Today’s Briefing
INC Ransom is exploiting two zero-day vulnerabilities in SonicWall SMA mobile access appliances to gain root-level access, marking active in-the-wild abuse of edge devices that sit on enterprise perimeters. Separately, Microsoft disclosed CVE-2026-58644, an unauthenticated remote code execution vulnerability in SharePoint Server already under exploitation, though the advisory does not yet identify the threat actor or campaign behind observed activity.
Top Stories
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.
Get the brief at 07:00, every weekday.
The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.