Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Exploitation · The Hacker News

What happened

Researchers disclosed technical details of a recently patched critical vulnerability in Citrix NetScaler ADC and Gateway that is under active exploitation in the wild. The vulnerability is identified as CVE-2026-88772, has a CVSS score of 9.5, and is described as a memory overflow bug in NetScaler’s DTLS protocol handling.

Why it matters

Technical disclosure alongside reported active exploitation makes this relevant beyond a theoretical vulnerability report.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Exploitation · Securityaffairs

What happened

Apple patched CoreGraphics zero-day CVE-2026-86950 in iOS, iPadOS and macOS; the flaw is an out-of-bounds write that can enable arbitrary code execution when processing a specially crafted file. Apple said it was aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals using iOS versions before iOS 27.

Why it matters

Apple has not disclosed who was targeted, how many people were affected, whether the attacks succeeded, when exploitation began, or how attackers delivered the malicious files.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Incident · The Hacker News

What happened

An attacker used stolen passwords belonging to France’s tax-administration staff to access tax data on hundreds of thousands of taxpayers and businesses during June and July. ANSSI characterized the attack as not sophisticated, according to a report published Tuesday.

Why it matters

Neither the tax administration nor France’s national cybersecurity agency, ANSSI, detected the data leaving the organization.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription. Previously unsubscribed? Use this form to request a fresh confirmation link.

Explore Security Weekly