TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

12 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
·Thu
12Fri
12Sat
4Sun
1Mon
12Tue
12Wed
IN THE WILD
4/ 12

items report exploitation — not proof of concept

ATTENTION
5 7
CATEGORIES
patch-or-mitigation7
CVE5
crime5
AI/agent3
cloud/AI-stack2
exploited2
SOURCES
BleepingComputer4
The Hacker News4
CISA Advisories3
SecurityWeek1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🎯CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Advisories · exploited · CVE

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active…

🎯CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The Hacker News · exploited · CVE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting…

🪪New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

The Hacker News · CVE · identity

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing…

📦Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

The Hacker News · AI/agent · supply-chain

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that…

🩹Acrisure KARR BT and DR-100

CISA Advisories · CVE · crime

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle…

💧TP-Link patches Omada ZTP flaws allowing hackers to breach networks

BleepingComputer · crime · code-execution

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that…

🤖OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

BleepingComputer · AI/agent · cloud/AI-stack

OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party…

🔑Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Hacker News · crime · identity

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add…

🤖Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

SecurityWeek · AI/agent · cloud/AI-stack

A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent.

🧬Thermo Fisher Applied Biosystems Genetic Analyzers

CISA Advisories · CVE · patch-or-mitigation

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files,…

🎣Phishing service spoofs RingCentral to steal Microsoft 365 accounts

BleepingComputer · crime · msft/identity

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle…

📡Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

BleepingComputer · crime · msft/identity

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard,…