Compiled from 52 monitored sources · 372 articles reviewed
Today’s Briefing
CISA added four vulnerabilities to the Known Exploited Vulnerabilities Catalog today: CVE-2026-33824 in Microsoft Internet Key Exchange Service Extensions, CVE-2026-59310 in Broadcom VMware vCenter, CVE-2026-55040 in Microsoft SharePoint, and CVE-2026-65400 in Apple macOS Screen Sharing. The macOS flaw allows network-based authentication bypass without valid credentials; the vCenter path traversal permits arbitrary code execution; the IKE double free enables remote code execution. Cisco Talos published research on UAT-11795, a financially motivated actor deploying a novel RAT named Starland and a bespoke C2 implant called WLDR.
Top Stories
- CISA Adds Four Known Exploited Vulnerabilities to Catalog
- CISA Malcolm
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.