Authorities and security firms report a state-sponsored campaign that compromised trusted South Korean websites. The attackers abused AnySign4PC vulnerabilities so visitors could be infected without downloads or prompts.
A researcher described how hidden instructions in Word files can be copied into Microsoft 365 Copilot drafts and alter document content. The issue requires a Copilot editing or drafting step rather than malware execution.
JetBrains warns that CVE-2026-63077 can allow authentication bypass and lead to TeamCity remote code execution on TeamCity On-Premises. Cloud customers don’t need action, but administrators should patch quickly.
This ThreatsDay roundup shows how AI-based abuse and social engineering increasingly pair with real intrusion paths. From Chrome weaknesses to DNS hijacking and credential stuffing—here are the key takeaways.
Horizon3 AI-hacking secures a $250M Series E and tripled its valuation in 14 months. The company develops NodeZero to continuously and controlledly stress-test networks.
Brinks Home says hackers accessed part of its IT systems and may expose information. The company reports alarm monitoring remains unaffected and advises customers to stay alert.
AI platforms in the SOC can boost productivity, but they aren’t built to investigate every alert 24/7. A layered approach turns AI FOMO into better security outcomes.
Two newly reported SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) have been exploited in ransomware incidents. Security teams urge rapid patching and active threat hunting.
New details suggest the US water cyberattacks extend well beyond Minnesota, with other states confirming malicious activity. Authorities also emphasize protections for OT systems.