Compiled from 52 monitored sources · 535 articles reviewed
Today’s Briefing
Love Electric, a UK electric vehicle salary sacrifice broker, has had 877,000 driver records offered for sale on an English-language breach forum for $600, exposing sensitive identity data held by third-party fleet providers. PaperCut has issued emergency patches for CVE-2026-81578 and CVE-2026-82078, critical vulnerabilities in PaperCut NG and MF that permit configuration modification and code execution. ServiceNow has released advisories for critical flaws in the Now and AI platforms enabling unauthenticated arbitrary code execution, privilege escalation, and SQL injection. Apache Tomcat has disclosed four critical vulnerabilities across versions 9.0, 10.1, and 11.0, including authentication bypass via capture-replay in the DIGEST authenticator (CVE-2026-65905), FORM authentication constraint bypass (CVE-2026-68525), and security constraint bypass when longer path constraints precede shorter sub-path restrictions (CVE-2026-65182). McKesson has confirmed unauthorised access to third-party applications after ShinyHunters claimed theft of 284 million patient records.
Top Stories
- Love Electric Breach: 877,000 Driver Records Offered for $600
- CC-4839 - ServiceNow Releases Security Advisory for Critical Vulnerabilities in the ServiceNow Now and AI Platforms
- Xiiaozet LK100W
- Rockwell Automation OTTO Fleet Manager
- CC-4838 - PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.