Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-09-05 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2022-35499 n/a - n/a In Tri...
2026-09-04 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2023-54356 kyverno - kyverno ...
Rogue ScreenConnect Installations Suggest Worm-Like Activity
Rogue ScreenConnect Installations Suggest Worm-Like Activity 🚨 Recently, Huntress observed a strange pattern across unrelated endpoints within several different organizations that we protect. In l...
Signature Optional - Analysis of CVE-2026-28323
Signature Optional - Analysis of CVE-2026-28323 The SamlConsumer.getAuthenticatedUserFromSamlResponse() method was where the authentication decision happened. This method processed SAMLResponse va...
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Pegasus Zero-Click Exploit Infects Serbian Student Activist’s iPhone A member of Serbia’s student protest movement has been infected with NSO Group’s Pegasus spyware through an iMessage zero-click...
Node.js Old Technique Makes a Comeback
Node.js: Old Technique Makes a Comeback 🚀 Abuse of Node.js has undergone a revival. The Symantec Threat Hunter Team has observed this technique being used by multiple actors since February 2026, w...
Cybercrooks Target Fishbrain to Steal Password Hashes
Cybercrooks Target Fishbrain to Steal Password Hashes Armed with password hashes and salts, attackers could already be kraken those credentials! 🦑 Cybercriminals have reeled in password hashes an...
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
BraZetsu Malware Overview Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercia...
2026-09-03 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-19593 OpenAI - Codex Desktop...
Daejon Love Case Highlights Online Romance Scams
Daejon Love Case Highlights Online Romance Scams The internet has revolutionized dating, and there has been a surge in U.S. adults using apps to find ideal matches post-pandemic. While these apps ...
Russian Hacker Faces Up to 20 Years in Prison Following Extradition and Indictment
Russian Hacker Faces Up to 20 Years in Prison Following Extradition and Indictment A federal grand jury in California has indicted Russian citizen Searzhudin Tamirlanovich Aktulaev for allegedly c...
Google Drops Key Memory Protection From Pixel 11, Forcing GrapheneOS to Rethink Its Future
Google Drops Key Memory Protection From Pixel 11 🚨 GrapheneOS has spent years turning hardened memory safety into a non-negotiable baseline for mobile security. Now the project faces its sharpest ...
2026-09-02 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-10195 fs-code - FS Poster - ...
Off the Hook Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 🚨 Overview In total, we reported 12 distinct vulnerabilities in the Switchvox product which have now ...
Mirage Kitten Switches to Node.js and JavaScript Malware
Mirage Kitten Switches to Node.js and JavaScript Malware 🚀 While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. The first sampl...
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Financially Motivated Threat Actor BREEZE COMET Targets Brazil 🚨 Overview Beginning in 2024, Mandiant investigated a series of compromises affecting Brazilian financial services, retail, and eComm...
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
Financial Stability Board Sounds the Alarm Over Frontier AI Risks The global financial system is at risk as frontier AI models transform the cyber-threat environment, the Financial Stability Board...