Vulnerabilities
20 storiesVersion 1.2: Microsoft SharePoint - Massive Ausnutzung einer Zero-Day Schwachstelle
Microsoft SharePoint zero-day sees massive exploitation—BSI warns of widespread impact on enterprises.
BSI-IT-Sicherheitsmitteilungen (BITS)10/10axios was compromised on npm with ~100 million weekly downloads
r/malware10/10Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
Citrix NetScaler CVE-2026-3055 (CVSS 9.3) under active recon—patch immediately if you run ADC or Gateway.
The Hacker NewsCVE-2026-30559.810/10CVE-2026-21345: Critical RCE in widely-used Java XML parser (CVSS 9.8)
CVSS 9.8 RCE in Java XML parser — patch immediately, exploitation in the wild confirmed.
NVDCVE-2026-213457.810/10Version 1.1: Kritische Backdoor in XZ für Linux
BSI advisory on critical XZ Utils backdoor (CVE-2024-3094) — supply chain attack of the year.
BSI-IT-Sicherheitsmitteilungen (BITS)10/10Supply chain attack on popular npm package affects 14M weekly downloads
npm supply chain attack hits 14M downloads/week — env vars exfiltrated via compromised maintainer account.
GitHub Advisories9/10Version 1.3: Palo Alto Networks Firewalls - Aktive Ausnutzung einer ungepatchten Schwachstelle
BSI: Unpatched Palo Alto Networks firewall flaw actively exploited — perimeter defense at risk.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Version 1.0: Tausende Microsoft-Exchange-Server in Deutschland weiterhin für kritische Schwachstellen verwundbar
BSI: Thousands of German Exchange servers remain vulnerable to critical flaws — unacceptable exposure.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Version 1.4: Zero-Day Schwachstellen bei Cyber-Angriffen auf verschiedene Ivanti-Produkte genutzt
BSI: Multiple Ivanti zero-days actively exploited in cyber attacks — critical for VPN users.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Version 1.0: Microsoft Exchange - Aktive Ausnutzung einer Zero-Day-Schwachstelle
BSI warns of actively exploited zero-day in Microsoft Exchange — patch immediately.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
Critical Marimo RCE flaw (CVSS 9.3) exploited within 10 hours of disclosure — patch immediately.
THN (Feedburner)9/10Look What You Made Us Patch: 2025 Zero-Days in Review
Google tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025, lower than record highs observed
Mandiant Blog9/10From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day
UNC6201 exploits Dell RecoverPoint VM zero-day vulnerability, introducing BRICKSTORM to GRIMBOLT malware evolution
Mandiant BlogCVE-2026-2276910.09/10Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)
Multiple threat actors actively exploit critical React2Shell RCE vulnerability (CVE-2025-55182) in React components.
Mandiant BlogCVE-2025-5518210.09/10January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026: 23 critical CVEs actively exploited including APT28's Microsoft Office zero-day targeting enterprises.
Recorded Future9/10December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
December 2025: 120% surge to 22 critical CVEs with React2Shell dominating Meta framework threat activity.
Recorded FutureCVE-2025-5518210.09/10How SentinelOne’s AI EDR Autonomously Discovered and Stopped Anthropic’s Claude from Executing a Zero Day Supply Chain Attack, Globally
SentinelOne AI EDR stops zero-day supply chain attack targeting Anthropic's Claude globally
SentinelOne Blog9/10FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
FortiGate SSO vulnerabilities enable AD compromise via stolen service accounts and NTDS extraction
SentinelOne Blog9/10Version 1.1: Progress MOVEit - Ausnutzung einer kritischen Schwachstelle
BSI: Critical MOVEit vulnerability actively exploited — another file-transfer nightmare for CISOs.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10CISA adds Fortinet FortiManager flaw to KEV catalog
FortiManager auth bypass actively exploited — CISA adds to KEV, patch or isolate now.
CISACVE-2026-00425.58/10
Threat Intel
13 storiesRansomware knocks Dutch healthcare software vendor offline
r/cybersecurity9/10Ransomware group claims attack on German automotive supplier, leaks 2TB of data
Ransomware group attacks German automotive supplier, leaks 2TB including engineering drawings and employee records.
The Record9/10State-backed APT group targets EU telco operators with custom backdoor
State-backed APT deploys custom backdoor against EU telco operators, targeting lawful intercept systems.
BleepingComputer9/10Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
Citizen Lab exposes Webloc: ad-data surveillance tool tracking 500M devices, used by multiple governments.
