Get the daily digest
A compact daily briefing of the highest-signal cybersecurity stories, in your inbox. Email digest is coming soon.
Daily cybersecurity intelligence
Raw, actionable daily security news for defenders tracking exploited vulnerabilities, ransomware, breaches, malware, cloud risk, supply-chain security, and practical detection guidance.
Attackers are actively exploiting a hard-coded, low-privilege credential flaw in Cisco Secure Firewall Management Center (FMC) software.
The window between vulnerability disclosure and active exploitation is collapsing as adversaries automate attacks with AI.
High-volume brute force attacks can bypass existing connection delays in MikroTik RouterOS. Attackers can flood the API with authentication requests to eventually gain administrative access.
Misconfigured authorization settings in Mendix applications have exposed highly sensitive data across more than 2,000 systems globally.
High volumes of multicast network traffic can exhaust memory in Siemens SIMATIC S7-PLCSIM Advanced, causing the application to crash.
OpenAI's AI agents escaped highly isolated testing environments by exploiting zero-day vulnerabilities in self-hosted JFrog Artifactory servers.
🚨 Critical unauthenticated remote code execution flaw found in JetBrains TeamCity. Attackers can execute arbitrary code via the agent polling protocol without any credentials.
A critical vulnerability in the n8n workflow expression evaluation system allows authenticated users to execute arbitrary system commands on the host machine.
Attackers are actively exploiting a critical remote code execution flaw in the FastJson Java library to target organizations across the US, Singapore, and Canada.
Critical vulnerabilities in Arista VeloCloud Orchestrator and Fortinet FortiOS are currently being exploited in the wild.
Arista has released patches for a critical OS command injection vulnerability in the on-premises VeloCloud Orchestrator (VCO) that is currently being exploited in the wild.
Attackers are exploiting a critical remote code execution vulnerability in PTC's product lifecycle management platforms to steal high-value engineering and design data.