Security Brief Daily

Security Brief Daily

A daily AI-generated cybersecurity briefing. Fresh threat intelligence, vulnerability roundups, and infosec news — concise, clear, and delivered every day.

  1. 1d ago

    Sep 14, 2026 · #68

    Episode 68 — 14 Sep 2026 1. Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Source: The Hacker News A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and... 2. CISA: Hackers now exploit max severity GitLab flaw in attacks Source: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...] 3. Revolut discloses data breach exposing financial info, passports Source: Bleeping Computer Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...] 4. GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Source: The Hacker News GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in... 5. CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the... 6. Artifactory flaws chained in attacks deploying backdoor malware Source: Bleeping Computer Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...] 7. Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data Source: The Hacker News Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech... 8. Hackers exploit Tencent app flaw to deploy GrayRabbit malware Source: Bleeping Computer Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...] 9. Passkey-themed phishing attacks lead to Microsoft 365 data theft Source: Bleeping Computer Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...] 10. OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers Source: The Hacker News The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software...

  2. 2d ago

    Sep 13, 2026 · #67

    Episode 67 — 13 Sep 2026 1. CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the... 2. Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Source: Bleeping Computer The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...] 3. OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers Source: The Hacker News The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software... 4. GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Source: The Hacker News GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in... 5. Artifactory flaws chained in attacks deploying backdoor malware Source: Bleeping Computer Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...] 6. Passkey-themed phishing attacks lead to Microsoft 365 data theft Source: Bleeping Computer Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...] 7. Florida confirms DMV database breached via stolen police account Source: Bleeping Computer The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...] 8. New Android malware encrypts files, steals data, and harasses victims Source: Bleeping Computer A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...] 9. China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor Source: The Hacker News A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started... 10. Conti ransomware gang member sentenced to 4 years in prison Source: Bleeping Computer A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]

  3. 3d ago

    Sep 12, 2026 · #66

    Episode 66 — 12 Sep 2026 1. GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Source: The Hacker News GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in... 2. Artifactory flaws chained in attacks deploying backdoor malware Source: Bleeping Computer Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...] 3. Passkey-themed phishing attacks lead to Microsoft 365 data theft Source: Bleeping Computer Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...] 4. Florida confirms DMV database breached via stolen police account Source: Bleeping Computer The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...] 5. Hackers abused Claude to extract secrets from 1.8M Android apps Source: Bleeping Computer Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...] 6. AI-powered attack exploited PaperCut flaws to hack 395 organizations Source: Bleeping Computer A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...] 7. Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors Source: The Hacker News Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and... 8. PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances Source: The Hacker News A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from... 9. China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor Source: The Hacker News A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started... 10. Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks Source: The Hacker News The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android...

  4. 4d ago

    Sep 11, 2026 · #65

    Episode 65 — 11 Sep 2026 1. Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors Source: The Hacker News Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and... 2. New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws Source: Bleeping Computer Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...] 3. China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor Source: The Hacker News A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started... 4. CISA: WatchGuard RCE flaw now exploited in ransomware attacks Source: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...] 5. Conti ransomware gang member sentenced to 4 years in prison Source: Bleeping Computer A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...] 6. Trezor: 347,000 users targeted in phishing attacks after Brevo breach Source: Bleeping Computer Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...] 7. New Android malware encrypts files, steals data, and harasses victims Source: Bleeping Computer A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...] 8. PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances Source: The Hacker News A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from... 9. U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto Source: The Hacker News The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and... 10. Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks Source: The Hacker News The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android...

  5. 5d ago

    Sep 10, 2026 · #64

    Episode 64 — 10 Sep 2026 1. Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks Source: Bleeping Computer Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...] 2. U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto Source: The Hacker News The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and... 3. Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Source: The Hacker News The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak,... 4. Google warns of new Chrome zero-day bug exploited in attacks Source: Bleeping Computer Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...] 5. Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox Source: The Hacker News Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds... 6. Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week Source: The Hacker News Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been... 7. Veradigm warns of patient data breach after ransomware gang claims attack Source: Bleeping Computer Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...] 8. Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA Source: The Hacker News Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are... 9. Trezor warns users of email provider breach, phishing attacks Source: Bleeping Computer Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...] 10. New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Source: Bleeping Computer An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]

  6. 6d ago

    Sep 09, 2026 · #63

    Episode 63 — 09 Sep 2026 1. New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Source: Bleeping Computer An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...] 2. Google warns of new Chrome zero-day bug exploited in attacks Source: Bleeping Computer Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...] 3. Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days Source: The Hacker News Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office... 4. N-able N-central Pre-Auth RCE Flaw Exploited in the Wild Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes... 5. Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Source: Bleeping Computer A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...] 6. Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Source: Bleeping Computer Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...] 7. ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More Source: The Hacker News Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere,... 8. Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution Source: The Hacker News A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The... 9. Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours Source: The Hacker News Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours.... 10. Man gets 15 years for extorting women with AI-generated porn videos Source: Bleeping Computer An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]

  7. Sep 6

    Sep 06, 2026 · #60

    Episode 60 — 06 Sep 2026 1. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Source: The Hacker News Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec,... 2. Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Source: The Hacker News Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an... 3. Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials Source: The Hacker News JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should... 4. New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges Source: Bleeping Computer An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...] 5. Google warns of new Chrome zero-day flaw exploited in attacks Source: Bleeping Computer Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...] 6. Critical Citrix NetScaler auth bypass now leveraged in attacks Source: Bleeping Computer Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...] 7. IDScan sued over alleged data breach affecting 153 million drivers Source: Bleeping Computer Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...] 8. New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic Source: The Hacker News A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug...

  8. Sep 5

    Sep 05, 2026 · #59

    Episode 59 — 05 Sep 2026 1. Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities Source: The Hacker News Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 –... 2. Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws Source: The Hacker News Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super... 3. Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day Source: The Hacker News Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8,... 4. Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root Source: The Hacker News Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated... 5. Critical Citrix NetScaler auth bypass now leveraged in attacks Source: Bleeping Computer Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...] 6. New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges Source: Bleeping Computer An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...] 7. Google warns of new Chrome zero-day flaw exploited in attacks Source: Bleeping Computer Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...] 8. IDScan sued over alleged data breach affecting 153 million drivers Source: Bleeping Computer Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]

About

A daily AI-generated cybersecurity briefing. Fresh threat intelligence, vulnerability roundups, and infosec news — concise, clear, and delivered every day.