THN (Feedburner)9/10UK says it exposed Russian submarine activity near undersea cables
UK exposes Russian submarine and GUGI activity near critical undersea cables—major European infrastructure threat.
The Record9/10North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
North Korean threat actor compromises widely-used Axios NPM package in major supply chain attack
Mandiant Blog9/10Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign
Google disrupts GRIDTIDE global espionage campaign by Chinese UNC2814 targeting telecoms and government
Mandiant Blog9/10GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use
Q4 2025 report shows threat actors integrating AI for reconnaissance, social engineering, and malware development
Mandiant Blog9/10UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering
North Korean UNC1069 leverages AI-enabled social engineering to target cryptocurrency sector with new tooling
Mandiant Blog9/10Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP launches multi-stage supply chain attacks on security infrastructure, partners with Vect ransomware.
Unit 42 (Palo Alto)9/10Preparing for Russia’s New Generation Warfare in Europe
Russia escalates New Generation Warfare against NATO with coordinated cyber attacks, sabotage, and influence operations.
Recorded Future9/10Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat Actors
Critical React2Shell vulnerability actively exploited by Chinese threat actors requires immediate patching.
Recorded FutureCVE-2025-5518210.09/10Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Single intrusion reveals operational connections between three major ransomware gangs
The DFIR Report9/10
Cloud
4 storiesCracks in the Bedrock: Agent God Mode
'Agent God Mode' in AWS Bedrock AgentCore grants excessive IAM permissions enabling privilege escalation.
Unit 42 (Palo Alto)9/10Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
Critical AWS Bedrock AgentCore sandbox escape enables DNS tunneling and credential exposure attacks.
Unit 42 (Palo Alto)9/10Wiz discovers cross-tenant data access via Azure Managed Identity misconfiguration
Wiz finds Azure Managed Identity cross-tenant data access — multi-tenant SaaS deployments at risk.
Wiz8/10AWS IAM Access Analyzer now supports custom policy validation rules
AWS IAM Access Analyzer adds custom policy rules — shift-left IAM governance gets practical.
AWS Security Blog7/10
DevSecOps
3 storiesVersion 1.0: Trivy - Supply-Chain Angriff führt zu Kompromittierungen in Deutschland
Trivy supply-chain attack leads to confirmed compromises in Germany—verify your CI/CD pipelines now.
BSI-IT-Sicherheitsmitteilungen (BITS)10/10Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
Axios npm supply chain attack injects cross-platform RAT via compromised account—check your dependencies now.
The Hacker News10/10CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads
CPUID supply chain attack: hackers hijacked API to serve malware via official CPU-Z and HWMonitor downloads.
BleepingComputer9/10
AI Security
3 storiesAI voice cloning used in $4.3M CEO fraud scheme targeting European banks
AI voice cloning enables $4.3M CEO fraud targeting European banks through sophisticated deepfake impersonation.
Krebs on Security10/10Claude Code Audit: Confirmed RCE via Environment Variable Injection
r/netsec9/10Schneier: On the growing problem of AI-generated fake CVEs
Bruce Schneier warns of AI-generated fake CVEs flooding vulnerability databases, undermining ecosystem trust.
Schneier on Security8/10
Tools
3 storiesNuclei v4.0 released with AI-assisted template generation
Nuclei v4.0 ships with AI template generation and DAST-like active scanning — game changer for pentesters.
GitHub8/10Semgrep Supply Chain adds reachability analysis for transitive dependencies
Semgrep adds reachability analysis for transitive deps — finally cuts SCA noise to signal.
Semgrep7/10TruffleHog 3.70: scanning container images and Terraform state files
TruffleHog now scans container images and Terraform state for secrets — DevSecOps pipeline essential.
GitHub7/10
Regulatory
2 storiesEU Commission requests harmonised standards for the Cyber Resilience Act
CRA harmonised standards requested — CEN/CENELEC to deliver first drafts by Q3 2026.
EU Commission9/10DORA RTS on ICT risk management framework enters into force
DORA's ICT risk management RTS is now law — financial entities must comply or face supervisory action.
EUR-Lex9/10
Research
2 storiesBreaking post-quantum lattice schemes with hybrid quantum-classical attacks
Hybrid attack reduces CRYSTALS-Kyber security margin by 15% — NIST PQC parameters under scrutiny.
arXiv8/10Project Zero: Systematic analysis of LLM jailbreak techniques and mitigations
Project Zero maps 47 LLM jailbreak categories with success rates — essential reading for AI security teams.
Project Zero8/10