Compiled from 52 monitored sources · 664 articles reviewed
Today’s Briefing
CISA added CVE-2026-59822 and CVE-2026-48710 to the Known Exploited Vulnerabilities catalogue, the former an authentication bypass in BerriAI LiteLLM's MCP Streamable HTTP endpoint allowing unauthenticated session establishment with an arbitrary bearer token, the latter a request smuggling flaw in Kludex Starlette enabling path injection into the host component that can bypass authentication mechanisms reliant on reconstructed URL paths. Microsoft published research on a social engineering campaign in which attackers impersonate IT support to gain remote session access and pivot to enterprise-wide compromise. Chrome released 152.0.7977.75 addressing three critical-severity vulnerabilities including CVE-2026-84324, a use-after-free in Proxy exploitable via crafted network traffic for arbitrary code execution outside the sandbox, CVE-2026-84354, an authorisation flaw in FileSystem, and CVE-2026-84325, an input validation defect in DataTransfer that permits bypass of system access restrictions via a co-installed application.
Top Stories
- CC-4842 - Cisco Releases IOS XR Software Security Hardening Guidance
- CC-4841 - Broadcom Releases Security Advisory for Critical Vulnerabilities in VMware Workstation and VMware Fusion
- The story behind the intelligence
- Rockwell Automation ControlFLASH
- Pyramid Solutions NetStaX EtherNet/IP Stack
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.