Follow the cybersecurity developments that matter, explained in about five minutes each weekday.
CISA says ransomware crews now exploit TeamCity CVE-2026-63077. Upgrade to 2025.11.7 or 2026.1.3, take the server off the Internet, and check for compromise.
A pre-auth SQL injection in Roundcube's virtuser_query plugin is now exploited. Update to 1.6.16 or 1.7.1 or disable the plugin. Here's what to check today.
A cPanel CalDAV/CardDAV flaw lets any hosting account run code as root. Update to 11.134.0.57, 11.136.0.41 or 11.138.0.8, plus WP Toolkit 6.11.3, today.
GitLab's issue-by-email address carries an account-wide token that can push code and run CI jobs past IP allowlists. How to rotate it and check for misuse.
Friday's 5-minute cyber brief: ransomware on TeamCity build servers, exploited Roundcube webmail, cPanel root for any account, and a risky GitLab email token.
Attackers went from probing to writing PHP in under a day. Verify you’re on a fixed release....
If auth sits in a Tomcat security constraint, an alternate endpoint name can skip it....
No known exploit yet — that’s the window, not a reason to wait....
Shared kernel, pre-auth, PoCs out. Role checks won’t save you....
WordPress under active exploitation, Tomcat WebSocket bypass, Palo Alto HIGHEST urgency, SAP OVERPASS with public PoCs....
Actively exploited CVSS 10 on on-prem VCO. Hosted patched; on-prem needs fixed builds and an IoC hunt....
In-the-wild V8 write; Chrome 153.0.8010.36/.37 fixes it. Federal KEV due is today — verify Edge and other Chromium browsers too....
Check Point VPN+mgmt KEV due Friday, F5 APM OAuth RCE, Arista VeloCloud CVSS 10, Chromium V8 due today....