Cybersecurity

The 5-Minute Cyber Brief: September 4, 2026

The 5-Minute Cyber Brief: September 4, 2026

Cisco network gear, court-system exposure, poisoned Terraform modules, and malware riding a trusted runtime....

Coder’s registry infrastructure compromised to push malicious modules

Coder’s registry infrastructure compromised to push malicious modules

The Coder incident is a supply-chain lesson in miniature: once attackers can tamper with trusted module distribution, defenders are no…

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The useful lesson in this campaign is not that Node.js is bad. It is that adversaries keep choosing legitimate runtimes…

HPE patches critical ArubaOS-CX remote code execution flaw

HPE patches critical ArubaOS-CX remote code execution flaw

ArubaOS-CX deserves attention because switching software rarely gets treated with the same urgency as identity or edge security until exploitation…

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The C-Track story matters because it sits inside judicial workflow, not generic office software. When court case-management data is exposed,…

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco's Nexus 9000 update is the kind of network-infrastructure issue that should not wait behind normal maintenance rhythm. The core…

The 5-Minute Cyber Brief: September 3, 2026

The 5-Minute Cyber Brief: September 3, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

Cisco Talos is making a more practical point than the headline alone suggests: if defensive workflows depend on third-party AI…

WordPress backup plugin flaw exposes millions of sites to takeover attacks

WordPress backup plugin flaw exposes millions of sites to takeover attacks

The All-in-One WP Migration and Backup plugin flaw is not just another WordPress plugin headline. Wordfence says CVE-2026-19949 can let…

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

CVE-2026-9586 in Sangoma Switchvox is more than a generic VoIP bug. Horizon3 says the unauthenticated SQL injection in the `/pa`…

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Two exploited zero-days in SonicWall SMA 1000 appliances are the kind of edge-security story that deserves faster attention than the…

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added ownCloud CVE-2023-49105, Linux kernel CVE-2026-53362, and JFrog Artifactory CVE-2026-66384 to the KEV catalog based on active exploitation. That…

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack…

Aesto Health says data breach affects over 9.5 million patients

Aesto Health says data breach affects over 9.5 million patients

Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals....

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42's AI-enabled malware research is useful because it separates hype from operational change. The story is not that attackers…

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications,…

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to…

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

CrowdStrike's August Patch Tuesday analysis matters because it turns a wall of Microsoft CVEs into a prioritization map. The real…

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA's latest KEV move matters because it turns two PaperCut flaws into an immediate exposure decision, not a routine backlog…

Identity Abuse Through Trusted Communication Channels

Identity Abuse Through Trusted Communication Channels

This Unit 42 research matters because it explains how identity attacks ride inside the tools employees already trust. The danger…

The 5-Minute Cyber Brief: September 1, 2026

The 5-Minute Cyber Brief: September 1, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix is valuable as a stand-alone story because it shows a modern ClickFix chain built for persistence, not just initial…

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Spring Ring is useful because it shows how collaboration platforms are becoming identity and access attack surfaces, not just communication…

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's Rhysida incident matters because it shows how quickly a public-sector cyber event becomes a data-governance and continuity problem once…

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA's latest KEV move matters because it turns two PaperCut flaws into an immediate exposure decision, not a routine backlog…

Identity Abuse Through Trusted Communication Channels

Identity Abuse Through Trusted Communication Channels

This Unit 42 research matters because it explains how identity attacks ride inside the tools employees already trust. The danger…

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix is valuable as a stand-alone story because it shows a modern ClickFix chain built for persistence, not just initial…

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42's AI-enabled malware research is useful because it separates hype from operational change. The story is not that attackers…

McKesson discloses breach after ShinyHunters claims patient data theft

McKesson discloses breach after ShinyHunters claims patient data theft

The McKesson disclosure is not valuable because of the raw record claim alone. It matters because it points to a…

PaperCut releases second emergency patch for exploited flaws

PaperCut releases second emergency patch for exploited flaws

PaperCut is warning that active exploitation now affects every NG and MF deployment, which makes this an exposure-mapping problem before…

The 5-Minute Cyber Brief: August 28, 2026

The 5-Minute Cyber Brief: August 28, 2026

The August 28 Cyber Brief tracks urgent Citrix and SharePoint exploitation, a critical zero-click WordPress risk, resilient GoCaracal malware, and…

