Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
CVE-2026-10848 - Out-of-bounds Read in Zephyr OCPP 1.6 RPC Message Parser
CVE-2026-10848 - Out-of-bounds Read in Zephyr OCPP 1.6 RPC Message Parser Published Date: August 2, 2026 Source: CVE Feed CVE-2026-10848 describes an out-of-bounds read vulnerability in the Zephy...
2026-08-02 Daily Vulns
Investigation into APT 5 and PLA Troop 61786
Threat Review Journal: Investigation into APT 5 and PLA Troop 61786 I began tracking a subset of what was assessed to be low-level criminal activity, which actually turned out to be a group of six...
Watchfire Controller Software Vulnerability Alert
Watchfire Controller Software Vulnerability Alert 🚨 On July 30, 2026, CISA published an alert regarding a significant vulnerability in the Watchfire Controller Software. This vulnerability, identi...
The 73,000-Server Market Reselling Western Frontier AI into China
The 73,000-Server Market Reselling Western Frontier AI into China Western frontier AI is not sold in mainland China, yet it is utilized daily. This report maps the infrastructure that enables this...
Schneider Electric IGSS Vulnerability Advisory
Schneider Electric IGSS Vulnerability Advisory 🚨 Date Published: July 30, 2026 Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCA...
NASA Core Flight System Health & Safety Application Vulnerability Advisory
NASA Core Flight System (cFS) Health & Safety (HS) Application Vulnerability Advisory 🚨 Attention! A critical vulnerability has been identified in the NASA Core Flight System (cFS) Health &...
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents 🚀 Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instru...
CosmosEscape Taking Over Every Database in Azure Cosmos DB
CosmosEscape: Taking Over Every Database in Azure Cosmos DB A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database. Wiz Research uncovered...
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks 🚨 Overview: Unit 42 has uncovered a sophisticated AI-enabled autonomous hacking campaign orchestrated by a Chinese-spe...
CVE-2026-68563 - Information Disclosure in Ansible Collection Redhat Leapp
CVE-2026-68563 - Information Disclosure in Ansible Collection Redhat Leapp CVE-2026-68563 describes an information disclosure vulnerability in ansible-collection-redhat-leapp related to insecure b...
2026-07-30 Daily Vulns
Securing Agents Across Perplexity's Client Endpoints with Numbat
Securing Agents Across Perplexity’s Client Endpoints with Numbat Numbat is Perplexity’s open-source agent security suite for client endpoints. It detects, prevents, and investigates risky AI agent...
The Average Cost of a Data Breach Rises to $5 Million
The Average Cost of a Data Breach Rises to $5 Million The average cost of a data breach has risen to almost $5 million! 🚀 This alarming figure was revealed in the 2026 edition of the annual IBM Co...
Cleaning Out Inboxes TA488 Comes for Outlook with Another Half-Click Exploit
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit On 22 July 2026, one day prior to Proofpoint’s recent joint release with the NSA on the Russia-aligned threat actor TA...
CVE-2026-14643 undici Vulnerable to Cross-User Information Disclosure
CVE-2026-14643: undici Vulnerable to Cross-User Information Disclosure 🚨 Overview: CVE-2026-14643 highlights a vulnerability in undici that allows for cross-user information disclosure due to impr...
Turns Out the Ghost Was the PLA
Turns Out the Ghost Was the PLA Our research uncovered a tidy little overlap that points straight at APT15 and the PLA Cyberspace Force’s 8th Technical Reconnaissance Base (8th TRB). This tool, kn...