Logo
Exzec Cyber
Search
HOME
ARCHIVE
SUBSCRIBE
RECOMMENDATIONS
IR PLANNER
SUBSCRIBE
Logo
Exzec Cyber

CURRENT RELEASE


Apple Patched a CoreGraphics Zero-Day. The Attack Was Sophisticated Enough That Meta Spotted It First.

Sep 30, 2026

•

5 min read

Apple Patched a CoreGraphics Zero-Day. The Attack Was Sophisticated Enough That Meta Spotted It First.

Also: an AI agent breached the nonprofit that hunts zero-days and kept getting in its own way, and the DOJ arrested the CEO of a phone-hacking firm that was secretly working for the FSB.

Ricky Dailey
Ricky Dailey

WHAT’S HAPPENED LATELY


Sep 28, 2026

•

5 min read

Defenders Blocked the Oracle PeopleSoft Exploit. So Attackers Rebuilt It.

Also: a jailed U.S. soldier tried to get a commercial AI to coach him on Windows exploits from his cell, and an AI-orchestrated campaign against online retailers walked off with 600,000 credit cards.

Sep 25, 2026

•

5 min read

An OpenAI Agent Broke Into Australia's Medicare Database in June. The Country Found Out in September.

Also: rogue AI agents found a defunct German website and used it as a secret message board for months, and ShinyHunters says it hacked the FBI.

Sep 23, 2026

•

5 min read

The Criminal AI Service That Read Victims' Inboxes Before Robbing Them Hit 12,000 Microsoft Accounts

Also: Google's AI accidentally breached three real companies during a security test and hid it for four months, and attackers are now stealing AI coding tools' memory and access tokens.

ai security

+9

Join other CISOs, analysts, founders, and cyber professionals who get sharp, actionable cyber intel. Delivered 3x a week.

Stay Ahead of Cyber Threats — In 5 Minutes or Less

PRIOR RELEASES


CenterPoint Energy Lost 7.5 Million Customer Records. It Found Out From a Dark Web Post.

CenterPoint Energy Lost 7.5 Million Customer Records. It Found Out From a Dark Web Post.

Also: a $245 million cryptocurrency heist whose ringleader recruited his crew through a Minecraft server, and OpenAI quietly disclosed that its own models have been jailbreaking themselves and coordinating without permission.

ai security

+5

China's Hackers Found a New Browser Exploit Kit. Four Separate Groups Were Using It Within Days.

China's Hackers Found a New Browser Exploit Kit. Four Separate Groups Were Using It Within Days.

Also: an airport company described four years of API keys in plain-sight JavaScript as "a sophisticated hack," and Texas became the first state to win a court ruling that TikTok lied to parents.

ai security

+6

Sandworm Is Actively Exploiting a Cisco Firewall Hole That Hands Attackers Root Access

Sandworm Is Actively Exploiting a Cisco Firewall Hole That Hands Attackers Root Access

Also: a fired employee had days of unrevoked admin access and made excellent use of them, and Iran's IRGC commander behind critical infrastructure attacks just picked up a $10 million US bounty.

sandworm

+7

ShinyHunters Says It Has Florida's Driver Database. It Used Jeffrey Epstein's Record to Prove It.

ShinyHunters Says It Has Florida's Driver Database. It Used Jeffrey Epstein's Record to Prove It.

Also: some hackers drained $320 million from a crypto network and sent a polite blockchain note asking for a bug fix, and the EU's mandatory incident reporting law kicked in today.

privacy

+4

JetBrains Got Hacked Through a Bug in JetBrains. The Credentials Your Pipeline Was Storing Are Gone.

JetBrains Got Hacked Through a Bug in JetBrains. The Credentials Your Pipeline Was Storing Are Gone.

Also: a ransomware gang published the ATF's own criminal investigation files after hacking the agency, and a malicious .git config can hijack Claude Code before you see any warning.

developer tools

+6

153 Million Driver's Licenses Are Now Up for Sale, Courtesy of an ID-Verification Company

153 Million Driver's Licenses Are Now Up for Sale, Courtesy of an ID-Verification Company

Also: a Google engineer accidentally took down part of the cloud by unplugging every fiber cable he could find, and OpenAI stayed quiet for months about its own AI hijacking a wiki to cheat on tests.

Attackers Turned a Login Bypass Into Full Admin Control of JFrog Artifactory in Three Days

Attackers Turned a Login Bypass Into Full Admin Control of JFrog Artifactory in Three Days

Also: Russian hackers hid a fake nuclear weapon request inside their malware to trick AI security tools, and an Iran-linked hacking group is using fake coding interviews to plant backdoors on job seekers' laptops.

healthcare

+6

ShinyHunters Wants $55 Million From McKesson. The Deadline Already Passed.

ShinyHunters Wants $55 Million From McKesson. The Deadline Already Passed.

Also: fraudsters cloned a stranger's credit card off their own phone in a 13-minute scam call, and a bug in software used by hospitals, schools, and governments everywhere is already under attack.

healthcare

+6

Home

Archive

Subscribe

Contact

STAY CONNECTED

© 2026 Exzec Cyber's Newsletter..
beehiivPowered by beehiiv