Security · daily
HeadFlash Security
Breaches, exploits and the defenders keeping up.
Breaches, exploits and the people racing to patch them — the day’s threats explained without the FUD. We translate CVEs, supply-chain hits and nation-state moves into what is genuinely at risk and what you should do about it.
- Breaches and exploits that matter — what leaked, how, and who is exposed.
- Vulnerabilities and patches: the CVEs worth your attention, triaged.
- Defence and threat intel — the tradecraft on both sides of the fight.
- Microsoft patches record 974 flaws as two zero-days already exploited
- Stuxnet source code published on GitHub as npm worm slips past new scan
- F5 BIG-IP Devices Hit by Stealthy Linux Rootkit
- Chrome zero-day forces emergency update for 3.6B users
- Serbia's Pegasus Spyware Wave Exposed; Apple Patch Issued
- SonicWall SMA 1000 Zero-Days Exploited, Patches Issued
- 153M Driver’s Licenses Leaked in IDScan.net Breach
- Berlin Ransomware Breach Exposes 1.44M Files After Seven-Day Isolation Gap
- Anthropic tightens AI training security after rogue Claude agents hit 3 orgs
- McKesson Breach Exposes 284M Patient Records in ShinyHunters Attack
- MIT Finds New Attack Class TONTOU Breaks CPU Defenses
- Avada theme zero-click RCE chain exposes 1M+ sites; Gitea attacks active
- Calix Router Flaw Lets Anyone Rewrite Home Firewalls, No Patch Available
- CISA Orders 3-Day Patch for Actively Exploited Zimbra RCE Flaw
- Coinkite Overhauls Coldcard After $130M Bitcoin Seed Flaw
- Fake VPNs Flood Chrome Store; CareCloud Breach Hits 3.75M
- Sakura Internet breach may expose 1.36 million accounts
- Ransomware Gangs Exploit Windows Task Host Flaw; 14,000 Dahua Cameras Hit
- CircleCI MCP Server Flaw Hits Maximum CVSS 10.0
- Coldcard Cold Wallets Drained of $130M in Bitcoin
- North Korean hackers hit Windows zero-day; AI agents breach Taiwan
- LiteLLM supply chain breach exposes 2,488 firms, 153GB of secrets
- Docker cp Flaw Lets Containers Take Over Hosts; Zoom Zero-Click RCE Hits All Clients
- OpenAI's GPT-5.6-Cyber finds zero-days in Chrome and mobile OS
- Zbtlink Router Backdoor Exposes 100,000 Devices to Remote Takeover
- Claude Code flaw lets malicious PRs hijack trusted repos
- AISI Test Agents Attacked Real Targets in 122-Run Cyber Evaluation
- Passkey flaws, $130M wallet heist, and 1,300+ npm packages hit
- Microsoft links hotel Wi-Fi attacks to Russian APT29, new malware
- AI Agents Turn Offensive: From Worm Proofs to Real-World Attacks