This week in cybersecurity, researchers disclosed multiple Windows zero-day vulnerabilities, including 'MiniPlasma' and 'YellowKey,' granting attackers full system access and bypassing BitLocker encryption. A critical 18-year-old flaw in NGINX, 'NGINX Rift,' is now under active exploitation, threatening millions of web servers. The line between cybercrime and nation-state attacks continues to blur as Iran-aligned actors weaponize ransomware against critical infrastructure. Additionally, a logical flaw in the Verus-Ethereum bridge led to an $11.5 million theft, and a widespread supply chain attack compromised popular open-source packages.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.