Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Vulnerability · Securityaffairs

What happened

The DOJ and FBI seized the China-linked Microscan and FishHub tools, which court documents allege were operated by Integrity Technology Group, a PRC-based company with PRC government contracts. The tools were used to scan and, in some cases, intrude into U.S. and foreign critical-infrastructure systems and other networks.

Why it matters

The associated Mirai-based IoT botnet database contained records for more than 1.2 million infected devices in June 2024, including more than 385,000 in the United States; about 260,000 devices were actively infected then.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Securityaffairs

What happened

CrowdStrike analyzed a campaign against South Korean financial organizations in late September–early October 2026 that ended with stolen data, using open directories left by the attacker. The exposed directories contained Claude Code session histories, ARTEX configuration files, and Claude memory files, giving researchers direct visibility into the operator’s methods and tooling.

Why it matters

CrowdStrike said the activity demonstrates that AI tooling can enable a financially motivated actor to conduct multiple intrusions within a short time span.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Securityaffairs

What happened

Anthropic launched OSS Scanner, a free vulnerability scanner for open-source projects that uses its AI models to identify vulnerabilities and help maintainers fix them. Over six months, Anthropic’s models identified more than 29,000 possible vulnerabilities in widely used open-source software; experts had manually reviewed about 6,000.

Why it matters

Anthropic’s validation tested 97 critical or high-severity findings across 48 projects: 85 met its process threshold, 11 of the remaining findings were real duplicates, and one was invalid.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription. Previously unsubscribed? Use this form to request a fresh confirmation link.

Explore Security Weekly