Latest from the feed

Content is curated from many trusted industry sources, including vendor advisories, security blogs, bug bounty programs, and conference organizers worldwide.

  • Apple CoreGraphics PoC Emerges; WhatsApp PDF Checks Hint

    Security researchers released the first public proof-of-concept for CVE-2026-86950, a CoreGraphics flaw Apple says may have been used against targeted individuals. A malicious PDF with a crafted embedded font crashes unpatched iPhones and Macs by triggering memory corruption, not code execution. This underscores the urgency of patching now.

    Source: The Hacker News

  • Zimbra flaw lets attackers breach mail servers without login

    Cyber attackers exploit a critical Zimbra Collaboration Suite (ZCS) flaw to breach email servers, deploy web shells and reverse shells, and maintain persistent access while attempting to steal sensitive email and authentication data. Researchers note stolen information is often archived on compromised hosts for later exfiltration. This risk is clear.!!

    Source: The 420

  • India’s Top Cyber Crime Stories: What You Must Know

    A CPT‑Algoritha Security briefing highlights 10 top cybercrime, cybersecurity, DFIR, AI, BFSI‑fraud, policing and national‑security developments. Notably, the Union Cabinet approved a ₹1,789.52‑crore AI‑powered Intelligent Traffic Management System for Delhi Police, signaling AI and security integration for policing in India.

    Source: The 420

  • Bitget: Third-Party Zero-Day Behind $387.5M Crypto Theft

    Bitget confirmed attackers stole $387.5 million last week by exploiting a zero-day flaw in third-party security products, per SlowMist's ongoing investigation. The probe links malicious activity to third-party security tools, identifies a zero-day vulnerability, and notes a customized tool recovered from the attacker. This flags third-party risk now

    Source: The Hacker News

  • Police Tech Launches 31-Day Cybersecurity Awareness 2026

    The Centre for Police Technology (CPT) launches a 31‑day knowledge initiative for Cybersecurity Awareness Month 2026, spotlighting AI-powered security, computer forensics, tech law, cybercrime investigations, and emerging digital threats. The October program in India involves CERT‑In to raise awareness and bolster readiness against evolving cyber threats.

    Source: The 420

  • Citrix NetScaler Exploit Drops Web Shell, Elevates Privilege

    Threat actors are exploiting a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway to deploy web shells and exfiltrate configuration data. LevelBlue THOR analyzed activity across multiple customer environments, noting malicious NetScaler instances targeted during these intrusions.

    Source: The Hacker News

  • Agentic AI Unleashed: Security Must Think Ahead Now

    Centre for Police Technology launches a 31-day Cybersecurity Knowledge Series for police, LEAs, corporate investigators, DF, fraud and security pros, aligning with Cybersecurity Awareness Month. The series probes technologies reshaping cyber defence and crime, beginning with Day 1: Agentic AI Security demanding proactive thinking. More details soon.

    Source: The 420

  • 543,000+ Valid Credentials Exposed in Public GitHub Repos

    A study found over 543,000 unique credentials remained valid in public GitHub repositories as of July 2026, underscoring persistent exposure of sensitive access data despite safeguards. The median public exposure lasted 784 days, illustrating long-term risk of credential leakage and potential misuse across projects and organizations.

    Source: The 420

  • MetaMask Incident Forces Some Ethereum Validators to Exit

    MetaMask reported an ongoing security incident impacting part of its infrastructure and said it is actively addressing and remediating the issue in coordination with external partners and security advisors. The company emphasized that it has identified no immediate threat to MetaMask wallets at this time. MetaMask will provide updates. Stay tuned!!

    Source: The Hacker News

  • OpenAI Flags Moonshot AI for Coordinated Model Distillation

    OpenAI disrupted a coordinated campaign by Moonshot AI, a Chinese firm behind the Kimi model, that used thousands of accounts to extract training data and hidden reasoning from OpenAI models. The activity, detected in July, prompted security investigations and mitigations.

    Source: Data Breach Today

  • OpenAI flags novel encryption bypass in distillation attack

    OpenAI attributed elements of the attack to individuals linked to Chinese firm MoonshotAI, yet offered no conclusive evidence. The CyberScoop report notes a purported novel encryption bypass used in a distillation attack, with the story first published there. The attribution remains unproven and disputed.

    Source: CyberScoop

  • Hackers Use Custom GPTs to Deliver RATs via Trusted Domains

    Threat actors conduct a ClickFix-style campaign that abuses legitimate OpenAI and Google domains to deceive users, leveraging trusted brands to host phishing pages, deliver malware, or harvest credentials, exploiting domain reputation to boost clicks and circumvent skepticism. This pattern exploits trust to drive traffic to fake pages and steal data

    Source: Dark Reading

Real-time threat intelligence392 signals

Latest Intelligence

Apple CoreGraphics PoC Emerges; WhatsApp PDF Checks Hint
News

Apple CoreGraphics PoC Emerges; WhatsApp PDF Checks Hint

Security researchers released the first public proof-of-concept for CVE-2026-86950, a CoreGraphics flaw Apple says may have been used against targeted individuals. A malicious PDF with a crafted embedded font crashes unpatched iPhones and Macs by triggering memory corruption, not code execution. This underscores the urgency of patching now.

