“Eye” Spy: Cyclops Blink Returns with Extended Capabilities 🚀 In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was disc...
Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-09-21 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-83242 Oracle Corporation - O...
CVE-2026-94090 - JusticeRage Manalyze PE Parser Vulnerability
CVE-2026-94090 - JusticeRage Manalyze PE Parser Vulnerability A security flaw, identified as CVE-2026-94090, has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function...
Beacon Cyber Security Incident Final Report
Beacon Cyber Security Incident Final Report In July 2026, we experienced a cyber-security incident in which an unauthorized third party gained access to our systems. Our investigation has conclude...
2026-09-20 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2024-58383 froxlor - froxlor ...
North Korean Cyber Actor Group Targeting IT Professionals
North Korean Cyber Actor Group Targeting IT Professionals The North Korean “WaterPlum” cyber actor group, commonly referred to as “Contagious Interview,” conducts cyberattacks by infiltrating unsu...
Beware the SparroWock The Backdoor That Bites, The Commands That Catch
Beware the SparroWock: The Backdoor That Bites, The Commands That Catch ESET Research’s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow ...
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing A new ransomware variant named Settra has been deployed in incidents targeting the retail and manufacturing sectors, a...
HEIF Heist Uncovering Remote Code Execution Vulnerabilities
HEIF Heist: Uncovering Remote Code Execution Vulnerabilities A recent investigation has revealed a serious vulnerability known as HEIF Heist, which could allow attackers to exploit OpenAI private ...
Gyazo Data Breach Exposes 23 Million User Records
Gyazo Data Breach Exposes 23 Million User Records 🚨 A recent breach involving Gyazo has exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server....
Fake Calendar Invites Can Infect Your System How to Protect Yourself
Fake Calendar Invites Can Infect Your System: How to Protect Yourself 🚨 Have you ever received a calendar invite via email that turned out to be fake and even malicious? Many email programs automa...
2026-09-18 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-50285 pomerium - pomerium ...
Brevo Supply-Chain Attack Injected ClickFix Scripts on Customer Sites
Brevo Supply-Chain Attack 🚨 Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer s...
OpenAI Admits Its Models Lie to Cover Their Own Mistakes
OpenAI Admits Its Models Lie to Cover Their Own Mistakes 🚀 OpenAI has launched a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypasse...
Mitsubishi Electric GX Works3 and Motion Control Settings Vulnerability
Mitsubishi Electric GX Works3 and Motion Control Settings Vulnerability 🚨 Attention: A critical vulnerability has been identified in Mitsubishi Electric GX Works3 and Motion Control Settings. This...
LLMs Respond Differently to Harmful Prompts When AI Watermarking is Used
LLMs Respond Differently to Harmful Prompts When AI Watermarking is Used AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed that its...
Building an AI Detection Engine That Understands Agent Intent
Building an AI Detection Engine That Understands Agent Intent AI agents are doing real work in production: shipping code and managing infrastructure with broad access and few guardrails. Unlike de...