Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-09-02 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-10195 fs-code - FS Poster - ...
Off the Hook Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 🚨 Overview In total, we reported 12 distinct vulnerabilities in the Switchvox product which have now ...
Mirage Kitten Switches to Node.js and JavaScript Malware
Mirage Kitten Switches to Node.js and JavaScript Malware 🚀 While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. The first sampl...
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Financially Motivated Threat Actor BREEZE COMET Targets Brazil 🚨 Overview Beginning in 2024, Mandiant investigated a series of compromises affecting Brazilian financial services, retail, and eComm...
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
Financial Stability Board Sounds the Alarm Over Frontier AI Risks The global financial system is at risk as frontier AI models transform the cyber-threat environment, the Financial Stability Board...
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in ...
CVE-2026-84482 - WWBN AVideo Cross-Site Request Forgery
CVE-2026-84482 - WWBN AVideo Cross-Site Request Forgery CVE-2026-84482, rated with a high CVSS 3.1 score of 8.8, affects WWBN AVideo and is identified as a Cross-Site Request Forgery via get_domai...
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Attackers Steal METR API Key and Burn $600,000 in AI Credits 🚨 Attackers have stolen an API key from the AI safety research organization METR and used it for three weeks to consume model credits w...
2026-09-01 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-81267 Mozilla - Firefox for ...
Windows Bug Incorrectly Tells Users That Microsoft Defender Antivirus Is Turned Off
Windows Bug Alert 🚨 Microsoft has reported a glitch that causes Windows to incorrectly inform users that Microsoft Defender Antivirus is turned off, despite it being fully functional. This bug pos...
Traefik Vulnerability Discovered in Version Through 3.7.11
Traefik Vulnerability Discovered in Version Through 3.7.11 🚨 Bishop Fox has identified a significant vulnerability in Traefik, an open-source reverse proxy and ingress controller widely used in co...
Microsoft Exchange Online Outage Causes Email Failures and Auth Issues
Microsoft Exchange Online Outage Causes Email Failures and Auth Issues 🚨 Microsoft is investigating a widespread service issue causing authentication issues, connection problems, email delays, and...
Security Incident – BGP Hijacking
Security Incident – BGP Hijacking 🚨 The Virtualizor platform, for those unfamiliar, is a VPS management platform used by many hosting providers to deploy and manage virtual servers on KVM, Xen, LX...
Cronos Blockchain Restarts After $74 Million Tectonic Exploit
Cronos Blockchain Restarts After $74 Million Tectonic Exploit 🚀 The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending ...
Breaking the Seal Static Deobfuscation of JSCeal's Compiled V8 Bytecode
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocur...
AI Killed the Typo Time to Rewrite Phishing Training
AI Killed the Typo: Time to Rewrite Phishing Training Source: SC Magazine Date Published: August 31, 2026 “Look for spelling mistakes and bad grammar.” For years, that was one of the defining pie...
2026-08-31 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-10522 Unknown - MemberHero ...