CISA Warns: Hackers Are Actively Exploiting VMware vCenter
A widely used VMware vCenter Server flaw is now confirmed under real-world attack, raising immediate risk for government and enterprise environments.
Source: CISA
Read more: CyberSecBrief

seen from United States
seen from United States
seen from China
seen from France
seen from Türkiye
seen from Russia

seen from Germany
seen from Türkiye
seen from United States
seen from France

seen from United States
seen from China

seen from Türkiye

seen from United States
seen from Saudi Arabia
seen from Romania
seen from Sweden
seen from Russia
seen from Iraq
seen from China
CISA Warns: Hackers Are Actively Exploiting VMware vCenter
A widely used VMware vCenter Server flaw is now confirmed under real-world attack, raising immediate risk for government and enterprise environments.
Source: CISA
Read more: CyberSecBrief
SmarterMail Servers Exposed to Silent Takeover
A critical SmarterMail flaw allows unauthenticated attackers to execute remote commands by abusing the ConnectToHub API.
Source: VulnCheck
Read more: CyberSecBrief
AI Agents Raise New Insider Threat Concerns
Security leaders warn that fast-growing AI agents inside organisations could be misused like trusted insiders, with broad access creating fresh opportunities for abuse.
Source: The Register
Read more: CyberSecBrief
Spyware Firms Now Out-Exploit Nation-States — Google's 2025 Zero-Day Report Is Out
Google tracked 90 zero-days exploited in 2025, and for the first time ever, commercial surveillance vendors were responsible for more attributed zero-day attacks than traditional state-sponsored espionage groups.
Source: Google Threat Intelligence Group
Read more: CyberSecBrief
Ivanti Endpoint Manager Flaws Patched
Ivanti released patches for Endpoint Manager vulnerabilities including a high-severity authentication bypass and SQL injection, closing loopholes for credential theft and database compromise.
Source: SecurityWeek
Read more: CyberSecBrief
Fortinet Fixes SQL Injection Flaw Allowing Unauthenticated Command Execution
A critical FortiClientEMS vulnerability enabled remote attackers to execute commands through the web interface before patches resolved the exposure.
Source: Arctic Wolf
Read more: CyberSecBrief
SolarWinds Fixes Critical Help Desk Bugs
SolarWinds patched serious Web Help Desk flaws that could have enabled unauthorised access and remote command execution.
Source: Arctic Wolf
Read more: CyberSecBrief