Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
SAP released July 2026 security updates addressing a critical memory corruption flaw in NetWeaver ABAP. The vulnerability could allow data exposure or modification by authenticated attackers.
Multiple vulnerabilities in Wget affect various Ubuntu LTS versions, potentially allowing attackers to redirect connections, cause denial of service, or execute arbitrary code.
Microsoft released a record 622 security patches, including two zero-day flaws actively exploited in the wild. Organizations should prioritize applying these critical updates immediately.
Two critical zero-day flaws in SonicWall's Secure Mobile Access appliances are being actively exploited. One allows full admin command execution without authentication.
Attackers are using the same automated tools as defenders—but with malicious intent. Meanwhile, old vulnerabilities remain unpatched, creating persistent risks.
Ubuntu 24.04 LTS systems using PipeWire are vulnerable to denial-of-service attacks due to unbounded input handling flaws. Patches are available immediately.
Google and Microsoft removed ModHeader from their stores after researchers discovered a dormant browsing history collector. Although inactive, the finding raises serious privacy concerns for over 1.6 million users.
A new macOS malware named CrashStealer uses a notarized dropper to bypass Apple's Gatekeeper security. It steals sensitive data after validating the user's login password.
Attackers linked to ShinyHunters bypassed traditional exploits by leveraging pre-existing OAuth trust relationships. They accessed corporate Salesforce data without triggering platform vulnerabilities.
Attackers use voice-based social engineering to trick users into enrolling fake passkeys. This grants unauthorized access to Microsoft 365 accounts for data extortion.