Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short
🚨 Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short N-able has released an emergency security update for N-central after attackers used an authentication bypass to gain remote ad...
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Google Password Manager Attacks 🚨 Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything appearing o...
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys 🚨 An alleged data leak from Żabka, Poland’s largest convenience store operator, has surfaced, offering a treasure trove of sensiti...
Google Chrome May Soon Block New Tab Hijacker Extensions by Default
Google Chrome May Soon Block New Tab Hijacker Extensions by Default 🚀 Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page...
CVE-2026-10848 - Out-of-bounds Read in Zephyr OCPP 1.6 RPC Message Parser
CVE-2026-10848 - Out-of-bounds Read in Zephyr OCPP 1.6 RPC Message Parser Published Date: August 2, 2026 Source: CVE Feed CVE-2026-10848 describes an out-of-bounds read vulnerability in the Zephy...
2026-08-02 Daily Vulns
Investigation into APT 5 and PLA Troop 61786
Threat Review Journal: Investigation into APT 5 and PLA Troop 61786 I began tracking a subset of what was assessed to be low-level criminal activity, which actually turned out to be a group of six...
Watchfire Controller Software Vulnerability Alert
Watchfire Controller Software Vulnerability Alert 🚨 On July 30, 2026, CISA published an alert regarding a significant vulnerability in the Watchfire Controller Software. This vulnerability, identi...
The 73,000-Server Market Reselling Western Frontier AI into China
The 73,000-Server Market Reselling Western Frontier AI into China Western frontier AI is not sold in mainland China, yet it is utilized daily. This report maps the infrastructure that enables this...
Schneider Electric IGSS Vulnerability Advisory
Schneider Electric IGSS Vulnerability Advisory 🚨 Date Published: July 30, 2026 Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCA...
NASA Core Flight System Health & Safety Application Vulnerability Advisory
NASA Core Flight System (cFS) Health & Safety (HS) Application Vulnerability Advisory 🚨 Attention! A critical vulnerability has been identified in the NASA Core Flight System (cFS) Health &...
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents 🚀 Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instru...
CosmosEscape Taking Over Every Database in Azure Cosmos DB
CosmosEscape: Taking Over Every Database in Azure Cosmos DB A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database. Wiz Research uncovered...
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks 🚨 Overview: Unit 42 has uncovered a sophisticated AI-enabled autonomous hacking campaign orchestrated by a Chinese-spe...
CVE-2026-68563 - Information Disclosure in Ansible Collection Redhat Leapp
CVE-2026-68563 - Information Disclosure in Ansible Collection Redhat Leapp CVE-2026-68563 describes an information disclosure vulnerability in ansible-collection-redhat-leapp related to insecure b...
2026-07-30 Daily Vulns
Securing Agents Across Perplexity's Client Endpoints with Numbat
Securing Agents Across Perplexity’s Client Endpoints with Numbat Numbat is Perplexity’s open-source agent security suite for client endpoints. It detects, prevents, and investigates risky AI agent...