Security Brief Daily

Security Brief Daily

A daily AI-generated cybersecurity briefing. Fresh threat intelligence, vulnerability roundups, and infosec news — concise, clear, and delivered every day.

  1. 19h ago

    Jul 24, 2026 · #20

    Episode 20 — 24 Jul 2026 1. Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Source: The Hacker News A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges,... 2. Chick-fil-A data breach affects more than 13,000 customers Source: Bleeping Computer Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...] 3. Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes Source: The Hacker News A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the... 4. Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks Source: The Hacker News The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it... 5. Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry Source: The Hacker News Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked... 6. Clop ransomware targets Windchill, FlexPLM in data theft attacks Source: Bleeping Computer The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...] 7. CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity Source: CISA News Related Articles May 21, 2026 Press Release CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form Apr 23, 2026 Press Release CISA, National Cyber Security Centre (NCSC) UK, and Global Partners Issue Advisory on Chinese Government-Linked Covert... 8. Man gets six years for hacking 750 women's Snapchat accounts Source: Bleeping Computer An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]

  2. 3d ago

    Jul 21, 2026 · #19

    Episode 19 — 21 Jul 2026 1. WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning Source: The Hacker News Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137,... 2. New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Source: The Hacker News Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model... 3. Estée Lauder discloses data breach via Oracle E-Business flaw Source: Bleeping Computer Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...] 4. SonicWall SMA1000 flaws exploited as zero-days to push custom malware Source: Bleeping Computer Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...] 5. Windows LegacyHive zero-day flaw gets free, unofficial patches Source: Bleeping Computer Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...] 6. Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs Source: The Hacker News A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19... 7. Critical ServiceNow code execution flaw now exploited in attacks Source: Bleeping Computer Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...] 8. Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution Source: The Hacker News F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus...

  3. 4d ago

    Jul 20, 2026 · #18

    Episode 18 — 20 Jul 2026 1. World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent Source: The Hacker News In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure... 2. Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution Source: The Hacker News F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus... 3. SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access Source: The Hacker News A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the... 4. UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Source: The Hacker News Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has... 5. WordPress Core "wp2shell" RCE flaws get public exploits, patch now Source: Bleeping Computer Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...] 6. Microsoft warns of surge in ACR Stealer attacks on customers Source: Bleeping Computer Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...] 7. Hackers abuse ViPNet software to target Russian govt agencies Source: Bleeping Computer An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...] 8. SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines Source: The Hacker News Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below -...

  4. 5d ago

    Jul 19, 2026 · #17

    Episode 17 — 19 Jul 2026 1. WordPress Core "wp2shell" RCE flaws get public exploits, patch now Source: Bleeping Computer Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...] 2. New Windows LegacyHive zero-day gives hackers admin privileges Source: Bleeping Computer A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. [...] 3. GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Source: The Hacker News 4. Microsoft warns of surge in ACR Stealer attacks on customers Source: Bleeping Computer Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...] 5. New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens Source: The Hacker News A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators,... 6. Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man Source: The Hacker News Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall... 7. Abbott probes two cyber incidents amid extortion claims Source: Bleeping Computer Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal... 8. Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Source: The Hacker News Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil,...

  5. Jul 17

    Jul 17, 2026 · #16

    Episode 16 — 17 Jul 2026 1. CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply... 2. CISA urges immediate action on actively exploited Fortinet flaws Source: Bleeping Computer CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. [...] 3. CISA orders feds to patch actively exploited Oracle flaw by Saturday Source: Bleeping Computer CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. [...] 4. New ClickLock macOS malware traps users into revealing login password Source: Bleeping Computer A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...] 5. US charges two over laundering $43 million from investment fraud Source: Bleeping Computer U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. [...] 6. Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Source: The Hacker News Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Workplace for Windows before version 7.0.0 and Zoom... 7. 20+ Hijacked Government Websites Became an Attack Channel Source: The Hacker News More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed... 8. Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor Source: The Hacker News An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("srt64.sys"), as the kernel-mode rootkit is referred to,...

  6. Jul 16

    Jul 16, 2026 · #15

    Episode 15 — 16 Jul 2026 1. Google Gemini CLI abused as a hacking agent, malware botnet operator Source: Bleeping Computer A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...] 2. Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Source: The Hacker News Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation... 3. CISA warns admins to patch actively exploited SharePoint flaws Source: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. [...] 4. We built a vulnerability vending machine: AI tokens in, zero-days out Source: Bleeping Computer Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with... 5. SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now Source: Bleeping Computer SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...] 6. CISA and Partners Publish Guidance to Help Software Manufacturers and Online Service Providers Work With Security Researchers Source: CISA News Jul 14, 2026 Press Release CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors 7. Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Source: The Hacker News Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200. Those... 8. CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors Source: CISA News Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on...

  7. Jul 15

    Jul 15, 2026 · #14

    Episode 14 — 15 Jul 2026 1. SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data Source: The Hacker News SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that... 2. SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now Source: Bleeping Computer SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...] 3. Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days Source: Bleeping Computer Today is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. [...] 4. US charges alleged operators of Russian bulletproof hosting service Source: Bleeping Computer U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. [...] 5. Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown Source: Bleeping Computer Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. [...] 6. CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors Source: CISA News Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on... 7. Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Source: The Hacker News Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200. Those... 8. 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Source: The Hacker News Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable...

  8. Jul 14

    Jul 14, 2026 · #13

    Episode 13 — 14 Jul 2026 1. Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity Source: The Hacker News Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually... 2. U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support Source: The Hacker News The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. The VPN, named... 3. CISA warns of actively exploited RCE flaws in Joomla extensions Source: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. [...] 4. Lessons Learned from CISA’s Recent GitHub Leak Source: Krebs on Security The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being... 5. CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks Source: The Hacker News Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers,... 6. iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.... 7. US and allies warn of Russian critical infrastructure attacks Source: Bleeping Computer Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. [...] 8. Lidl discloses online shop breach after service provider hack Source: Bleeping Computer German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider. [...]

About

A daily AI-generated cybersecurity briefing. Fresh threat intelligence, vulnerability roundups, and infosec news — concise, clear, and delivered every day.