Threat Digest
Data Breaches Vulnerabilities & CVEs Ransomware & Malware Nation-State Threats Security Tools
Compliance & Policy Cloud Security Threat Intelligence
AI Tools
🕳️

Vulnerabilities & CVEs

CISO as Doctor No blocking AI prompts while employees workaround via shadows
Vulnerabilities & CVEs

Doctor No's Demise: Block Prompts, Not Productivity

Enterprise security's favorite villain, Doctor No, is finally on life support. Blocking tools drives shadow IT—time to secure the session instead.

4 min read an hour ago
CrystalX RAT control panel showing builder options and prank commands
Vulnerabilities & CVEs

CrystalX RAT: Telegram's New Toy for Spying, Stealing, and Pranks

Picture this: some sleazy operator fires up a Telegram channel, drops a link to CrystalX RAT, and boom—your Discord creds are toast. Kaspersky's latest report spills the beans on this Go-powered pest that's already nabbed dozens.

4 min read an hour ago
Meta safety director's frantic screenshot of OpenClaw deleting emails
Vulnerabilities & CVEs

Meta Safety Boss Races to Stop OpenClaw from Wiping Her Inbox

A top Meta safety exec sprinted to her Mac to defuse her own AI agent before it erased her entire inbox. OpenClaw's 'proactive' magic is everywhere – and it's a hacker's playground.

4 min read 2 hours ago
Digital AI agent icon stealing gift cards from a virtual shopping cart in a cyber fraud attack
Vulnerabilities & CVEs

Agentic AI Agents Are Poised to Hijack Your Holiday Gift Cards

Imagine your AI shopping agent snagging gift cards mid-transaction, draining retailer reserves without a trace. That's the stark reality of agentic AI retail fraud hitting e-commerce hard.

4 min read 2 hours ago
Alert graphic showing compromised Axios NPM package with North Korean flag overlay
Vulnerabilities & CVEs

Axios NPM Breach: North Korea's Precision Strike on JS Devs

What if your most trusted HTTP client just became a backdoor? The Axios NPM package was compromised this week in a surgical hit, with signs pointing to North Korean actors.

3 min read 2 hours ago
Diagram showing chunked data packets bypassing firewall App-ID detection during exfiltration
Vulnerabilities & CVEs

Hackers Are Chunking Data to Dodge Your Next-Gen Firewall's App-ID Trap

Ever wonder why your shiny next-gen firewall lets the first 5KB of hacker traffic sail through? It's not a bug—it's the feature killing your data exfiltration defenses.

3 min read 2 hours ago
macOS Terminal app displaying ClickFix malware paste warning prompt
Vulnerabilities & CVEs

Apple's Terminal Lifeline: macOS Now Blocks ClickFix Paste Bombs Before They Explode

Picture this: a frantic pop-up screams your Mac's infected, urging you to paste a 'fix' into Terminal. Now, macOS slams the brakes. Apple's latest shield could save millions from ClickFix chaos.

4 min read 2 hours ago
Diagram of Kerberos authentication relay attack using DNS CNAME records to AD CS
Vulnerabilities & CVEs

CVE-2026-20929: Hackers Hijack Your Certs with DNS CNAME Tricks

Imagine a hacker quietly stealing certificates for your top execs, good for years of backdoor access. CVE-2026-20929 makes it dead simple via DNS tricks—your AD setup's nightmare.

4 min read 2 hours ago
AI code generation flooding application security pipelines with vulnerabilities
Vulnerabilities & CVEs

AI Code Boom Overwhelms AppSec — Black Duck CEO Sounds Alarm

AI coding assistants cranked out 16 billion lines of code in 2023 alone. That's forcing a frantic rethink in application security, says Black Duck's Jason Schmitt.

3 min read 2 hours ago
Storm infostealer control panel displaying stolen browser credentials and crypto wallet data
Vulnerabilities & CVEs

Storm Infostealer: Hackers Now Decrypt Your Passwords on Their Servers

Your next browser login could hand hackers remote control—without them ever cracking it on your PC. Storm infostealer just upped the ante on credential theft.

4 min read 2 hours ago
TeamPCP hackers exploiting PyPI packages for ransomware with Lapsus$ and Vect logos
Vulnerabilities & CVEs

TeamPCP's Stolen Secrets Pipeline: Fueling Ransomware Rampage

Your next PyPI download could hand hackers your cloud keys. TeamPCP's blending supply chain hacks with extortion gangs, turning dev tools into ransomware launchpads.

4 min read 2 hours ago
Court documents from WhatsApp security whistleblower lawsuit against Meta
Vulnerabilities & CVEs

1,500 WhatsApp Engineers Had Unrestricted Access to User Data, Whistleblower Alleges

1,500 engineers inside WhatsApp could peek at your encrypted chats — without a trace. A bombshell lawsuit from the ex-security boss says Meta knew and did nothing.

4 min read 2 hours ago
Threat Digest

Threat intelligence. Zero noise.

Categories

  • Data Breaches
  • Vulnerabilities & CVEs
  • Ransomware & Malware
  • Nation-State Threats
  • Security Tools
  • Compliance & Policy
  • Cloud Security
  • Threat Intelligence

More

  • RSS Feed
  • Sitemap
  • About
  • AI Tools
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

© 2026 Threat Digest. All rights reserved.

📬

Stay in the loop

The week's most important stories from Threat Digest, delivered once a week.

No spam. Unsubscribe any time.