CVE-2024-43468, CVE-2025-0836, CVE-2025-15556, CVE-2025-40536, CVE-2025-40587, CVE-2025-40936, CVE-2025-7740, CVE-2025-9491, CVE-2026-1358, CVE-2026-1731, CVE-2026-20700, CVE-2026-22923, CVE-2026-25655, CVE-2026-25656
Domains:
tapnetic[.]pro.
Get tomorrow's brief in your inbox
Generated: 2026-02-13 | Sources: 40 articles from 17 feeds
Sources: CISA KEV | The Register | BleepingComputer | The Hacker News
BeyondTrust Remote Support/PRA RCE Being Exploited in the Wild (CVE-2026-1731, CVSS 9.9)
get_portal_info endpoint to extract the x-ns-company value, then establish a WebSocket channel for code execution. EPSS is 0.04 (89th percentile).get_portal_info endpoint.Sources: The Hacker News | BleepingComputer | SecurityWeek
Apple Zero-Day Actively Exploited (CVE-2026-20700)
Sources: SINEC NMS | NX | Solid Edge | Siveillance | Polarion
Airleader Master RCE via Unrestricted File Upload (CVE-2026-1358, CVSS 9.8)
Source: CISA ICS Advisory
Hitachi Energy SuprOS Default Credentials (CVE-2025-7740)
Source: CISA ICS Advisory
Windows LNK Shortcut Spoofing Techniques Disclosed
Source: The Register
Qilin Ransomware Hits Romania's Oil Pipeline Operator Conpet
Sources: The Register | The Hacker News
North Korean Lazarus Group Runs Fake Recruiter Campaign via npm/PyPI ("Graphalgo")
Sources: BleepingComputer | The Hacker News
Claude AI Artifacts Abused in ClickFix Campaigns Targeting macOS
Source: BleepingComputer
Dutch Telecom Odido Breached, 6.2 Million Customers Exposed
Sources: The Register | BleepingComputer
QR Code Phishing Evolving with Deep Links and Direct APK Downloads
Covered in Critical Alerts above. This is the top priority for Windows/AD environments today. The CVSS 9.8 SQL injection allows unauthenticated RCE against ConfigMgr servers. Patched October 2024, now confirmed exploited. EPSS 0.86 (99th percentile).
Copilot Studio Agent Security: Top 10 Risks
Source: Microsoft Security Blog
Microsoft Fixes Family Safety Bug Blocking Chrome
Sources: The Hacker News (UNC2970) | The Hacker News (DIB)
npm Authentication Overhaul Post-Sha1-Hulud
Source: The Hacker News
LVMH Brands Fined $25M for SaaS Security Failures
Source: BleepingComputer
Gartner Warns Misconfigured AI in Cyber-Physical Systems Could Cause G20-Level Outages by 2028
Today's feed is dominated by long-overdue exploitation of known vulnerabilities. The Microsoft ConfigMgr flaw (CVE-2024-43468) was patched 16 months ago but is only now hitting KEV, reinforcing that patching delays create compounding risk. BeyondTrust exploitation within 24 hours of PoC release shows the shrinking window between disclosure and active attacks for internet-facing remote access tools. The abuse of legitimate RMM and employee monitoring software by ransomware operators is a growing blind spot for organizations that trust their own tooling implicitly; audit your remote access and monitoring deployments with the same rigor you apply to external attack surface.