Vulnerabilities
10 storiesMicrosoft Exchange Zero-Day Under Attack, No Patch Available
Active exploitation window opens for European enterprises using Exchange OWA while Microsoft develops emergency patch response.
Dark ReadingCVE-2026-428978.19/10Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Perfect CVSS 10.0 score on Cisco Secure Workload highlights critical data exposure risks in network segmentation solutions protecting European critical infrastructure.
THN (Feedburner)CVE-2026-2022310.09/10[NEU] [hoch] Splunk Splunk Enterprise: Mehrere Schwachstellen
SIEM platform vulnerabilities create blind spots in security monitoring infrastructure when logging systems become attack vectors themselves.
CERT-Bund (BSI)9/10[UPDATE] [hoch] Red Hat Advanced Cluster Management und Multicluster engine for Kubernetes: Schwachstelle ermöglicht Codeausführung oder DoS
Critical Red Hat Kubernetes management platforms face authenticated remote code execution risk, threatening container orchestration security across European hybrid cloud infrastructures under NIS2 scope.
CERT-Bund (BSI)9/10[UPDATE] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Mehrere Schwachstellen
Enterprise collaboration platforms face coordinated attack surface as Atlassian issues high-severity patches across its entire product portfolio simultaneously.
CERT-Bund (BSI)9/10[NEU] [hoch] Apache Airflow: Mehrere Schwachstellen
Apache Airflow vulnerabilities allow attackers to manipulate workflow files and expose sensitive data in enterprise data pipeline orchestration platforms.
CERT-Bund (BSI)9/10Ubiquiti patches three max severity UniFi OS vulnerabilities
Network infrastructure vendor critical flaws underscore supply chain risk in European SME environments heavily reliant on single-vendor networking solutions.
BleepingComputer9/10[NEU] [mittel] Microsoft Windows 11 und Windows Server 2025: Schwachstelle ermöglicht Umgehen der Laufwerksverschlüsselung
BitLocker bypass enables encrypted data access on compromised enterprise devices.
CERT-Bund (BSI)8/10[NEU] [mittel] IBM DB2: Mehrere Schwachstellen
Enterprise database platform IBM DB2 contains multiple flaws enabling information disclosure and service disruption across mission-critical business applications.
CERT-Bund (BSI)7/10Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
Japanese Learning Management Systems face active exploitation through deserialization flaws, highlighting risks for European subsidiaries and partnerships using similar educational technology platforms.
Google Threat Intel7/10
Security
8 stories[tl;dr sec] #329 - AI-powered Honeypots, GitHub Action Canaries, Microsoft’s Agentic Security Scanner
Microsoft launches autonomous security scanning while emerging AI honeypot technologies promise enhanced deception capabilities against sophisticated attackers.
tl;dr sec9/10GitHub Confirms Breach, 4K Internal Repos Stolen
The 4,000 stolen repositories from GitHub's internal systems highlight supply chain risks when development platforms themselves become breach targets.
Dark Reading9/10GitHub confirms breach of 3,800 repos via malicious VSCode extension
Hacker News (Security)9/10The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It.
Board-level discussions now center on AI-accelerated vulnerability discovery, requiring CISOs to articulate strategic responses that balance increased threat velocity with pragmatic resource allocation.
Recorded Future9/10GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos
TeamPCP's breach of 3,800+ GitHub internal repositories via employee device compromise exposes enterprise dependency risks on core development infrastructure platforms.
THN (Feedburner)9/10Investigating unauthorized access to GitHub-owned repositories
Platform hosting millions of repositories faces internal breach investigation, highlighting supply chain risks for enterprises dependent on external development infrastructure.
GitHub Security Blog9/10Trend Micro warns of Apex One zero-day exploited in the wild
Security vendor compromise highlights the meta-risk when endpoint protection platforms become attack vectors against their own customer base.
BleepingComputer9/10Drupal: Critical SQL injection flaw now targeted in attacks
Active exploitation of CMS injection vulnerability demonstrates the compressed timeline between disclosure and weaponization affecting European web properties.
BleepingComputer9/10
Threat Intel
6 storiesChina's Webworm Uses Discord, Microsoft Graphs to Hack EU Governments
Chinese APT Webworm's targeting of EU governments through legitimate cloud services demonstrates how threat actors weaponize trusted platforms for espionage.
Dark Reading9/10The New Phishing Click: How OAuth Consent Bypasses MFA
EvilTokens platform compromised 340 Microsoft 365 organizations using OAuth consent manipulation, bypassing traditional MFA protections through device registration flows.
THN (Feedburner)9/10FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks
Kali365 phishing service exploits OAuth token persistence to maintain Microsoft 365 access despite password changes and MFA implementations.
The Record9/10The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
Coordinated campaign compromises developer tools across GitHub, NPM, and VSCode ecosystems to establish persistent access in enterprise development pipelines.
Wiz Blog9/102 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services
Chinese-language phishing-as-a-service platforms are diversifying the global threat landscape, requiring updated detection rules for organizations with Asian market exposure or manufacturing partnerships.
Google Threat Intel8/10Canadian man arrested, charged for running KimWolf DDos botnet
KimWolf botnet arrest demonstrates international law enforcement coordination against DDoS-for-hire services affecting one million compromised devices globally.
The Record6/10
AI Security
3 storiesmacOS Kernel Memory Corruption Exploit
Adversaries now leverage frontier AI models for systematic vulnerability discovery and exploit development, fundamentally altering the threat landscape timeline for enterprise defenders.
Schneier on Security9/10RAG-Pull: Turning Retrieval into a Code-Injection Channel via Invisible Unicode Perturbations
Enterprise RAG implementations face a novel supply chain risk where malicious actors could inject invisible Unicode characters into knowledge bases to trigger code execution.
arXiv Crypto & Security9/10Why Policy in Amazon Bedrock AgentCore chose Cedar for securing agentic workflows
Policy framework addresses fundamental security challenge of non-deterministic AI agent behavior in enterprise automation workflows.
AWS Security Blog8/10
Regulatory
2 storiesLawmakers Demand Answers as CISA Tries to Contain Data Leak
Congressional scrutiny following the CISA data leak signals potential regulatory changes for federal contractor security requirements, particularly around cloud credential management and public repository oversight.
Krebs on Security8/10CISA to allow researchers to report vulnerabilities to exploited bugs catalog
CISA opens vulnerability nomination process for KEV catalog, enabling industry contribution to federal exploitation tracking and patch prioritization frameworks.
The Record8/10