CISA Warns: Hackers Are Actively Exploiting VMware vCenter
A widely used VMware vCenter Server flaw is now confirmed under real-world attack, raising immediate risk for government and enterprise environments.
Source: CISA
Read more: CyberSecBrief

seen from Germany
seen from China
seen from Kenya
seen from Germany

seen from Spain

seen from United Kingdom
seen from Japan
seen from United States
seen from United States
seen from China

seen from United Kingdom
seen from United States
seen from China

seen from United States
seen from Singapore
seen from United Kingdom
seen from United States
seen from China
seen from Türkiye

seen from Pakistan
CISA Warns: Hackers Are Actively Exploiting VMware vCenter
A widely used VMware vCenter Server flaw is now confirmed under real-world attack, raising immediate risk for government and enterprise environments.
Source: CISA
Read more: CyberSecBrief
SmarterMail Servers Exposed to Silent Takeover
A critical SmarterMail flaw allows unauthenticated attackers to execute remote commands by abusing the ConnectToHub API.
Source: VulnCheck
Read more: CyberSecBrief
AI Agents Raise New Insider Threat Concerns
Security leaders warn that fast-growing AI agents inside organisations could be misused like trusted insiders, with broad access creating fresh opportunities for abuse.
Source: The Register
Read more: CyberSecBrief
Spyware Firms Now Out-Exploit Nation-States — Google's 2025 Zero-Day Report Is Out
Google tracked 90 zero-days exploited in 2025, and for the first time ever, commercial surveillance vendors were responsible for more attributed zero-day attacks than traditional state-sponsored espionage groups.
Source: Google Threat Intelligence Group
Read more: CyberSecBrief
Ivanti Endpoint Manager Flaws Patched
Ivanti released patches for Endpoint Manager vulnerabilities including a high-severity authentication bypass and SQL injection, closing loopholes for credential theft and database compromise.
Source: SecurityWeek
Read more: CyberSecBrief
Fortinet Fixes SQL Injection Flaw Allowing Unauthenticated Command Execution
A critical FortiClientEMS vulnerability enabled remote attackers to execute commands through the web interface before patches resolved the exposure.
Source: Arctic Wolf
Read more: CyberSecBrief
SolarWinds Fixes Critical Help Desk Bugs
SolarWinds patched serious Web Help Desk flaws that could have enabled unauthorised access and remote command execution.
Source: Arctic Wolf
Read more: CyberSecBrief