Compiled from 52 monitored sources · 291 articles reviewed
Today’s Briefing
CISA added CVE-2025-62593 in Ray-Project Ray to the Known Exploited Vulnerabilities catalogue today, a code injection flaw allowing remote code execution against developers using Ray as a development tool through Firefox and Safari. Separately, a researcher has released ShieldBreak, a new technique that bypasses Microsoft's patch for an earlier Defender vulnerability and achieves SYSTEM privileges, and attackers are actively exploiting a macOS Screen Sharing vulnerability to gain root access and install Monero cryptominers. Cisco Talos disclosed a financially motivated campaign by UAT-11795 deploying the novel Starland RAT and a bespoke WLDR C2 implant.
Top Stories
- ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
- CISA Adds One Known Exploited Vulnerability to Catalog
- Update your Mac: Screen Sharing vulnerability exploited in the wild
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.