The day’s global security activity, graded and distilled into a single brief.
14 items from the 36-hour window: a KEV-listed Gitea code injection flaw under active exploitation, a weaponized SharePoint RCE chain, and Trail of Bits research showing an AI agent autonomously finding 0-days to escape a VM sandbox.
Three KEV-listed flaws under active exploitation (Gitea, Oracle WebLogic, Zimbra), a cluster of critical MCP/agent-framework CVEs, and a heavy day for healthcare and government breach disclosures.
Today: Oracle WebLogic and Zimbra both hit CISA's KEV catalog; a miniOrange WordPress plugin is under active exploitation; a cluster of 9.0+ CVSS bugs in LXD, Netis, DrayTek, rConfig, and phpIPAM; RansomLook itself discloses three authorization flaws; plus a prompt-injection risk in NVIDIA NemoClaw.
CISA issues an emergency directive for an actively exploited Zimbra flaw; critical bugs surface in Joomla, LXD, StackGres, Keycloak and Zscaler; ShinyHunters and suspected North Korea-linked actors are active in supply-chain and data-theft incidents.
Today's picks: batch critical disclosures in NLTK and Joomla Fabrik, CVSS 9.8 flaws in WS Form LITE and Mailgun for WordPress, MCP-tool secret leakage in SiYuan, plus Android malware and TikTok's child-privacy settlement.
Scanned 9 sources and 321 raw items, selected 21: Zimbra/GitLab/SPIP/TrueConf under active exploitation, plus Cisco/Azure SQL/Incus/FreeRTOS critical CVEs (CVSS 9+), AI security flaws (Headroom, Omnigent), and malware intel.
Scanned 33 sources, 401 raw items; selected 33. Three CVE pairs (TrueConf, MLflow, Windows IKE) newly added to CISA KEV this week with active exploitation; Entra ID, Zimbra and GitLab flaws reported exploited but not yet KEV-listed; plus 12 curated CVSS≥8 vulnerabilities (FreeIPA, IBM AIX, n8n and more) and a Rust supply-chain compromise.
Scanned ~360 items from 11 active sources, selected 16: CISA added five actively-exploited flaws in a single day (MLflow SSRF, Windows IKE, SharePoint, vCenter, macOS); a Zimbra SNMP RCE is confirmed exploited in the wild by CERT Polska; Citrix NetScaler auth-bypass, Elementor Pro, and two CVSS-10 Joomla extension bugs demand urgent patching.
Scanned 33 sources, 380 new items in the 36-hour window, 22 selected: CISA's four-vulnerability KEV batch, active exploitation of Ray/MLflow/FUXA, an AI-generated-script campaign against Siemens S7 PLCs, and a critical Firefox/Thunderbird 154 security release.
Scanned 12 sources, 373 raw items, selected 15: a perfect-10.0 Joomla RCE exploited within 3 days of patching, plus active exploitation of Ray, GitLab, and VMware vCenter.
Scanned 33 sources / 304 raw items, selected 18: one new KEV addition, a suspected China-nexus APT deploying ransomware via a VMware vCenter flaw, and a batch of 15 critical CVSS-9.3 CVEs in the openssl_encrypt PyPI package.
Today: Evooo1Bot router botnet, AmnesiaStealer macOS infostealer; no high-priority CVE/KEV hits today.
Scanned 259 raw items in 36h, selected 18: two CVSS-10 unauthenticated RCEs (MindsDB, Haiwell IoT), three high-severity CVE clusters (Grav, IBM Db2 Mirror, Tenable Security Center), active exploitation of SAP Commerce Cloud and a macOS Screen Sharing flaw, and a 1.6M-account RingCentral breach.
33 sources scanned, 20 items selected: PostgreSQL/Flowise critical vuln clusters, 5 actively-exploited flaws (SharePoint, SAP Commerce Cloud, VMware vCenter among them), CISA's 15-advisory ICS release, and breaches at Shell, RingCentral and Trezor.
19 items selected: Cisco ASA/FTD and a Windows AFD zero-day both hit CISA's KEV list under active exploitation; SharePoint and VMware vCenter flaws were exploited right after PoC release. On the AI-security side, a cross-vendor reasoning-API leak, the SpatialJB jailbreak, and VIPER-MCP's 106 MCP zero-days stand out.
Patch Tuesday collides with an NVD critical-CVE surge: SAP, Adobe ColdFusion, SIMULIA, and Siemens IoT2050 all hit CVSS 10.0; a Windows AFD zero-day exploited by Lazarus lands on CISA's KEV list, alongside fresh in-the-wild exploitation reports for VMware vCenter and SharePoint.
Scanned 9 sources, 746 raw items (36h window), selected 30: 8 high/critical CVEs (incl. a CVSS 10.0 Joomla Fabrik RCE), 3 actively-exploited KEV entries (incl. SharePoint now hit by ransomware crews), 4 AI-security items.
Scanned 33 sources, selected 20 items from 379 raw records: five CVSS≥9.0 critical flaws, two CISA-KEV vulnerability sets already exploited by ransomware gangs, and North Korea's Kimsuky building an offline AI stack for phishing and malware development.
Scanned 33 sources, 209 items collected in the last 36 hours, 15 selected: 4 critical vulnerabilities, 3 actively exploited/KEV, 5 vendor advisories, 1 web security research finding, 1 AI security item, 1 other.
Generated automatically · 30 sources scanned · 22 items selected
Generated automatically · 24 sources scanned · 16 items selected · window: past 24h
Generated automatically · 30 sources scanned · 27 items selected · window: past ~24–48h
Generated automatically · 30 sources configured · 22 items selected
Generated automatically · ~29 sources scanned · 16 items selected
Generated automatically · ~29 sources scanned · 18 items selected
Generated automatically · ~20 sources scanned · 18 items selected
Generated automatically · 20 sources scanned · 28 items selected
Generated automatically · 20+ sources scanned · 17 items selected
Generated automatically · 20+ sources scanned · 16 items selected
Generated automatically · ~14 sources scanned (via WebSearch) · 18 items selected