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42's AI-enabled malware dataset is useful because it cuts through hype with numbers: 405 samples collected, only 12 observed…

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Arctic Wolf's GoCaracal research is useful because it adds specifics to the Dark Caracal story: a Go-based framework with lightweight…

Critical Avada WordPress theme flaw enables zero-click RCE

Critical Avada WordPress theme flaw enables zero-click RCE

CVE-2026-18431 is not a simple plugin bug. Wordfence says attackers can chain six weaknesses across the Avada theme and Fusion…

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Hackers target Microsoft SharePoint RCE chain with PoC exploit

The SharePoint story is more specific than "RCE chain under attack." Defenders are now dealing with CVE-2026-55040 in the JWT…

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CVE-2026-8452 is no longer a theoretical NetScaler problem. CISA has now ordered federal agencies to fix it by August 29…

The 5-Minute Cyber Brief: August 26, 2026

The 5-Minute Cyber Brief: August 26, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

This campaign is worth attention because it moves dead-drop logic into an FTP welcome banner, which is unusual enough to…

The safety penalty: Reclaiming operational sovereignty in the age of AI

The safety penalty: Reclaiming operational sovereignty in the age of AI

Cisco Talos is making a strategic point that security leaders should not dismiss as thought-leadership filler. If defensive workflows depend…

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

AnonyMousKIT is more than another phishing-kit story because it connects stolen-device monetization to identity abuse. The useful operator detail is…

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

This campaign matters because the attacker is abusing trusted software-distribution infrastructure rather than only throwaway phishing sites. The useful detail…

Hackers breached over 270 Zimbra servers in ongoing attacks

Hackers breached over 270 Zimbra servers in ongoing attacks

CVE-2026-73570 is the kind of email-infrastructure issue that creates immediate cleanup pressure because it combines unauthenticated remote code execution with…

The 5-Minute Cyber Brief: August 25, 2026

The 5-Minute Cyber Brief: August 25, 2026

Live Zimbra exploitation, WordPress SSO abuse, a Keycloak takeover bug, and a router flaw that punches through NAT....

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos is describing a change in attacker workflow, not just another flashy AI label. UAT-10147 appears to be using…

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Keycloak CVE-2026-18963 deserves attention because it attacks the recovery path defenders usually trust when something else goes wrong. If an…

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

The Calix router flaw is useful because it turns a familiar consumer and branch-office assumption upside down. NAT is often…

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers target WordPress sites in miniOrange auth bypass attacks

The miniOrange WordPress SAML issue matters because it is sitting on an identity trust boundary many site owners assume is…

CISA orders urgent patching of actively exploited Zimbra flaw

CISA orders urgent patching of actively exploited Zimbra flaw

CVE-2026-73570 is the kind of email-infrastructure issue that creates immediate cleanup pressure because it combines unauthenticated remote code execution with…

The 5-Minute Cyber Brief: August 24, 2026

The 5-Minute Cyber Brief: August 24, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos is describing a change in attacker workflow, not just another flashy AI label. UAT-10147 appears to be using…

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock matters because Microsoft is describing more than another ransomware name. The operation uses decentralized infrastructure for communications, negotiation, and…

Defending Against an Active Threat to Siemens S7 Series PLCs

Defending Against an Active Threat to Siemens S7 Series PLCs

CISA, NSA, FBI, DOE, and EPA say actors are actively targeting Siemens S7 PLCs by scanning for internet-exposed devices and…

New SynkLoader malware pushed in Microsoft Teams phishing campaign

New SynkLoader malware pushed in Microsoft Teams phishing campaign

Expel says the campaign uses Microsoft Teams messages to push a fake "PowerShell Cleaner" MSI from Azure, then drops a…

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 is not a minor project-integrity issue. It is a 9.4 unauthenticated code-injection path against public projects, which means…

The 5-Minute Cyber Brief: August 21, 2026

The 5-Minute Cyber Brief: August 21, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos is describing a change in attacker workflow, not just another flashy AI label. UAT-10147 appears to be using…

CISA warns of hackers exploiting critical MLflow vulnerability

CISA warns of hackers exploiting critical MLflow vulnerability

MLflow is now important enough that an exposed default deployment can become a cloud-credentials problem, not just an AI-tooling problem.…

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 is not a minor project-integrity issue. It is a 9.4 unauthenticated code-injection path against public projects, which means…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

CrowdStrike's August Patch Tuesday analysis matters because it turns a wall of Microsoft CVEs into a prioritization map. The real…

Critical Zimbra RCE flaw now actively exploited in attacks

Critical Zimbra RCE flaw now actively exploited in attacks

CVE-2026-73570 is the kind of email-infrastructure issue that creates immediate cleanup pressure because it combines unauthenticated remote code execution with…

#StopRansomware: Gunra Ransomware

#StopRansomware: Gunra Ransomware

CISA's Gunra advisory is useful because it gives defenders more than a ransomware name. It maps how the group gets…

Phishing 3.0: The Fight Moves to Agent Versus Agent

Phishing 3.0: The Fight Moves to Agent Versus Agent

This story is valuable when read as a change in attack economics, not as another vague AI warning. The important…

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Cisco Talos adds something the broader Patch Tuesday roundups often miss: a defender's view of which Microsoft flaws are likely…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

CrowdStrike's August Patch Tuesday analysis matters because it turns a wall of Microsoft CVEs into a prioritization map. The real…

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

CISA's latest KEV additions are not four unrelated patch notes. They expose four different trust boundaries already under pressure: remote…

The 5-Minute Cyber Brief: August 19, 2026

The 5-Minute Cyber Brief: August 19, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

Hunting MacSync Stealer infrastructure through behavioral pivots

Hunting MacSync Stealer infrastructure through behavioral pivots

Microsoft says MacSync Stealer keeps rotating domains and delivery hosts, but it reuses the same AppleScript-assisted collection and exfiltration patterns,…

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers are exploiting an MLflow SSRF flaw to reach cloud metadata services and steal credentials, while a separate FUXA issue…

Clop created custom web shell for Windchill data theft attacks

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

This moved from important to urgent fast. CrowdStrike is pointing to a live exploitation or incident path that should be…

CISA: Windows Task Host flaw now exploited by ransomware gangs

CISA: Windows Task Host flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task…

The 5-Minute Cyber Brief: August 18, 2026

The 5-Minute Cyber Brief: August 18, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

This moved from important to urgent fast. CrowdStrike is pointing to a live exploitation or incident path that should be…

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock matters because Microsoft is describing more than another ransomware name. The operation uses decentralized infrastructure for communications, negotiation, and…

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers…

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software…

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse"…

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Three Known Exploited Vulnerabilities to Catalog

This is not just another catalog update. CISA is effectively telling defenders that these flaws have crossed from known problem…

Why metaphor may dictate your security strategy

Why metaphor may dictate your security strategy

In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely…

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including…

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated…

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse"…

The 5-Minute Cyber Brief: August 17, 2026

The 5-Minute Cyber Brief: August 17, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

AmnesiaStealer is worth a closer look because it is not just another Mac infostealer. Its operators pair ClickFix-style social engineering…

Max severity SAP Commerce Cloud flaw now targeted in attacks

Max severity SAP Commerce Cloud flaw now targeted in attacks

A max-severity SAP Commerce Cloud flaw being targeted only days after patch release should move this out of routine enterprise-app…

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock matters because Microsoft is describing more than another ransomware name. The operation uses decentralized infrastructure for communications, negotiation, and…

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

A SharePoint authentication bypass becomes much more serious once public proof-of-concept code and real exploitation arrive together. At that point,…

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

A Lazarus-linked Windows zero-day is not routine vulnerability noise. It is the kind of story that forces defenders to treat…

The 5-Minute Cyber Brief: August 14, 2026

The 5-Minute Cyber Brief: August 14, 2026

The cybersecurity developments that matter most today, explained in about five minutes....

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support…

Critical VMware vCenter RCE flaw exploited for reverse SSH access

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy…

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code.…

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch…

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched…

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Three Known Exploited Vulnerabilities to Catalog

This is not just another catalog update. CISA is effectively telling defenders that these flaws have crossed from known problem…

Why metaphor may dictate your security strategy

Why metaphor may dictate your security strategy

In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely…

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

This moved from important to urgent fast. CrowdStrike is pointing to a live exploitation or incident path that should be…

The 5-Minute Cyber Brief: August 13, 2026

The 5-Minute Cyber Brief: August 13, 2026

The cybersecurity developments that matter most today, explained in about five minutes....