SOC manager brief
High-signal items — worth prioritizing for SOC triage and manager awareness.
Ranked using headline + RSS summary text (CVEs, incidents, vulns, ransomware, phishing, and related terms). Not a replacement for analyst judgment.
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek .
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Patching brief
CVEs, advisories, and patch-focused items from your current feed view — use for patch planning and change windows.
Heuristic filter on headline + RSS summary (CVE patterns, vuln/patch language). Verify severity and applicability in your environment.
CVE-2026-15981
CVE-2026-61979
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek .
CVE-2026-18963
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.
CVE-2026-21962
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek .
CVE-2026-19478
No feed summary available — open the article for context.
CVE-2026-19598
Custom Content Types and Fields (CVE-2026-19598)
CVE-2026-74480
No feed summary available — open the article for context.
CVE-2026-73570
CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
Feed snapshot
Time window
Last 24 hours
Since Mon Aug 24 · 17:21 · UTC
Stories in this view
37
Feeds configured
8
7 source(s) represented below
Time span (local)
17:38 – 16:23
By source
- The Hacker News14
- BleepingComputer12
- SecurityWeek10
- The Register: Security5
- NCSC Ireland4
- Dark Reading3
- Schneier on Security2
-
Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
SecurityWeek
16:23
-
You could've applied all 1,449 Oracle patches and still been hit by this attack
The Register: Security
16:09
-
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
BleepingComputer, The Hacker News
15:52
Links (2)
-
Is Cyber Facing an Affordability Crisis?
Dark Reading
14:53
-
Hospital operator Nutex Health says data stolen in cyberattack
BleepingComputer
14:44
-
Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails
SecurityWeek
14:11
-
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
The Hacker News
14:07
-
From Fake Workers to Account Recovery: The Growing Identity Verification Risk
BleepingComputer, Schneier on Security
14:01
Links (2)
-
Microsoft PowerToys adds Alt+Tab-style switching for an app's windows
BleepingComputer
13:51
-
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
SecurityWeek, The Hacker News
13:33
Links (2)
-
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
The Hacker News, BleepingComputer, SecurityWeek
13:19
Links (3)
-
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
SecurityWeek
12:57
-
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
The Hacker News
12:43
-
Hackers breached over 270 Zimbra servers in ongoing attacks
BleepingComputer
12:04
-
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
The Hacker News
11:56
-
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
The Hacker News, The Register: Security, BleepingComputer
11:52
Links (3)
-
First Malware Built Specifically for Car Head Units Fuels Botnet
SecurityWeek
11:18
-
Frontier AI: Vulnerability Management's Systemic Revolution
The Hacker News
11:14
-
Police arrests dozens of suspects in global cybercrime crackdown
BleepingComputer
10:53
-
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
The Register: Security
10:43
-
Silent Patches Don’t Stop Attackers – They Blind Defenders
SecurityWeek
10:00
-
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
SecurityWeek, Schneier on Security
08:30
Links (2)
-
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
SecurityWeek, The Hacker News
07:46
Links (2)
-
Critical Linux Kernel Network Bridge Vulnerability (CVE-2026-74480)
NCSC Ireland
00:00
-
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
NCSC Ireland, The Hacker News
00:00
Links (2)
-
Critical Vulnerability in GitLab CE/EE (CVE-2026-19478)
NCSC Ireland
00:00
-
Critical Vulnerability exists in Wordpress Plugin: Pods – Custom Content Types and Fields (CVE-2026-19598)
NCSC Ireland
00:00
-
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
Dark Reading
21:46
-
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
The Register: Security, The Hacker News
21:39
Links (2)
-
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
BleepingComputer
21:14
-
Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks
The Register: Security
21:07
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Dark Reading, The Hacker News
20:51
Links (2)
-
Hackers target WordPress sites in miniOrange auth bypass attacks
BleepingComputer
19:26
-
TikTok reaches $400M settlement with US over COPPA violations
BleepingComputer
17:56
-
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
The Hacker News
17:41
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
The Hacker News
17:41
-
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
SecurityWeek, BleepingComputer
17:38
Links (2)