Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
A CISA deadline lands today for a SharePoint RCE attackers are using to steal machine keys that survive patching, a Certighost exploit lets any domain user impersonate a Domain Controller, Golden Chickens resurfaces with four new modular malware families, and Craneware confirms attackers stole data affecting thousands of US hospitals.
Read source →ShinyHunters vishes an Abbott employee into handing over an Entra SSO account and claims tens of millions of patient records, Chaos ransomware's new msaRAT backdoor hides its C2 traffic inside Chrome and Edge, Stadler Rail refuses a $12.3M ransom after a supplier's platform is breached, and a Chrome extension flaw on 329 million browsers let any website read WhatsApp Web chats.
Read source →A public PoC turns a fourth SharePoint RCE into active machine-key theft, a chained WordPress Core bug lets anonymous attackers run code on default installs, Anubis ransomware claims Coca-Cola's Fairlife breach and threatens to leak 1TB of data, and Google ships an AI model that finds, exploits, and patches vulnerabilities on its own.
Read source →A hacker wipes Romania's entire land registry after a failed extortion attempt, an exposed AWS bucket leaks 48,000 car rental bookings, Zimbra patches an unauthenticated command-injection flaw and four XSS bugs, and a researcher nets $78,000 for an IDOR chain in Meta's support platform.
Read source →A ransomware attack halts US production at Coca-Cola's Fairlife dairy unit, ServiceNow's AI Platform gets hit with a pre-auth sandbox-escape RCE days after disclosure, a Russian-speaking actor runs a botnet almost entirely through Gemini CLI, and Qilin ransomware crews ride a GlobalProtect auth bypass into corporate networks.
Read source →Kaspersky catches HelloNet abusing ViPNet's own update channel against Russian government networks, a 13-year-old Daxin rootkit resurfaces in Taiwan next to a pre-login SYSTEM backdoor, EY confirms client tax records stolen via a support-ticket platform, and Ecopetrol blocks encryption but still loses data from 3,300 cloud accounts.
Read source →CISA's Sunday deadline hits for two exploited FortiSandbox flaws, Checkmarx exposes a blockchain-C2 npm supply chain attack on Vite developers, a new Spirals ransomware strain encrypts a network in 24 hours, and Abbott fights a dual extortion claim.
Read source →CISA fast-tracks a critical SharePoint deserialization bug into KEV, WordPress force-patches a pre-auth RCE chain dubbed wp2shell, North Korean hackers hide malware in SVG images, and 23andMe pays $18M over its 2023 breach.
Read source →SAP patches a max-impact CVSS 9.9 NetWeaver flaw, a 16-year-old Linux KVM bug lets guest VMs escape to the host, an unpatched Windows flaw mounts admin hives, Kaspersky exposes a patient SE Asia espionage campaign, and Scattered Spider's TfL hackers get 5.5 years.
Read source →A ShareFile zero-day forces customers to pull servers offline, 292 fake GitHub repos spread a Chrome-encryption-bypassing infostealer, a ransomware crew's Bosch 'proof' turns out to be a public manual, and an unpatched Claude for Chrome flaw lets rogue extensions read your Gmail.
Read source →