cyber Security
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Critical FortiMail Zero-Day Exploited With No Patch Yet
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Kiteworks Patches Second Max-Severity Flaw in a Week
Self-Healing WordPress Backdoor Defies Standard Removal
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
MetaMask Discloses Incident, Exits Ethereum Validators
TeamViewer Patches Critical Access-Control Bypass Flaw
WatchGuard Patches Critical Root Code Execution Flaw
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Pentagon Records Agency Breach Exposes Data on 3 Million
France Tax Agency Breached Seven Weeks via Stolen Passwords
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
FBI Tells ShinyHunters Members to Turn Themselves In
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
101 Malicious npm Packages Add Developers to WhatsApp Groups
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Cybersecurity
ToddyCat APT’s Umbrij Tool Reads Corporate Gmail via OAuth Silently
Kaspersky attributed Umbrij to ToddyCat APT, a .NET tool that silently reads corporate Gmail via OAuth without triggering login alerts or standard security notifications.
Application Security
Apple Hide My Email Still Leaks Real Addresses After Claimed Fix
Apple's iCloud+ Hide My Email vulnerability still exposes real addresses at 100% success, with multiple claimed fixes from Apple failing to close the flaw.
Cybersecurity
90-Domain SEO Campaign Abuses ScreenConnect to Deploy AsyncRAT
Kaspersky exposed a 90-domain SEO poisoning campaign that installs AsyncRAT on Windows via a fake ScreenConnect installer, targeting users across 10 languages.
Cybersecurity
VEIL#DROP Campaign Uses Google Blogger to Deliver PureLogs Stealer
Securonix disclosed VEIL#DROP, an active campaign routing PureLogs Stealer through Google Blogger to bypass reputation-based enterprise security controls.
Cybersecurity
90-Domain SEO Campaign Abuses ScreenConnect to Deploy AsyncRAT
Kaspersky exposed a 90-domain SEO poisoning campaign that installs AsyncRAT on Windows via a fake ScreenConnect installer, targeting users across 10 languages.
Application Security
Unit 42 Confirms 13,000 Malicious Phantom Squatting Sites
Unit 42 documented phantom squatting, with 13,229 malicious URLs active on AI-hallucinated domains and 250,000 more unregistered sites available to attackers.
Cybersecurity
Trump Administration Lifts Claude Fable 5 Access Restrictions
The Trump administration reversed Commerce Department restrictions on Anthropic's Fable 5, restoring global access while Mythos 5 stays limited to vetted U.S. organizations.
Application Security
JADEPUFFER: First AI-Orchestrated Ransomware Exploits Langflow RCE
Sysdig identified JADEPUFFER, the first ransomware campaign run by an LLM autonomous agent exploiting CVE-2026-33017 in Langflow to complete full attack chains without human operators.
Application Security
CISA Adds SharePoint RCE CVE-2026-45659 to KEV Catalog
CISA confirmed active exploitation of CVE-2026-45659, a CVSS 8.8 SharePoint Server deserialization flaw enabling authenticated remote code execution in enterprise environments.
Application Security
Poisoned Email Turns Claude Desktop Into a Reverse Shell
Red teamers showed that email inbox prompt injection turns Claude Desktop into a reverse shell when MCP connectors with command execution are installed.
Application Security
Adobe’s Seven CVSS 10.0 Flaws Span ColdFusion and Campaign Classic
Adobe patched seven maximum-severity CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic, enabling unauthenticated code execution and privilege escalation.
Cybersecurity
Qilin Ransomware Claims Canadian Manufacturer Chamco Industries
Qilin listed Chamco Industries on its dark web extortion portal, threatening to leak stolen data in its latest attack on a Canadian manufacturing company.
Cybersecurity
FortiBleed True Scale: 430,000 Firewalls Targeted, INC and Lynx Linked
SOCRadar confirmed FortiBleed hit 430,000 FortiGate firewalls with sniffers on 19,000 devices, linking the operation to INC Ransom and Lynx ransomware groups.
Application Security
Unpatched Argo CD RCE Puts Kubernetes Clusters at Risk
Synacktiv disclosed an unpatched unauthenticated RCE in Argo CD's repo-server component that can lead to full Kubernetes cluster takeover with no fix currently available.
Application Security
DuneSlide Flaws Let Prompt Injection Break Cursor AI Sandbox
Cato AI Labs disclosed CVE-2026-50548 and CVE-2026-50549 in Cursor IDE, CVSS 9.8 flaws enabling zero-click prompt injection to escape the sandbox and execute system commands.
Cybersecurity
ChocoPoC RAT Targets Security Researchers via Fake GitHub PoC Repos
ChocoPoC, a new remote access trojan, targets vulnerability researchers through trojanized proof-of-concept exploit repositories on GitHub, stealing credentials and establishing backdoors.
Application Security
DeepSeek Built Browser Ransomware Using Chrome File System API
Check Point researchers showed DeepSeek generated InfernoGrabber 9000, near-functional browser ransomware using Chrome's File System Access API to encrypt files across four OS platforms.
Cybersecurity
Scattered Spider Suspect Peter Stokes Extradited From Finland
Peter Stokes, 19, a dual U.S.-Estonian citizen, was extradited from Finland to face federal computer fraud and conspiracy charges linked to the Scattered Spider hacking ...
