“Eye” Spy: Cyclops Blink Returns with Extended Capabilities 🚀 In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was disc...
Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
The ZRON Leak, Part 1 What has Endured and What is Evolving in China's Commercial Hacking Ecosystem Since the 2024 i-SOON Leak
The ZRON Leak, Part 1: What has Endured and What is Evolving in China’s Commercial Hacking Ecosystem Since the 2024 i-SOON Leak? On September 16, 2026, a Wall Street Journal headline proclaimed, “...
FBI Warns of Ongoing FortiBleed Attacks Locking Out VPN Admins
FBI Warns of Ongoing FortiBleed Attacks Locking Out VPN Admins 🚨 The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways, ...
CVE-2026-107284 - AsyncHttpClient Vulnerability Discovered
CVE-2026-107284 - AsyncHttpClient Vulnerability 🚨 A new vulnerability, CVE-2026-107284, has been identified in the AsyncHttpClient (AHC) library, which allows Java applications to easily execute H...
CVE-2026-105816 - Vault Vulnerable to Arbitrary Code Execution
CVE-2026-105816 - Vault Vulnerable to Arbitrary Code Execution Published Date: October 7, 2026 Source: Cvefeed Vault and Vault Enterprise did not consistently verify that stored plugin catalog en...
2026-10-07 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-105089 WWBN - AVideo W...
Hitachi Energy SOI Vulnerability Alert
Hitachi Energy SOI Vulnerability Alert Hitachi Energy is aware of a Remote Code Execution (RCE) vulnerability in the Apache ActiveMQ component of the SOI product. This vulnerability affects the fo...
Facebook Marketplace Scam Uses Your Name and Number
Facebook Marketplace Scam Alert 🚨 Facebook users are reporting receiving messages with fake Facebook Marketplace listings that feature their name as the seller. Here’s how it works: you receive a ...
Request, Aggregate, Bypass How Attackers Can Evade LLM Safety Classifiers
Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers Modern frontier AI models deploy safety classifiers. These are second AI models that sit between the user and the frontie...
Hackers Obtain Counterfeit TLS Certificates for Google and Other Large Services
Hackers Obtain Counterfeit TLS Certificates for Google and Other Large Services 🚨 Breaking News: Attackers have hijacked three top-level domains and used their control to mint counterfeit TLS cert...
Domino's Customers Targeted in Credential Stuffing Attacks
Domino’s Customers Targeted in Credential Stuffing Attacks 🚨 Domino’s Pizza customers have reported receiving alarming emails indicating that their accounts have been accessed by unauthorized thir...
Blinder Tunnel Targets Critical Infrastructure
Blinder Tunnel Targets Critical Infrastructure An Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value...
A Personnel File is a Map Why the FBI Breach Matters
A Personnel File is a Map: Why the FBI Breach Matters A personnel file maps a public servant’s life, family, career, network, and, in some cases, mission. At scale, those files can illuminate an o...
ASOS Confirms Data Breach After "HACKED" In-App Notifications
ASOS Confirms Data Breach After “HACKED” In-App Notifications 🚨 UK fashion retailer ASOS has confirmed a data breach after hackers sent unauthorized push notifications through its mobile app, clai...
2026-10-06 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2023-54404 colinhacks - zod ...
Denmark Population Registry Data Breach Affects 8.8 Million People
Denmark Population Registry Data Breach Affects 8.8 Million People Denmark’s Central Population Register (CPR) has issued a warning regarding a significant data breach that has compromised the per...
Rejetto HFS Servers Actively Scanned for Critical RCE Flaw
Rejetto HFS Servers Actively Scanned for Critical RCE Flaw 🚨 Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery,...