Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

AI & Agents · Theregister Security

What happened

Researchers say Plugin4Shell is a zero-click remote-code-execution vulnerability affecting Claude Code, Codex, Gemini CLI, Microsoft Copilot, and GitHub Copilot; exploitation could expose assets and data reachable by the agent. The attack targets trusted plugin marketplaces rather than the underlying model or agent, and researchers say it could reach millions of users and machines.

Why it matters

With automatic plugin updates enabled, swapping a pinned commit upstream can replace an installed plugin with malicious code; the researchers reported that Claude and Codex automatically update installed plugins by default.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Exploitation · The Hacker News

What happened

A critical vulnerability in Check Point Security Management and Log Servers could let an unauthenticated network attacker execute code as root. Check Point released a fix through its LivePatch update channel; the supplied text truncates the statement about whether the flaw has been exploited.

Why it matters

The Security Management Server controls firewall policy and administrator access, so compromise could affect those management functions.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Identity · Certcc Vulnotes

What happened

Dokploy versions 0.29.8 and 0.29.11, plus canary commit 24b02f5, are vulnerable to OS command injection during database backup creation and restoration. The vulnerable backup and restore functions incorporate user-controlled database-name or backupFile values into shell commands without shell escaping or restrictions on metacharacters.

Why it matters

An authenticated user with database-backup permission can execute arbitrary commands as root on the Dokploy host because the backup operations run in the root-privileged Dokploy process.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription.

Explore Security Weekly