CVE Vulnerability Alerts
Citrix Patches Six NetScaler Flaws Including HTTP/2 Bomb Vector
Citrix patched six NetScaler ADC and Gateway vulnerabilities including a new HTTP/2 Bomb denial-of-service vector and information disclosure flaws similar to the CitrixBleed session token ...
Application Security
Attackers Hit Oracle EBS CVE-2026-46817 Days After Patch
Oracle E-Business Suite CVE-2026-46817 (CVSS 9.8) is under active attack, with honeypots logging crafted XML payloads targeting the /OA_HTML endpoint.
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Cybersecurity
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
VEIL#DROP Campaign Uses Google Blogger to Deliver PureLogs Stealer
Securonix disclosed VEIL#DROP, an active campaign routing PureLogs Stealer through Google Blogger to bypass reputation-based enterprise security controls.
90-Domain SEO Campaign Abuses ScreenConnect to Deploy AsyncRAT
Kaspersky exposed a 90-domain SEO poisoning campaign that installs AsyncRAT on Windows via a fake ScreenConnect installer, targeting users across 10 languages.
Unit 42 Confirms 13,000 Malicious Phantom Squatting Sites
Unit 42 documented phantom squatting, with 13,229 malicious URLs active on AI-hallucinated domains and 250,000 more unregistered sites available to attackers.
Trump Administration Lifts Claude Fable 5 Access Restrictions
The Trump administration reversed Commerce Department restrictions on Anthropic's Fable 5, restoring global access while Mythos 5 stays limited to vetted U.S. organizations.
JADEPUFFER: First AI-Orchestrated Ransomware Exploits Langflow RCE
Sysdig identified JADEPUFFER, the first ransomware campaign run by an LLM autonomous agent exploiting CVE-2026-33017 in Langflow to complete full attack chains without human operators.
CISA Adds SharePoint RCE CVE-2026-45659 to KEV Catalog
CISA confirmed active exploitation of CVE-2026-45659, a CVSS 8.8 SharePoint Server deserialization flaw enabling authenticated remote code execution in enterprise environments.
Poisoned Email Turns Claude Desktop Into a Reverse Shell
Red teamers showed that email inbox prompt injection turns Claude Desktop into a reverse shell when MCP connectors with command execution are installed.
Adobe’s Seven CVSS 10.0 Flaws Span ColdFusion and Campaign Classic
Adobe patched seven maximum-severity CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic, enabling unauthenticated code execution and privilege escalation.
Qilin Ransomware Claims Canadian Manufacturer Chamco Industries
Qilin listed Chamco Industries on its dark web extortion portal, threatening to leak stolen data in its latest attack on a Canadian manufacturing company.
FortiBleed True Scale: 430,000 Firewalls Targeted, INC and Lynx Linked
SOCRadar confirmed FortiBleed hit 430,000 FortiGate firewalls with sniffers on 19,000 devices, linking the operation to INC Ransom and Lynx ransomware groups.
Unpatched Argo CD RCE Puts Kubernetes Clusters at Risk
Synacktiv disclosed an unpatched unauthenticated RCE in Argo CD's repo-server component that can lead to full Kubernetes cluster takeover with no fix currently available.
DuneSlide Flaws Let Prompt Injection Break Cursor AI Sandbox
Cato AI Labs disclosed CVE-2026-50548 and CVE-2026-50549 in Cursor IDE, CVSS 9.8 flaws enabling zero-click prompt injection to escape the sandbox and execute system commands.
ChocoPoC RAT Targets Security Researchers via Fake GitHub PoC Repos
ChocoPoC, a new remote access trojan, targets vulnerability researchers through trojanized proof-of-concept exploit repositories on GitHub, stealing credentials and establishing backdoors.
DeepSeek Built Browser Ransomware Using Chrome File System API
Check Point researchers showed DeepSeek generated InfernoGrabber 9000, near-functional browser ransomware using Chrome's File System Access API to encrypt files across four OS platforms.
Scattered Spider Suspect Peter Stokes Extradited From Finland
Peter Stokes, 19, a dual U.S.-Estonian citizen, was extradited from Finland to face federal computer fraud and conspiracy charges linked to the Scattered Spider hacking ...
Citrix Patches Six NetScaler Flaws Including HTTP/2 Bomb Vector
Citrix patched six NetScaler ADC and Gateway vulnerabilities including a new HTTP/2 Bomb denial-of-service vector and information disclosure flaws similar to the CitrixBleed session token ...
Attackers Hit Oracle EBS CVE-2026-46817 Days After Patch
Oracle E-Business Suite CVE-2026-46817 (CVSS 9.8) is under active attack, with honeypots logging crafted XML payloads targeting the /OA_HTML endpoint.
Apple Patches 30+ Flaws as AI Systems Earn WebKit CVE Credit
Apple's iOS 26.2 and macOS Tahoe 26.2 updates patch 30-plus flaws, including four WebKit vulnerabilities co-discovered by OpenAI and Anthropic AI systems.
Six AirDrop and Quick Share Flaws Put 5B Devices at Risk
CISPA researchers disclosed six vulnerabilities in Apple AirDrop and Android Quick Share exposing more than five billion active devices to proximity attacks.
BioShocking Attack Turns AI Browsers Into Credential Thieves
LayerX's BioShocking research shows AI browsers including ChatGPT Atlas, Perplexity Comet, and the Claude extension can be tricked into stealing credentials.