News

Zimbra flaw lets attackers breach mail servers without login

Cyber attackers exploit a critical Zimbra Collaboration Suite (ZCS) flaw to breach email servers, deploy web shells and reverse shells, and maintain persistent access while attempting to steal sensitive email and authentication data. Researchers note stolen information is often archived on compromised hosts for later exfiltration. This risk is clear.!!

News

India’s Top Cyber Crime Stories: What You Must Know

A CPT‑Algoritha Security briefing highlights 10 top cybercrime, cybersecurity, DFIR, AI, BFSI‑fraud, policing and national‑security developments. Notably, the Union Cabinet approved a ₹1,789.52‑crore AI‑powered Intelligent Traffic Management System for Delhi Police, signaling AI and security integration for policing in India.

Bitget: Third-Party Zero-Day Behind $387.5M Crypto Theft
News

Bitget: Third-Party Zero-Day Behind $387.5M Crypto Theft

Bitget confirmed attackers stole $387.5 million last week by exploiting a zero-day flaw in third-party security products, per SlowMist's ongoing investigation. The probe links malicious activity to third-party security tools, identifies a zero-day vulnerability, and notes a customized tool recovered from the attacker. This flags third-party risk now

News

Police Tech Launches 31-Day Cybersecurity Awareness 2026

The Centre for Police Technology (CPT) launches a 31‑day knowledge initiative for Cybersecurity Awareness Month 2026, spotlighting AI-powered security, computer forensics, tech law, cybercrime investigations, and emerging digital threats. The October program in India involves CERT‑In to raise awareness and bolster readiness against evolving cyber threats.

Citrix NetScaler Exploit Drops Web Shell, Elevates Privilege
News

Citrix NetScaler Exploit Drops Web Shell, Elevates Privilege

Threat actors are exploiting a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway to deploy web shells and exfiltrate configuration data. LevelBlue THOR analyzed activity across multiple customer environments, noting malicious NetScaler instances targeted during these intrusions.

News

Agentic AI Unleashed: Security Must Think Ahead Now

Centre for Police Technology launches a 31-day Cybersecurity Knowledge Series for police, LEAs, corporate investigators, DF, fraud and security pros, aligning with Cybersecurity Awareness Month. The series probes technologies reshaping cyber defence and crime, beginning with Day 1: Agentic AI Security demanding proactive thinking. More details soon.

News

543,000+ Valid Credentials Exposed in Public GitHub Repos

A study found over 543,000 unique credentials remained valid in public GitHub repositories as of July 2026, underscoring persistent exposure of sensitive access data despite safeguards. The median public exposure lasted 784 days, illustrating long-term risk of credential leakage and potential misuse across projects and organizations.

MetaMask Incident Forces Some Ethereum Validators to Exit
News

MetaMask Incident Forces Some Ethereum Validators to Exit

MetaMask reported an ongoing security incident impacting part of its infrastructure and said it is actively addressing and remediating the issue in coordination with external partners and security advisors. The company emphasized that it has identified no immediate threat to MetaMask wallets at this time. MetaMask will provide updates. Stay tuned!!

OpenAI Flags Moonshot AI for Coordinated Model Distillation
News

OpenAI Flags Moonshot AI for Coordinated Model Distillation

OpenAI disrupted a coordinated campaign by Moonshot AI, a Chinese firm behind the Kimi model, that used thousands of accounts to extract training data and hidden reasoning from OpenAI models. The activity, detected in July, prompted security investigations and mitigations.

OpenAI flags novel encryption bypass in distillation attack
News

OpenAI flags novel encryption bypass in distillation attack

OpenAI attributed elements of the attack to individuals linked to Chinese firm MoonshotAI, yet offered no conclusive evidence. The CyberScoop report notes a purported novel encryption bypass used in a distillation attack, with the story first published there. The attribution remains unproven and disputed.

Hackers Use Custom GPTs to Deliver RATs via Trusted Domains
News

Hackers Use Custom GPTs to Deliver RATs via Trusted Domains

Threat actors conduct a ClickFix-style campaign that abuses legitimate OpenAI and Google domains to deceive users, leveraging trusted brands to host phishing pages, deliver malware, or harvest credentials, exploiting domain reputation to boost clicks and circumvent skepticism. This pattern exploits trust to drive traffic to fake pages and steal data

Download Secwiser App