Cyber News

Inside the Daily Brief

A real sample of the weekday read

WordPress backup plugin flaw exposes millions of sites to takeover attacks

WordPress backup plugin flaw exposes millions of sites to takeover attacks

The All-in-One WP Migration and Backup plugin flaw is not just another WordPress plugin headline. Wordfence says CVE-2026-19949 can let…

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

CVE-2026-9586 in Sangoma Switchvox is more than a generic VoIP bug. Horizon3 says the unauthenticated SQL injection in the `/pa`…

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Two exploited zero-days in SonicWall SMA 1000 appliances are the kind of edge-security story that deserves faster attention than the…

The CyberExperts Daily Brief

Keep up with the cyber news that changes the day

Get the weekday brief for people scanning the news: the developments worth a closer look, explained in about five minutes.

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added ownCloud CVE-2023-49105, Linux kernel CVE-2026-53362, and JFrog Artifactory CVE-2026-66384 to the KEV catalog based on active exploitation. That…

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack…

Aesto Health says data breach affects over 9.5 million patients

Aesto Health says data breach affects over 9.5 million patients

Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals....

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42's AI-enabled malware research is useful because it separates hype from operational change. The story is not that attackers…

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications,…

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to…

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

CrowdStrike's August Patch Tuesday analysis matters because it turns a wall of Microsoft CVEs into a prioritization map. The real…

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA's latest KEV move matters because it turns two PaperCut flaws into an immediate exposure decision, not a routine backlog…

Identity Abuse Through Trusted Communication Channels

Identity Abuse Through Trusted Communication Channels

This Unit 42 research matters because it explains how identity attacks ride inside the tools employees already trust. The danger…