Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Incident · Malwarebytes Labs

What happened

Arizona’s court system said attackers gained access after an employee clicked a malicious link in a phishing email and copied sensitive backup files involving protective orders and foster care cases. The court later said attackers copied more than 150,000 Foster Care Review Board recommendation reports covering current and past children’s-care cases dating back to 2010.

Why it matters

The reports can include children’s information, names of involved parties, case materials, findings, and recommendations; the court said they do not contain addresses or telephone numbers.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Identity · Arstechnica Security

What happened

Microsoft warned that attackers were exploiting critical CVE-2026-73570 in Zimbra Collaboration Suite to seek email backups and authentication credentials from vulnerable organizations. The vulnerability allows unauthenticated attackers to remotely issue operating-system commands.

Why it matters

Shadowserver reported that scans found 274 separate compromised Zimbra instances.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Cyberscoop

What happened

Proofpoint attributed phishing campaigns to TA419, a China-aligned cyber espionage group, targeting U.S. AI policy experts and seeking access to cloud accounts at think tanks, universities, and law firms. The campaigns impersonated prominent officials, economists, and an Anthropic employee, using invitations about AI policy committees, export controls, supply chains, or military use of Claude models to start conversations.

Why it matters

Proofpoint characterized the operation as adversary-in-the-middle phishing: victims could interact with genuine Microsoft infrastructure, enter passwords, complete multifactor authentication, and pass access checks while session information was captured.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription. Previously unsubscribed? Use this form to request a fresh confirmation link.

Explore Security Weekly