[MEDIUM] – CISA Releases Updated Insider Threat Mitigation Guide
CISA released an updated guide for organizations developing or improving insider-threat mitigation programs.
[MEDIUM] – InjectEave Research Demonstrates RF-Induced Device Eavesdropping
Researchers demonstrated RF-induced side channels recovering audio and appliance states on 11 commercial devices.
[CRITICAL] – CISA Adds ConnectWise ScreenConnect Flaw to KEV
CISA added a ConnectWise ScreenConnect authorization flaw enabling file transfer and execution in active sessions to its KEV catalog.
[CRITICAL] – WordPress Super Forms Flaw Under Active Exploitation
Attackers are exploiting an unauthenticated arbitrary-file-upload flaw in the WordPress Super Forms plugin.
[MEDIUM] – Conti Ransomware Conspirator Sentenced to Four Years in U.S.
The U.S. Justice Department says a Conti ransomware conspirator received a four-year prison sentence.
[MEDIUM] – Surfshark Discloses Breach of Misconfigured Internal Test Server
Surfshark says an unauthorized party accessed a misconfigured internal test server; customer data and VPN services were unaffected.
[HIGH] – Mantax Otax Android Malware Combines Ransomware and Spyware
Mantax Otax targets Android users with ransomware, data theft, credential harvesting, and device-control capabilities.
[HIGH] – Anthropic Details AI-Assisted Cyber Operations in New Threat Report
Anthropic reports disrupting AI misuse across cyber operations, surveillance, fraud, influence, weapons, and model distillation.
[CRITICAL] – GitLab Releases Critical Patch for CE and EE
GitLab released 19.3.2, 19.2.6, and 19.1.8 with critical security fixes for self-managed installations.
[HIGH] – BlueMoon Exploit Kit Chains Chrome and Windows Flaws in Espionage Campaigns
Proofpoint identified four espionage-focused groups using BlueMoon to chain Chrome and Windows vulnerabilities.
