Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

AI & Agents · Securityaffairs

What happened

Attackers used a compromised, long-lived Cloudflare API key with full permissions to deploy a malicious Worker and alter Brevo-served scripts on customer websites. The edge-delivered malware reached visitors of Brevo’s site and sites using its services; Sansec estimated that more than 100,000 sites may have been affected.

Why it matters

Because the Worker rewrote responses at the CDN edge and removed security headers while leaving origin files unchanged, origin hashes and standard integrity checks did not detect the modification.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Cyberscoop

What happened

U.S. and allied agencies warned that the North Korean group WaterPlum, also called Contagious Interview, poses as prospective employers to target software developers and IT professionals worldwide. The actors impersonate AI, cryptocurrency, and NFT companies, use recruiting services, and in some cases operate as North Korean IT workers performing web-system design and development for clients.

Why it matters

The alert says WaterPlum infected more than 30,000 devices in over 100 countries and transferred nearly $11 million in cryptocurrency from more than 7,000 wallets to North Korea.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Securityaffairs

What happened

Researchers exploited a heap buffer overflow in libheif processing of HEIC/HEIF uploads on a Discourse forum, then used the compromised OpenAI SSO path to hijack staff ChatGPT and Codex accounts. The attack did not use phishing or a leaked password; it began through an image upload, and the reported sequence from finding the bug to accessing an internal OpenAI repository took less than 72 hours.

Why it matters

The researchers confirmed local code execution and later obtained root-level access on a cloud instance; in OpenAI’s environment, they demonstrated account takeover by opening a single harmless pull request, without reading source code or merging changes.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription.

Explore Security Weekly