π¨ ACTIVE EXPLOITS & INCIDENTS
- Nissan Employee Data Breached in Oracle PeopleSoft Hack β SecurityWeek A targeted campaign exploiting Oracle PeopleSoft vulnerabilities has compromised employee data at Nissan, one of over 100 affected organizations. This ongoing supply chain-style breach highlights the critical risk to enterprises using PeopleSoft ERP systems.
- Blackfield Ransomware Demands $2M from Nidec Corporation β BleepingComputer The Blackfield ransomware gang has targeted Nidec Corporation, a major Japanese electronics manufacturer, demanding a $2 million ransom. This attack underscores continued ransomware focus on industrial and manufacturing sectors.
π VULNERABILITIES & CVEs
- Critical Progress Kemp LoadMaster Flaw Allows Pre-Auth Root Command Execution (CVE-2026-8037, CVSS 9.8) β The Hacker News An unauthenticated attacker can execute arbitrary root commands via the LoadMaster API. Immediate patching is essential for all users with API enabled to prevent full appliance compromise.
- Oracle E-Business Suite CVE-2026-46817 Actively Exploited in the Wild (CVSS 9.8) β The Hacker News A critical privilege management/authentication flaw in Oracle Payments is under active exploitation. This vulnerability allows attackers to take over vulnerable instances, demanding urgent patch application.
- Critical SimpleHelp Vulnerability Exploited for Credential Theft and Malware Delivery β SecurityWeek Attackers are exploiting a SimpleHelp flaw to harvest credentials, SSH keys, crypto wallets, and dev tooling. Organizations using SimpleHelp should apply mitigations or patches immediately.
- Windows BlueHammer Privilege Escalation Exploited by Ransomware Groups β BleepingComputer CISA confirms active exploitation of the Microsoft Defender privilege escalation vulnerability dubbed BlueHammer. Ransomware operators are leveraging this zero-day in ongoing campaigns; patching and detection tuning are critical.
- Apple Patches 30+ iOS/macOS/Safari Flaws Including AI-Discovered WebKit Bugs β The Hacker News Apple released updates fixing over 30 vulnerabilities, including four WebKit memory corruption bugs found via AI tools (e.g., Anthropic Claude, OpenAI Codex). Immediate updates recommended for iOS, macOS, and Safari users.
- New Remote Hacking Flaws in Daktronics Highway Sign Controllers β SecurityWeek Three vulnerabilities in Daktronics controllers could allow remote attackers to manipulate highway signs and billboards. Organizations managing such infrastructure should review CISA advisories and apply mitigations.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- BioShocking Attack Tricks AI Browsers into Leaking User Credentials β The Hacker News LayerX researchers demonstrated βBioShocking,β a novel attack that convinces AI browsers (including ChatGPT Atlas, Perplexity Comet, Anthropic Claude) to disclose user credentials by framing interactions as games. This exposes a new attack surface in AI-assisted browsing.
π PRODUCT LAUNCHES & UPDATES
- Kali Linux 2026.2 Released with 9 New Tools and NetHunter Improvements β BleepingComputer The latest Kali Linux release adds nine new pentesting tools and updates to Kali NetHunter, enhancing mobile and embedded device testing capabilities. Security teams should evaluate new tools for integration into red team operations.
πΌ INDUSTRY NEWS, M&A & DEALS
- Quantifind Raises $200M to Expand AI-Native Risk Intelligence Platform β SecurityWeek Quantifind secured $200 million to accelerate global expansion and enhance localized AI-driven risk intelligence. This funding signals growing investment in AI-powered security analytics and threat intelligence.