Security Brief Daily

Security Brief Daily

A daily AI-generated cybersecurity briefing. Fresh threat intelligence, vulnerability roundups, and infosec news — concise, clear, and delivered every day.

  1. 1日前

    Aug 07, 2026 · #34

    Episode 34 — 07 Aug 2026 1. ClickFix attack pushes macOS infostealer for crypto theft attacks Source: Bleeping Computer A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...] 2. TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign Source: The Hacker News A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.... 3. Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access Source: The Hacker News Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into... 4. Swiss government SharePoint breach compromised 200 accounts Source: Bleeping Computer Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...] 5. CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild Source: The Hacker News A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8),... 6. New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts Source: The Hacker News Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is... 7. CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws Source: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...] 8. Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group Source: Bleeping Computer A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]

  2. 2日前

    Aug 06, 2026 · #33

    Episode 33 — 06 Aug 2026 1. CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild Source: The Hacker News A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8),... 2. Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk Source: The Hacker News Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers... 3. Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Source: The Hacker News Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span... 4. Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Source: The Hacker News An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea... 5. Ransom Cartel ransomware creator sentenced to 16 years in prison Source: Bleeping Computer Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...] 6. CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws Source: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...] 7. Hackers run khunt post-exploitation toolkit from Oracle database Source: Bleeping Computer Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...] 8. COLDCARD security audit phishing attack installs remote access tool Source: Bleeping Computer A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]

  3. 3日前

    Aug 05, 2026 · #32

    Episode 32 — 05 Aug 2026 1. CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS... 2. TP-Link patches Omada ZTP flaws allowing hackers to breach networks Source: Bleeping Computer TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...] 3. QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer Source: The Hacker News Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain... 4. New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Source: The Hacker News cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes... 5. Phishing service spoofs RingCentral to steal Microsoft 365 accounts Source: Bleeping Computer The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...] 6. Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access Source: The Hacker News Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and... 7. OpenAI, Anthropic AI agents targeted real people and systems in cyber tests Source: Bleeping Computer OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing... 8. New XCSSET variant targets macOS devs via compromised Xcode projects Source: Bleeping Computer A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]

  4. 4日前

    Aug 04, 2026 · #31

    Episode 31 — 04 Aug 2026 1. INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws Source: The Hacker News The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware... 2. New Pass-ta-key attacks let malware hijack Google-synced passkeys Source: Bleeping Computer Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...] 3. Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts Source: The Hacker News Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud... 4. Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts Source: Bleeping Computer Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...] 5. Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS Source: The Hacker News An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100... 6. 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users Source: The Hacker News Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking... 7. N-able warns of N-central auth bypass flaw exploited in attacks Source: Bleeping Computer N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...] 8. New DOUBLECUP ClickFix service hides malware in browser cache images Source: Bleeping Computer A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]

  5. 6日前

    Aug 02, 2026 · #29

    Episode 29 — 02 Aug 2026 1. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Source: The Hacker News Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity... 2. Rails patches critical Active Storage flaw with RCE potential Source: Bleeping Computer A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...] 3. Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes Source: The Hacker News An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A... 4. Amgen says cloud data breach exposed patient health, proprietary info Source: Bleeping Computer Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...] 5. Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites Source: The Hacker News Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and... 6. Online ad firm Adform’s script compromised to steal cryptocurrency Source: Bleeping Computer Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...] 7. CISA warns of cyberattacks disrupting U.S. water utilities Source: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...] 8. Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk Source: The Hacker News A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025....

  6. 8月1日

    Aug 01, 2026 · #28

    Episode 28 — 01 Aug 2026 1. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Source: The Hacker News Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity... 2. Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware Source: The Hacker News A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and... 3. Hacker uses DeepSeek AI to autonomously attack vulnerable servers Source: Bleeping Computer A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...] 4. Amgen says cloud data breach exposed patient health, proprietary info Source: Bleeping Computer Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...] 5. VMware fixes three critical flaws allowing auth bypass, VM escapes Source: Bleeping Computer Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...] 6. Microsoft Teams vishing attacks lead to Chaos ransomware attacks Source: Bleeping Computer Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...] 7. Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk Source: The Hacker News A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.... 8. HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm Source: The Hacker News Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a...

  7. 7月31日

    Jul 31, 2026 · #27

    Episode 27 — 31 Jul 2026 1. Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day... 2. JetBrains warns of critical TeamCity remote code execution flaw Source: Bleeping Computer JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...] 3. Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers Source: Bleeping Computer Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...] 4. Cisco warns of FMC static credential flaw exploited in zero-day attacks Source: Bleeping Computer Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...] 5. Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads Source: The Hacker News Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails... 6. VMware fixes three critical flaws allowing auth bypass, VM escapes Source: Bleeping Computer Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...] 7. Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts Source: The Hacker News South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or... 8. Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Source: The Hacker News The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the...

關於

A daily AI-generated cybersecurity briefing. Fresh threat intelligence, vulnerability roundups, and infosec news — concise, clear, and delivered every day.