LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
nation-state

Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through […]

zeroday.news ·

CenterPoint Energy, a Texas-based utility provider, has confirmed a data breach following claims by a hacker that they had stolen 7.49 million customer records. The company acknowledged that an unauthorized intruder accessed customer information.

Separately, the cloud photo and GIF sharing service Gyazo announced a data breach affecting 23 million user records. Details regarding the nature of the compromised data or the timeline of the incident were not immediately available.

In another incident, Revolut, a financial technology company, experienced a data leak. Initial investigations suggest this breach may be linked to compromised Italian government accounts, though Revolut has not confirmed this connection.

Further cybersecurity concerns emerged with a critical vulnerability identified in Check Point VPN products, which is reportedly under active exploitation. Users are urged to update their systems promptly to address these flaws. The U.S. CISA has also added several critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Acronis Backup, Cisco ISE, Google Pixel, Cisco Secure Email Gateway, GitLab, JFrog Artifactory, and ConnectWise ScreenConnect.

Cisco specifically warned of ongoing exploitation of a critical zero-day vulnerability in its Secure Email Gateway. Additionally, a non-zero-day VPN flaw exposed Japan's government shared network platform, potentially compromising 246,000 personnel records.

A significant supply-chain attack targeting Brevo, a marketing automation platform, reportedly infected over 100,000 websites. This incident highlights the widespread impact that a single compromise within a software supply chain can have.

In other news, Google patched a zero-day vulnerability in Pixel modems that was exploited in targeted attacks. A bug in LiteSpeed Enterprise, used in shared hosting environments, was also found to potentially grant root access from a single tenant, posing a significant risk to hosted websites.

An exploit chain targeting both Chrome and Windows has been linked to two distinct espionage campaigns, indicating sophisticated threat actor activity. A flaw in Telegram Desktop could also turn old chat exports into data theft traps, while a malicious Twitch browser extension exposed 30,000 users' OAuth tokens to a Russian bot service.

Law enforcement agencies have taken action against cybercrime, with the FBI seizing several domains associated with DDoS-for-hire services as part of a crackdown on "booter" and "stresser" operations. This effort led to the takedown of NightmareStresser, a prominent DDoS-for-hire platform. Furthermore, a Conti hacker involved in malware development and victim attacks received a four-year prison sentence.

nation-stateai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]