Cyber Signal
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
items report exploitation — not proof of concept
Attention classes are how much attention we gave an item. They are not severity verdicts.
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting…
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing…
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle…
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that…
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add…
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files,…
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle…
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard,…