// THREAT ADVISORIES

THREAT ADVISORIES

Advisories, vulnerabilities and threat intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
0
Last 24h
27
Last 7 Days
0
Critical (7d)
All Critical High Medium Low
✕ Clear All
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFWhen the Whole Company Adopts AI: What It Does to Your SOC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate

Medium · Sep 12, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFEU Gets Access to Anthropic Cyber AI — But Not Its Newest Model

ENISA has gained access to Anthropic’s Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations. The post EU Gets Access to Anthropic Cyber AI — But Not Its Newest Model appeared first on TechRepublic .

Medium · Sep 11, 2026 · TechRepublic Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFAI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech

See what you missed in Daily Tech Insider from Sept. 7–11. The post AI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech appeared first on TechRepublic .

Medium · Sep 11, 2026 · TechRepublic Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft fixes Teams, Outlook launch failures on ARM Windows PCs

Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]

Medium · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)

[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]

🌐 sans.edu
Medium · Sep 10, 2026 · SANS Internet Storm Center
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft fixes bug that wiped Windows desktop settings

Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]

Medium · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF ☁️
VERISQ BRIEFProduct showcase: GitGuardian Honeytoken catches credential theft as it happens

Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential paths. The families active now cast a much wider net. Shai-Hulud, for instance, ran a secret scanner across the entire filesystem and validated whatever it turned up, rather than checking a handful of expected locations. That breadth is what makes deception practical, and the speed is what makes it urgent. … More → The post Product showcase: GitGuardian Honeytoken catches credential theft as it happens appeared first on Help Net Security .

Medium · Sep 10, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-79910.

Medium · Sep 10, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81978.

Medium · Sep 10, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80160.

Medium · Sep 10, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81991.

Medium · Sep 10, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80162.

Medium · Sep 10, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFSmashing Security podcast #484: How websites are tracking you with silence

When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated." All this and more in episode 484 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

Medium · Sep 09, 2026 · Graham Cluley
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFChrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

Medium · Sep 09, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF ☁️
VERISQ BRIEFGartner: 70% of SOCs will pilot AI agents. Only 15% will see results

In the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 operations, but only 15% will achieve measurable improvements without structured evaluation.” Just last year, Gartner placed AI SOC Agents at the Innovation Trigger stage with single-digit adoption. As of earlier this year, Gartner’s Hype Cycle … More → The post Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results appeared first on Help Net Security .

Medium · Sep 09, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-60162.

Medium · Sep 09, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18444.

Medium · Sep 09, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.

Medium · Sep 09, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.

Medium · Sep 09, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.

Medium · Sep 09, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFFDA Pilot Gives AI Health Tools a Real-World Test Bed

4 Manufacturers Will Test Tools for Diabetes, Hypertension and Mental Health The FDA's TEMPO pilot allows selected AI-enabled health devices to reach chronic care patients before formal marketing authorization while manufacturers collect real-world evidence regulators can use to evaluate safety, performance and patient outcomes.

Medium · Sep 09, 2026 · DataBreachToday
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFOpenAI says ChatGPT outage causes image generation errors

OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]

Medium · Sep 08, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFThe US military just turned off ad tracking on its phones. Maybe you should too

Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Hot for Security blog.

Medium · Sep 08, 2026 · Graham Cluley
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFWhat It Took to Reach 1 Billion Build Manifests

In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally

Medium · Sep 08, 2026 · The Hacker News
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🏥
VERISQ BRIEFBefore You Paste Anything Into ChatGPT, Check This List

Before pasting passwords, medical records, source code, or company data into ChatGPT, use this checklist to decide what should stay private. The post Before You Paste Anything Into ChatGPT, Check This List appeared first on TechRepublic .

