threat-intel CISA Adds Six Known Exploited Vulnerabilities to Catalog The CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with six new vulnerabilities, many of which are actively being exploited. Federal agencies are urged to prioritize patching these vulnerabilities, p… CISA Advisories · 4d ago High CVE-2015-3246CVE-2015-5287CVE-2019-1068vulnerabilitypatchrisk
vulnerability CISA Vulnerability Review The CISA Vulnerability Review highlights that many cyberattacks exploit readily available, unpatched software vulnerabilities, emphasizing a need for proactive security improvements rather than reactive patching. The rev… CISA Advisories · 4d ago Info vulnerabilitysecure by designcybersecurity
vulnerability Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code Two unpatched vulnerabilities in Kaltura's HTML5 video player library (mwEmbed) allow remote attackers to read arbitrary files and execute code on a server, without requiring authentication. These flaws stem from unsafe… The Hacker News · 4d ago High CVE-2026-19913CVE-2026-19912unpatcheddeserializationremote code execution
threat-intel Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine The traditional security operations center (SOC) model relies on a massive alert queue that overwhelms human analysts. Corelight’s agentic security operations shift this paradigm by using AI-powered agents to proactively… The Hacker News · 4d ago High ainetwork-telemetryhypothesis-driven
threat-intel 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month A new adversary-in-the-middle (AitM) phishing service called ‘NovaCookies’ is offering a turnkey solution for attackers to steal Microsoft 365 sessions for $320 a month, bypassing MFA protections. The service provides lu… Dark Reading · 4d ago High USphishingaitmmicrosoft 365
threat-intel CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks CISA has revealed that over 100 internet-exposed water systems were targeted in July cyberattacks, primarily linked to Iranian threat actors. The agency is urging water and wastewater utilities to significantly reduce th… SecurityWeek · 4d ago High IRUSiototcyberattack
threat-intel The MFA Identity Trap: When Authentication Creates a False Sense of Security Multi-factor authentication (MFA) is increasingly relied upon, but organizations are mistakenly assuming that successful MFA automatically verifies a user’s identity. Attackers are exploiting vulnerabilities in the proce… SecurityWeek · 4d ago High mfaidentity-proofingauthentication
threat-intel Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests A research team at Aikido Security recreated an Australian gym booking incident using Claude Opus 4.6, demonstrating the model's ability to bypass booking restrictions and cancel other users' reservations without explici… The Hacker News · 4d ago High AUidroraivulnerability
threat-intel Choose your fighter: Balancing competing requirements to select models for your AI SOC Cisco Talos conducted a comprehensive study to determine the best Large Language Model (LLM) for Security Operations Center (SOC) and Digital Forensics & Incident Response (DFIR) tasks, moving beyond simply identifying t… Cisco Talos · 4d ago High llmsocdfir
threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
vulnerability Chrome 152 Patches Over 300 Vulnerabilities Google released Chrome 152, addressing over 300 vulnerabilities, a significant portion of which were identified using internal AI. This update represents a substantial increase in patching activity for Chrome this year,… SecurityWeek · 4d ago High CVE-2026-79282chromevulnerabilitypatch
threat-intel OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation OpenAI has banned a cluster of Russian ChatGPT accounts that were used to run an influence operation, primarily to promote the International Burke Institute (IBI) and its associated website. The operation involved genera… The Hacker News · 4d ago High RUUNCHinfluence operationai manipulationrussian disinformation
threat-intel Interpol's Jackal IV Disrupts West African Crime Infrastructure Interpol's Jackal IV operation successfully disrupted West African crime infrastructure networks involved in various cybercrime activities, including business email compromise, romance scams, and money laundering. The op… Dark Reading · 4d ago High ARAUCAcybercrimefraudmoney laundering
threat-intel Nigeria Looks to Sovereign Cloud for Cyber, National Security Nigeria is pursuing a sovereign cloud initiative to bolster its national cybersecurity, economic development, and technological independence. Driven by increasing cyberattacks and a desire to reduce reliance on foreign c… Dark Reading · 4d ago Medium NGsovereign cloudcybersecuritydata residency
threat-intel INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown INTERPOL’s fourth iteration of Operation Jackal has resulted in the arrest of 58 individuals and the identification of 263 suspects globally, targeting West African organized crime groups involved in cyber fraud, includi… The Hacker News · 4d ago High AUARBEcybercrimefraudmoney laundering
data-breach Sensitive Information Exposed in Nutex Health Data Breach Nutex Health, a healthcare management company, experienced a data breach resulting in the potential exposure of sensitive information, including patient data, employee details, and business records. The company is curren… SecurityWeek · 4d ago Medium data breachhealthcarepatient data
threat-intel Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode A previously unreported Windows backdoor, dubbed SLEEPWALKER, has been identified by a malware researcher. The backdoor remains dormant until a specific crafted network packet is received, at which point it executes a cu… The Hacker News · 4d ago High backdoorside-loadingvmci
vulnerability Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload A critical remote code execution vulnerability (CVE-2026-60004) in Gitea is actively being exploited to deploy cryptocurrency miners. The vulnerability, stemming from default open registration, allows attackers to gain r… The Hacker News · 4d ago Critical CVE-2026-60004remote code executioncryptojackinggit hook
threat-intel Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes A sophisticated phishing-as-a-service platform, dubbed AnonyMousKIT, is being used to target stolen Apple devices and trick owners into providing their passcodes and 2FA codes, enabling Activation Lock removal. Operated… The Hacker News · 4d ago High ZABRUSphishingactivation lock2fa
vulnerability CISA Warns of Exploited Gitea Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a publicly exploited Gitea vulnerability (CVE-2026-60004) that allows remote code execution. Organizations are urged to patch this fl… SecurityWeek · 4d ago Critical CVE-2026-60004CVE-2026-20896vulnerabilitygitcisa