“Eye” Spy: Cyclops Blink Returns with Extended Capabilities 🚀 In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was disc...
Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-09-18 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-50285 pomerium - pomerium ...
Brevo Supply-Chain Attack Injected ClickFix Scripts on Customer Sites
Brevo Supply-Chain Attack 🚨 Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer s...
OpenAI Admits Its Models Lie to Cover Their Own Mistakes
OpenAI Admits Its Models Lie to Cover Their Own Mistakes 🚀 OpenAI has launched a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypasse...
Mitsubishi Electric GX Works3 and Motion Control Settings Vulnerability
Mitsubishi Electric GX Works3 and Motion Control Settings Vulnerability 🚨 Attention: A critical vulnerability has been identified in Mitsubishi Electric GX Works3 and Motion Control Settings. This...
LLMs Respond Differently to Harmful Prompts When AI Watermarking is Used
LLMs Respond Differently to Harmful Prompts When AI Watermarking is Used AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed that its...
Building an AI Detection Engine That Understands Agent Intent
Building an AI Detection Engine That Understands Agent Intent AI agents are doing real work in production: shipping code and managing infrastructure with broad access and few guardrails. Unlike de...
Bransys ELD Vulnerabilities Identified
Bransys ELD Vulnerabilities Identified 🚨 Attention Users! Successful exploitation of vulnerabilities in the Bransys ELD could allow unauthorized access to telemetry data and firmware. The Bransys ...
2026-09-17 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-11984 spacetime - Ad Inserte...
Update on Iranian Cyber Actors' Malware Deployment
Update on Iranian Cyber Actors’ Malware Deployment The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate a detailed malware analysis of the HEAVYGRAM malware. The FBI as...
Nonprofit that Tracks Meteors Taken Down by Cyberattack
Nonprofit that Tracks Meteors Taken Down by Cyberattack The International Meteor Organization, the nonprofit that coordinates and publishes amateur and professional observations of meteor phenomen...
Google Pixel Phones Vulnerable to Zero-Click Attacks
Google Pixel Phones Vulnerable to Zero-Click Attacks Both Google and Uncle Sam have issued warnings that attackers have exploited a zero-day improper authorization bug in Pixel phones’ cellular mo...
DPRK Fake IT Workers Inside Their Evolving Network Infrastructure
DPRK Fake IT Workers: Inside Their Evolving Network Infrastructure This report is a follow-up to our previous research on the internal network of DPRK IT workers. Using stealer logs, we expand our...
Operation RapidRust APT36 Deploys New Malware Tools
Operation RapidRust: APT36 Deploys New Malware Tools 🚀 In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation R...
NightEagle APT Targets Russian Organizations
NightEagle APT Targets Russian Organizations Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group ...
Memory-safe Programming Goes from Advocacy to Adoption
Memory-safe Programming Goes from Advocacy to Adoption 🚀 Just over a year ago, the U.S. Cybersecurity and Infrastructure Security Agency and the National Security Agency released their report on t...
Data Broker Radaris Loses Domains in Privacy Fight
Data Broker Radaris Loses Domains in Privacy Fight The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of peopl...