Medium · Sep 07, 2026 · TechRepublic Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft says some users can’t open the Teams desktop client

Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]

Medium · Sep 04, 2026 · BleepingComputer
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 📧
VERISQ BRIEFExchange Online outage causes email delays, 'Server busy' errors

Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]

Medium · Sep 04, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFScammers have figured out the best time to text you

The suspicious calls, texts, and DMs you got recently aren’t a coincidence, according to Malwarebytes. Scammers have worked out which platform gets them the best results for each type of con, and they stick to that formula. (Source: Malwarebytes) The company looked at its own threat data collected between April 15 and July 14, 2026, and tracked more than 20 scam categories, from tech support cons to sextortion. “Intuitively, the platforms favored often match the … More → The post Scammers have figured out the best time to text you appeared first on Help Net Security .

Medium · Sep 04, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF ☁️
VERISQ BRIEFNew infosec products of the week: September 4, 2026

Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because of its strategic position in customers’ infrastructure. Enhancements to F5 WAF for Distributed Cloud and virtual patching provide the precision … More → The post New infosec products of the week: September 4, 2026 appeared first on Help Net Security .

Medium · Sep 04, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft says KB5120998 Windows update resets desktop settings

Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]

Medium · Sep 03, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFResearching Employment Scams

Researchers built a fake company to study fake employee scams .

Medium · Sep 03, 2026 · Schneier on Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🎓
VERISQ BRIEFResearchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working with the National University of Singapore and Singapore Management University, has built a small LED accessory that tries to answer … More → The post Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms appeared first on Help Net Security .

Medium · Sep 03, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft Teams, Outlook fail to launch on ARM-based Windows PCs

Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]

Medium · Sep 03, 2026 · BleepingComputer
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFYour phone or computer may soon ask how old you are

California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.

Medium · Sep 03, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🗄️
VERISQ BRIEFYour threat feed is someone else’s database: What ingesting malware intel at scale takes

The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone else’s database. Someone else’s processes built it, someone else’s judgement calls shaped it, and someone else’s bad Tuesday is sitting it right now, waiting for … More → The post Your threat feed is someone else’s database: What ingesting malware intel at scale takes appeared first on Help Net Security .

Medium · Sep 03, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFWhen AI quietly breaks things, who pays?

David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures in applications can turn into warranties an insurer uses to deny a claim, who should sign off on AI use questions, when the claim clock starts for slow-building model degradation, and how … More → The post When AI quietly breaks things, who pays? appeared first on Help Net Security .

Medium · Sep 03, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFWindows memory integrity switches on automatically for eligible devices in October 2026

Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory integrity is the layer that allows only trusted kernel-mode code and drivers to run, which is how it stops an attacker who is trying to compromise the Windows kernel and take control of core operating system functions. The … More → The post Windows memory integrity switches on automatically for eligible devices in October 2026 appeared first on Help Net Security .

Medium · Sep 03, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFHoneypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)

[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]

🌐 sans.edu
Medium · Sep 03, 2026 · SANS Internet Storm Center
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFAir Launches With $50M to Keep Enterprise AI Agents Safe

Startup's Platform Continuously Vets Websites and Add-Ons Before Agents Reach Them Air emerged from stealth with $50 million from Sequoia and Greenoaks to build pre-runtime security that vets AI models, websites and add-ons before enterprise agents interact with them, while investing in interpretability research to expose risks inside the models themselves.

Medium · Sep 03, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 💀
VERISQ BRIEFH1 2026 Malware Vulnerability Trends

Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security.

Medium · Sep 03, 2026 · Recorded Future Feed
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFAI’s Vulnerability Surge May Be More Manageable Than First Feared

New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.

Medium · Sep 02, 2026 · Dark Reading
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 📧
VERISQ BRIEFAI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier, I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. I set up my own mail server and am sending this myself...

Medium · Sep 02, 2026 · Schneier on Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🏥
VERISQ BRIEFGoogle, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them

Medium · Sep 02, 2026 · The Hacker News
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 💀
VERISQ BRIEFRansomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]

Medium · Sep 02, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFScammers are getting smarter about where they target you 

New Malwarebytes research reveals how different scams are tailored to different platforms.

Medium · Sep 02, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →