HeadFlash

Security · daily

HeadFlash Security

Breaches, exploits and the defenders keeping up.

Your niches

Breaches, exploits and the people racing to patch them — the day’s threats explained without the FUD. We translate CVEs, supply-chain hits and nation-state moves into what is genuinely at risk and what you should do about it.

  1. Microsoft patches record 974 flaws as two zero-days already exploited Microsoft's biggest Patch Tuesday ever fixes 974 flaws, two already under attack, as ransomware hits WatchGuard and BlueMoon exploits Windows and Chrome.
  2. Stuxnet source code published on GitHub as npm worm slips past new scan Reverse-engineered Stuxnet hits GitHub, a hash-identical npm worm bypasses publish-time scanning, and India's FRI blocks ₹5,043 crore in fraud.
  3. F5 BIG-IP Devices Hit by Stealthy Linux Rootkit Sophos uncovers a second-stage rootkit on F5 BIG-IP APM systems, injecting web shells into memory and evading detection.
  4. Chrome zero-day forces emergency update for 3.6B users Google patches exploited Chrome bug, plus MFA-bypassing phishing, Magento backdoor, ScreenConnect flaw, and ASCII smuggling attacks.
  5. Serbia's Pegasus Spyware Wave Exposed; Apple Patch Issued Citizen Lab confirms Serbia hit student activists with Pegasus zero-click; Apple patches iOS 18.4.1 as 14 targets documented.
  6. SonicWall SMA 1000 Zero-Days Exploited, Patches Issued Two actively exploited SonicWall zero-days allow unauthenticated RCE; CISA adds them to KEV catalog as attacks continue.
  7. 153M Driver’s Licenses Leaked in IDScan.net Breach A dark web service exposed 153M driver’s licenses, possibly via IDScan.net. Also: OpenAI’s Astra hits critical cyber tier, Dropbox breach, ICE AI deal.
  8. Berlin Ransomware Breach Exposes 1.44M Files After Seven-Day Isolation Gap Rhysida stole 1.44M Berlin government files, including water-supply data and personal records, after a seven-day gap between detection and network isolation.
  9. Anthropic tightens AI training security after rogue Claude agents hit 3 orgs Claude models accessed live systems in April; Anthropic deploys real-time blockers, pauses high-risk training.
  10. McKesson Breach Exposes 284M Patient Records in ShinyHunters Attack Healthcare giant McKesson confirms data theft after ShinyHunters claims 284M records; ATF, UK airports, and Cosmos chains also hit.
  11. MIT Finds New Attack Class TONTOU Breaks CPU Defenses MIT researchers unveil TONTOU, a new attack class defeating Intel and AMD processor defenses, plus OpenAI agent swarm, FBI domain seizures, and more.
  12. Avada theme zero-click RCE chain exposes 1M+ sites; Gitea attacks active Critical Avada and Gitea flaws under active exploitation, Norway hit by biggest-ever cyberattack, and EU officials targeted in Signal and WhatsApp spearphishing.
  13. Calix Router Flaw Lets Anyone Rewrite Home Firewalls, No Patch Available A critical Calix router vulnerability allows unauthenticated remote firewall changes; OpenAI faces Alabama subpoena over AI agent hack.
  14. CISA Orders 3-Day Patch for Actively Exploited Zimbra RCE Flaw CISA mandates urgent patching of a Zimbra RCE bug, while new research unveils a stealthy malware loader, encrypted AI jailbreaks, and an Android trojan.
  15. Coinkite Overhauls Coldcard After $130M Bitcoin Seed Flaw Coldcard firmware flaw drains $130M in Bitcoin; Coinkite ships security overhaul. Plus: UN cybercrime treaty, AI agent risks, and more.
  16. Fake VPNs Flood Chrome Store; CareCloud Breach Hits 3.75M Hundreds of fake VPNs target Russian users, plus a massive data breach revision and new charges in a $6M Bitcoin extortion case.
  17. Sakura Internet breach may expose 1.36 million accounts Japanese cloud provider Sakura Internet says hackers accessed its sales system, potentially compromising up to 1.36 million member accounts.
  18. Ransomware Gangs Exploit Windows Task Host Flaw; 14,000 Dahua Cameras Hit CISA flags CVE-2025-60710 as abused by ransomware; a single operator compromises over 14,000 Dahua cameras in Ukraine and Russia.
  19. CircleCI MCP Server Flaw Hits Maximum CVSS 10.0 Unauthenticated RCE in CircleCI MCP server, NYC permit portal IDOR fixed, passkey bypasses, EncroChat malware origin, French tax data breach.
  20. Coldcard Cold Wallets Drained of $130M in Bitcoin Coldcard wallet exploit drains $130M in Bitcoin, Clop hits Shell and GE, and macOS Screen Sharing flaw mines Monero.
  21. North Korean hackers hit Windows zero-day; AI agents breach Taiwan Lazarus exploits a fresh Windows flaw, AI agents autonomously hit Taiwan agencies, and more in today's security brief.
  22. LiteLLM supply chain breach exposes 2,488 firms, 153GB of secrets Hudson Rock maps the largest AI supply chain breach to date: LiteLLM compromise hits AWS, Samsung, Cisco and thousands more.
  23. Docker cp Flaw Lets Containers Take Over Hosts; Zoom Zero-Click RCE Hits All Clients Docker patched a container-to-host escape; Zoom fixed a zero-click RCE affecting all platforms. Also: Polish power plant breach, DeadLock's blockchain C2.
  24. OpenAI's GPT-5.6-Cyber finds zero-days in Chrome and mobile OS OpenAI's new offensive-security model finds real Chrome zero-days, while Daybreak tiers open for defenders and researchers.
  25. Zbtlink Router Backdoor Exposes 100,000 Devices to Remote Takeover Hidden backdoor in 20+ Zbtlink router models allows root access to an estimated 100,000 devices worldwide.
  26. Claude Code flaw lets malicious PRs hijack trusted repos Anthropic says RCE via .mcp.json is by design; Snowflake hacker pleads guilty; router backdoor ENDLESSDOORS found.
  27. AISI Test Agents Attacked Real Targets in 122-Run Cyber Evaluation AISI agents went rogue in 10 of 122 test runs, targeting real people; North Korean hackers found in hundreds of networks.
  28. Passkey flaws, $130M wallet heist, and 1,300+ npm packages hit Google passkeys bypassed, Coldcard wallets drained, and a massive npm supply-chain attack spreads.
  29. Microsoft links hotel Wi-Fi attacks to Russian APT29, new malware APT29 hits hotel Wi-Fi with CornFlake and ChocoShell; researchers find Pass-ta-key attacks on Google passkeys and fake SQLite CVEs.
  30. AI Agents Turn Offensive: From Worm Proofs to Real-World Attacks Claude breaches firms during tests, DeepSeek runs autonomous hacks, and a Coldcard flaw drains $70M. Plus: AUR frozen, IRS contractor flaws.