Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-09-08 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2024-11080 pickplugins - Post Gri...
2026-09-07 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2025-15693 Unknown - JCH Optimize...
Critical Vulnerabilities in MikroTik RouterOS Being Actively Exploited
Critical Vulnerabilities in MikroTik RouterOS Being Actively Exploited The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS. Combining two...
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control
ASUS Control Center Vulnerability Alert 🚨 ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that allow...
2026-09-06 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2021-44320 n/a - n/a Parrot...
CVE-2026-86148 - Tenda CP3 Kylin System Command Injection
CVE-2026-86148 - Tenda CP3 Kylin System Command Injection A security flaw, identified as CVE-2026-86148, has been discovered in Tenda CP3 27.5.57.101. This vulnerability has a CRITICAL CVSS 4.0 sc...
2026-09-05 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2022-35499 n/a - n/a In Tri...
Plex Issues Urgent Patch Warning for 300,000 Media Servers
Urgent Patch Warning for Plex Media Servers 🚨 Plex has issued an urgent warning to update Plex Media Servers and the Desktop client app to the latest versions. Thousands of Plex owners haven’t pat...
Contagious Interview Trojanized macOS Installers
Contagious Interview: Trojanized macOS Installers Jamf Threat Labs has uncovered fake macOS installers tied to the same infrastructure behind past Git hook and VS Code task file attacks. 🚨 Jamf Th...
X Money Rollout Linked to Password-Reset Attacks
X Money Rollout Linked to Password-Reset Attacks 🚨 X has reported that attackers may be targeting accounts as its X Money payments service becomes more widely available. The company is currently i...
New Backdoors from Toy Ghouls
New Backdoors from Toy Ghouls 🚨 We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian o...
Multiple Vulnerabilities in XING CPTrans-ME-X
Multiple Vulnerabilities in XING CPTrans-ME-X 🚨 XING CPTrans-ME-X contains multiple vulnerabilities that pose significant security risks. Specifically, firmware versions prior to Ver 1.8.1.17 are ...
Chinese Speaking Threat Actors Targeting Mexican Android Users With Remote Access Trojan
Chinese Speaking Threat Actors Targeting Mexican Android Users With Remote Access Trojan 🚨 Intel471 Malware Intelligence researchers recently uncovered a sprawling phishing operation that used Met...
2026-09-04 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2023-54356 kyverno - kyverno ...
Rogue ScreenConnect Installations Suggest Worm-Like Activity
Rogue ScreenConnect Installations Suggest Worm-Like Activity 🚨 Recently, Huntress observed a strange pattern across unrelated endpoints within several different organizations that we protect. In l...
Signature Optional - Analysis of CVE-2026-28323
Signature Optional - Analysis of CVE-2026-28323 The SamlConsumer.getAuthenticatedUserFromSamlResponse() method was where the authentication decision happened. This method processed SAMLResponse va...
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Pegasus Zero-Click Exploit Infects Serbian Student Activist’s iPhone A member of Serbia’s student protest movement has been infected with NSO Group’s Pegasus spyware through an iMessage zero-click...