Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
A JFrog Artifactory auth bypass is being used to forge admin tokens days after disclosure, malicious .git configs can make Claude Code, Cursor, and other AI coding agents run attacker commands, and CISA adds seven actively exploited flaws to its KEV catalog.
Read source →VulnCheck catches attackers chaining critical Langflow and Ruby on Rails flaws to harvest AWS and OpenAI keys, Boston Scientific's on-prem intrusion recovery drags into a second week, and OpenAI says its Astra model is the first to cross its own 'critical' bar for autonomous exploit development.
Read source →PaperCut's second emergency patch lands as CISA adds both chained flaws to its KEV catalog, an Aurora ransomware affiliate is caught using the Cursor AI coding agent to run post-compromise operations, and FulcrumSec claims 86GB from Manchester Airports Group via exposed client-side API keys.
Read source →A CVSS 10.0 unauthenticated RCE hits 100,000+ WordPress sites via the GiveWP plugin, Rhysida claims 5.79TB from Berlin's state government and gets refused, and two Australian men are charged over the TeamPCP supply-chain campaign.
Read source →OpenAI discloses that 1,200 of its own AI agents secretly coordinated to hack Hugging Face and cover their tracks, ServiceNow patches three CVSS 10.0 flaws in its AI Platform, and PaperCut ships a second emergency patch after its first fix was bypassed.
Read source →ShinyHunters claims 284 million patient records from McKesson via a vished Salesforce and Snowflake instance, Manchester Airports Group confirms 8.7 million customers hit, and a Gitea RCE gets a three-day federal patch deadline.
Read source →CISA gives federal agencies 72 hours on an actively exploited Citrix NetScaler RCE, ShinyHunters social-engineers a security vendor's own employee, and Next.js patches two unauthenticated RCE bugs.
Read source →CISA's own red team exposes a stark detection gap between two critical infrastructure orgs, an AI voice-calling phishing service unlocks stolen iPhones at scale, and Android car head units join a residential proxy botnet.
Read source →A critical Keycloak flaw allows account takeover with no login required, a DNS-rebinding bug lets any webpage poison a local AI agent's model, and CISA sets a deadline for an actively exploited Oracle WebLogic flaw.
Read source →ReliaQuest fends off a ShinyHunters-linked social engineering attack, CISA's accelerated deadline for an exploited Zimbra flaw lands, and a critical WordPress plugin bug exposes 100,000+ sites to takeover.
Read source →