Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Exploitation · Cyberscoop

What happened

Volexity reported that the China-aligned group UTA0565 exploited a three-vulnerability zero-day chain affecting Chrome and Microsoft before the defects were disclosed or patched, during September 3–4. The chain included CVE-2026-85046 and CVE-2026-87491, remote-code-execution defects in Chromium-based browser JavaScript engines, and CVE-2026-85880, a Windows Advanced Local Procedure Call privilege-escalation zero-day.

Why it matters

Volexity said UTA0565 used multiple fake websites, phishing emails targeting Asian government entities, and spoofed domains impersonating the Center for American Progress and China Digital Times. The reported chain crosses browser and operating-system boundaries, making the distinction between those layers central to its practitioner relevance.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Identity · The Hacker News

What happened

Attackers are exploiting CVE-2026-94127, a critical flaw in F5 BIG-IP Access Policy Manager (APM) that can allow unauthenticated code execution on a BIG-IP system, according to F5. The vulnerability affects only systems where APM operates as an OAuth authorization server issuing access tokens to applications.

Why it matters

The reported condition narrows relevance to a specific authorization role rather than all BIG-IP deployments.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Identity · Helpnetsecurity

What happened

Check Point released emergency fixes for critical Management Server vulnerability CVE-2026-93616, which had been exploited as early as July 23, 2026. Check Point confirmed that CVE-2026-85102, a pre-authentication remote-code-execution vulnerability in Check Point Quantum Security Gateway, was probed a few days after patches were released on September 9, 2026.

Why it matters

The two reported cases distinguish exploitation of a management component from post-patch probing of a gateway defect.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription.

Explore Security Weekly