Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
U.S. Disrupts Xinbi Guarantee Scam Marketplace 🚨 The U.S. Department of Justice (DOJ) announced coordinated actions against an illicit online marketplace known as Xinbi Guarantee. This marketplace...
Once Bluemoon Multiple State Aligned Threat Actors Rapidly Adopt Novel Exploit
Once Bluemoon Multiple State Aligned Threat Actors Rapidly Adopt Novel Exploit 🚨 Proofpoint has identified four espionage-motivated threat actors employing a new exploit kit that chains multiple C...
New N0va Phishkit Targets North America and EU A Growing Identity Risk for SOCs
New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the E...
CVE-2026-88002 - Open WebUI Vulnerability Exposes Server to Hang
CVE-2026-88002 - Open WebUI Vulnerability 🚨 CVE-2026-88002: Open WebUI allows any authenticated user to hang the server via a cyclic chat message history. Open WebUI is an extensible, feature-rich...
CVE-2026-15460 - Missing Channel-State Validation in Zephyr Bluetooth Classic L2CAP Receive Path
CVE-2026-15460 - Missing Channel-State Validation in Zephyr Bluetooth Classic L2CAP Receive Path CVE-2026-15460 details a missing channel-state validation in the Zephyr Bluetooth Classic L2CAP rec...
2026-09-09 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2021-44319 n/a - n/a Parrot...
Grindr Settles UK Data Privacy Claims for £26m
Grindr Settles UK Data Privacy Claims for £26m Grindr has agreed to pay £26m ($35.2m) to settle a UK group action over allegations that it unlawfully processed users’ personal data and misused pri...
ShinyHunters Hackers Claim Breach of Florida "DAVID" DMV Database
ShinyHunters Hackers Claim Breach of Florida “DAVID” DMV Database The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known ...
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data 🚨 An exposed Vietnam-linked APIS database has revealed 220.8 million passenger and crew records, including sensitive passport ...
Hackers Breach F5 BIG-IP APM Devices to Deploy Linux Rootkit
Hackers Breach F5 BIG-IP APM Devices to Deploy Linux Rootkit A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly...
DoppelCart Fraud Network Exposed 119,000 Fake Shops Stealing Credit Cards
DoppelCart Fraud Network Exposed: 119,000 Fake Shops Stealing Credit Cards A massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal paymen...
AD Rights Management Service (Part 1) Architecture, Deprecation, and Reconnaissance
AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance Answering six weeks of research into Active Directory Rights Management Services (AD RMS) produced a compiled t...
2026-09-08 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2024-11080 pickplugins - Post Gri...
Mathspace Discloses Data Breach Affecting Over 1 Million People
Mathspace Discloses Data Breach Affecting Over 1 Million People 🚨 Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, s...
LG TV Flaws Could Let Attackers Listen In, Even In Standby Mode
LG TV Flaws Could Let Attackers Listen In, Even In Standby Mode Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks u...
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
Condé Nast Data Breach 🚨 Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud, and scams. A database said to contain 32.8 million Condé...
Welsh Environment Regulator's FoI Blunder Exposes Diversity Data of 2,000 Staff
Welsh Environment Regulator’s FoI Blunder Exposes Diversity Data of 2,000 Staff Natural Resources Wales (NRW) has revealed that diversity data belonging to approximately 2,000 current and former e...