
AI-Discovered Vulnerabilities Exploitation Accelerates
Five threat clusters exploited a critical remote code execution flaw in BeyondTrust products within a week of its disclosure, a vulnerability found

Five threat clusters exploited a critical remote code execution flaw in BeyondTrust products within a week of its disclosure, a vulnerability found

Two former US Air Force members stationed at Dover Air Force Base have been sentenced to a combined 189 months in prison for a business email compromise

Attackers are actively exploiting a critical Citrix NetScaler zero-day, CVE-2026-88772, to gain root access and deploy custom WHIPSHOT and SLAPSHOT malware

A DARPA-backed AI security startup, Xint, identified three critical vulnerabilities in Signal's Android app during a one-hour scan.

Microsoft has publicly detailed the NeedyMantis malware framework, discovered during analysis of the May 2026 Daemon Tools supply chain attack.

A New Mexico jury found Meta's Facebook liable for over 43 million violations of state consumer protection law, ruling it deceived users about data sharing

Two critical Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in zero-day attacks to deploy webshells

Bitget confirmed a $387.5 million crypto theft by suspected North Korean hackers, exploiting a backend wallet system.

Cloudflare fixed a cross-tenant data leakage flaw in its Containers service after a researcher demonstrated that residual data from other customers could

Two unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway appliances are under active exploitation, with no vendor patch or

CISA has published a 13-page Election Infrastructure Security Plan 40 days before the November 2026 midterms, offering guidance against cyber and physical

Actively exploited in the wild

Application Allowlisting · Application Whitelisting

Security control failure · Enterprise IT security and governance
Attacks on Managed Service Providers · MSPs and their clients

Australia · 18th century
Recall · CVE-2024-30051
Breach Notification Timelines By Country · 24 to 72 hours

Information security / Data protection · Organizations handling personal data

Kiteworks advised customers worldwide to shut down servers for a six-hour window on Saturday, September 26, based on credible threat intelligence from

The ShinyHunters extortion gang is exploiting the Oracle PeopleSoft CVE-2026-35273 zero-day using a percent-encoded URL to bypass web application

Zenity Labs disclosed three critical zero-click vulnerabilities in Salesforce Agentforce, collectively named SalesBleed, enabling silent data exfiltration

Senators Mark Warner and Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act, creating a voluntary framework for telecom

Researcher Rasmus Moorats chained two unpatched OnePlus software flaws to gain root access on an Android phone via a malicious app requiring no

Cofense has expanded its AI-driven Phishing Defense Platform with a new Competency Dashboard in its Command Center.
The vulnerability or campaign, and the patch or control that stops it, with an Asian regional focus. Vulnerabilities and Threats hold the offensive side as reported, Defence holds the mitigations, Regulation & compliance covers the legal duties, and Incidents follows breaches as they are disclosed.
No. Coverage is defensive: pieces describe what has been disclosed, what is affected and what the vendor or advisory recommends, without proof of concept code or step by step exploitation.
From vendor advisories, national cyber agencies, researchers and named publications, credited and linked in each piece. Severity ratings belong to whoever assigned them, and the vendor's own advisory is the version to patch against.
Only as far as the source says. Attribution and breach scope change repeatedly in the days after disclosure, and a piece reports who claimed what rather than settling it. Attacker claims are reported as claims.
Nobody is bylined. Pieces are written with automated assistance from the source material, and the advisory or publication behind them is credited in place of an author.
As the sources publish, which for a widely exploited flaw means several pieces in a day as details change. Anything you are acting on should be checked against the current advisory rather than the summary.