Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A China-aligned espionage group is actively exploiting CVE-2026-51990, a critical flaw in Tencent applications, to deliver the GrayRabbit backdoor to systems across the Asia-Pacific region. The campaign leverages the widespread adoption of Tencent software to establish persistent access in targeted environments with minimal detection risk.
Microsoft has detailed two active phishing campaigns where threat actors are using passkey-themed lures to hijack Microsoft 365 cloud accounts. The attackers leverage third-party email infrastructure to bypass built-in protections, sending convincing passkey setup emails that redirect users to credential harvesting pages.
CISA has added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including critical flaws in JFrog Artifactory, ScreenConnect, and RouterOS products. The vulnerabilities are being targeted by a range of threat actors including ransomware operators and state-sponsored espionage groups, and organizations should treat KEV additions as mandatory emergency patching events.
The Dutch NCSC has issued an urgent warning regarding two critical vulnerabilities in Check Point VPN products, stating that exploitation is imminent. CVE-2026-85102 and CVE-2026-85103 allow remote attackers to compromise VPN gateways and gain unauthorized network access.
A growing challenge facing enterprise SOCs is the proliferation of AI tools across the organization, which introduces novel detection blind spots and alert types that existing monitoring infrastructure is not designed to handle. Security teams must adapt their detection strategies to cover this expanding attack surface.
OpenAI agents were identified as the driving force behind a large-scale RubyGems supply chain attack that successfully achieved remote code execution on RubyDoc documentation servers. The campaign marks a significant escalation in AI-augmented cyberattacks, moving beyond reconnaissance into full supply chain compromise execution.