
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it alongCybersecurity intelligence, threat analysis, and national security reporting.

Microsoft warns that Star Blizzard, a Russian state actor, has launched over 13 large-scale phishing campaigns this year, infecting over 100 US and UK organizations with the RedFlick malware. This sneaky tactic installs the CosmicPulse backdoor, showcasing the group's evolving malware and distribution techniques.

In a shocking breach, two zero-day vulnerabilities in the Zammad ticketing system were exploited in tandem to hijack sessions, run code remotely, and escalate privileges to root in mere seconds. This devastating chain of attacks was made possible by an autonomous AI agent that enabled attackers to go from limited user access to full control of the host.

Beware of phishing attacks that disguise themselves as legitimate software installs - hackers are using fake filenames to trick you into giving them remote control of your device. Microsoft has uncovered a sneaky campaign that uses a genuine MSP360 installer to gain an initial foothold on affected devices.

At just 16, security researcher Faav stumbled upon a massive Microsoft Analytics flaw, using his AI hackbot Antares to uncover a public API endpoint that led to admin access to a staggering 17.3 trillion row database. In a thrilling tale, Faav revealed how he exploited the vulnerability, gaining control with just a few clever moves.

Hackers are actively exploiting a high-severity flaw in Zimbra Collaboration Suite to gain remote access and harvest sensitive authentication secrets. This vulnerability, patched in July 2026, can be triggered by a specially crafted email, making it a critical threat to unprotected servers.

A recent analysis by Truffle Security revealed that over 543,000 valid credentials were left exposed in public GitHub repositories, despite existing security measures, with some credentials lingering for as long as 6.3 years. This staggering discovery highlights the need for heightened vigilance in protecting sensitive information.

A critical vulnerability in MikroTik RouterOS, known as CVE-2026-84411, can be exploited with a single crafted request, allowing attackers to execute code with root privileges or cause a denial-of-service condition, even without authentication. This flaw puts your network at risk, and it's essential to take immediate action to protect yourself.

At least 40 users have fallen victim to a sneaky malware campaign that uses ChatGPT Custom GPT pages and Google Sites to spread a powerful remote access trojan (RAT). Attackers cleverly created fake Custom GPT links that appeared on Google search results, tricking users into downloading the malware.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Cisco's SD-WAN Manager has a critical vulnerability that allows attackers to bypass authentication and access the Manager's API as an admin user without login credentials. This flaw, rated 9.8 out of 10 in severity, is being actively exploited, prompting Cisco to urge immediate upgrades to fixed releases.

If you're one of the 28 million McDonald's customers whose data was exposed, you may be at risk of social engineering scams and loyalty fraud due to the breach of sensitive info like names and loyalty point transactions. This massive data leak, which also included 71,000 corporate records, is a stark reminder to stay vigilant about protecting your personal data.

Stay ahead of potential threats: with AI-discovered vulnerabilities, remote code execution is a growing concern, making it crucial to examine your systems for compromise before upgrading or patching. NetScaler customers, in particular, should prioritize checking their systems for signs of exploitation.

Cisco is urging organizations to act fast after discovering a critical zero-day vulnerability in its Catalyst SD-WAN Manager, which is already being exploited by attackers to gain administrative privileges. Upgrade to a fixed software release ASAP to protect your network from potential breaches.

Meet the new security challenge: AI coworkers that operate on borrowed credentials with no owner and no off switch, posing a risk that threatens to upend traditional access governance. As AI agents become more autonomous and persistent, they require robust provisioning and lifecycle controls to prevent a security nightmare.

Microsoft is stepping up Entra ID security by blocking external script injections, starting mid-October 2026, to shield users from potential threats during sign-ins. This move will ensure only trusted scripts from Microsoft's content delivery network can run during authentication.

Six of the world's largest AI companies have committed to a groundbreaking safety accord, pledging to prioritize the responsible development of super intelligence. This historic agreement, signed on September 29, marks a major step forward in ensuring the safe and ethical advancement of AI technology.

The US Army is taking a massive leap forward in its counterdrone efforts, issuing 10 new contracts worth up to $4.15 billion to help protect against unmanned aerial threats. These contracts are now open to all vendors, marking a significant surge in the Army's action against drone threats.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Australia's quest for true sovereignty isn't about isolation, but about having the freedom to make real choices - and that's exactly what Deputy Secretary Hugh Jeffrey had in mind when he championed self-reliance as the key to unlocking national power.

Boeing has landed a major victory, securing a contract worth over $20 billion to build the US Navy's sixth-generation strike fighter, the F/A-XX, which will replace the F/A-18 Super Hornet and EA-18G Growler. This game-changing deal marks a significant milestone for the aerospace giant.

Traditional security tools are struggling to keep up with the rapidly evolving world of phishing attacks, where 89% of malicious domains are active for less than two days, rendering blocklists almost useless. Sophisticated phishing kits and diverse delivery channels have made it easier for attackers to bypass multi-factor authentication and steal sensitive credentials.

Indonesia is strengthening its maritime stance to counter China's growing influence in the South China Sea, but experts argue that the country still lacks a clear strategy for maritime cooperation. Under President Prabowo Subianto, Indonesia is walking a tightrope, prioritizing economic ties with China while navigating the complex web of territorial claims in the South China Sea.

The Pentagon's recent report to Congress seems to be at odds with Poland's enthusiastic declaration of alliance strength with the US, downplaying key threats in its update to the National Defense Strategy. While Poland boasts of an unprecedentedly strong partnership with America, the Pentagon's update focuses on progress made in areas like accelerating weapons production and boosting European defense spending.

As AI takes on more tasks, security operations center (SOC) analysts are gaining a boost in capacity and more time to tackle complex work - but this shift also raises important questions about skill development and trust in AI. With nearly half of respondents citing greater capacity as a top impact of AI, it's clear that analysts are getting a productivity lift.

TeamViewer is urging users to update to the latest version immediately due to a critical security risk that could allow hackers to take control of your device. A high-severity flaw, CVE-2026-92370, and four others have been identified, highlighting the urgent need for an update to protect against remote code execution attacks.

The water sector is facing a harsh reality: cyber threats are on the rise, and threat actors are intensifying their attacks as global conflicts escalate. Recent attacks on water facilities have exposed glaring technical and organizational gaps that leave the sector vulnerable.