<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Morning Brief — BLACKMESA.CA</title>
    <link>https://brief.blackmesa.ca</link>
    <description>A short daily security briefing: top developments, newly exploited vulnerabilities, patch activity and vulnerability watch.</description>
    <language>en-ca</language>
    <lastBuildDate>Wed, 02 Sep 2026 17:06:54 +0000</lastBuildDate>
    <ttl>720</ttl>
    <atom:link href="https://brief.blackmesa.ca/feed.xml" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://blackmesa.ca/favicon.svg</url>
      <title>BLACKMESA.CA Morning Brief</title>
      <link>https://brief.blackmesa.ca</link>
    </image>
  <item>
    <title><![CDATA[Morning Brief — Wednesday, September 2, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-09-02/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-09-02/</guid>
    <pubDate>Wed, 02 Sep 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users; Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities; Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products; Another Artifactory CVE under attack by AI agents or humans; Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw. 505 new CVEs in 24h. Vendor batches: HP (86), Unknown (55), WordPress (53), Mozilla (34), NVIDIA (30)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Tuesday, September 1, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-09-01/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-09-01/</guid>
    <pubDate>Tue, 01 Sep 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement; Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations; Hackers Abuse Real ChatGPT Links to Trick Windows Users Into Installing Malware; WatchGuard Patches Critical Vulnerabilities; Attackers Steal METR API Key and Consume AI Credits Worth About $600,000. 324 new CVEs in 24h. Vendor batches: Unknown (84), WordPress (27), ash-project (20), Microsoft (15), ellite (13)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Monday, August 31, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-31/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-31/</guid>
    <pubDate>Mon, 31 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor; Security Risk Advisors Launches SCALR AI as a Free SOC AI Platform for Security Teams; Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India; Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams; Microsoft Investigating New Exchange Online Outage Tracked as EX1464935 [Updated]. 188 new CVEs in 24h. Vendor batches: ash-project (25), Unknown (25), D-Link (8), Apache (8), itsourcecode (7)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Sunday, August 30, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-30/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-30/</guid>
    <pubDate>Sun, 30 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Google's Calling Lake Ontario 'Lake America' Now; TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor; 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code; Microsoft Teams Has Become a Haven for Scammers in China; Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE. 61 new CVEs in 24h. Vendor batches: WordPress (10), pac4j (5), jeremyevans (5), itsourcecode (4), ash-project (4)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Saturday, August 29, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-29/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-29/</guid>
    <pubDate>Sat, 29 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Microsoft Teams Has Become a Haven for Scammers in China; Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers; 700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation; Critical ServiceNow Flaws Let Attackers Execute Code and Access Data; OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems. 351 new CVEs in 24h. Vendor batches: Unknown (64), WordPress (33), Open-Xchange GmbH (25), Microsoft (17), IBM (16)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Friday, August 28, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-28/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-28/</guid>
    <pubDate>Fri, 28 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions; Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix; CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks; CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs; 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code. 480 new CVEs in 24h. Vendor batches: Linux (126), Unknown (40), Spring (35), WordPress (32), WatchGuard (29)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Thursday, August 27, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-27/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-27/</guid>
    <pubDate>Thu, 27 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks; Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE; Android Malware Hijacks Update System for Car Head Units; CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs; Learn How to Build Security Operations Ready for AI-Powered Attacks. 280 new CVEs in 24h. Vendor batches: Unknown (66), Spring (40), WordPress (24), Dell (13), Apple (8)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Wednesday, August 26, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-26/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-26/</guid>
    <pubDate>Wed, 26 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations; SonicWall NetExtender Vulnerabilities Allow an Attacker to Write Arbitrary Files as Root; Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware; WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android; WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks. 706 new CVEs in 24h. Vendor batches: Google (327), Adobe (38), NVIDIA (28), Microsoft (24), TYPO3 (23)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Tuesday, August 25, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-25/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-25/</guid>
    <pubDate>Tue, 25 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next; Hackers Abuse Google Sites to Host Fake OpenAI Codex Download Pages; You don't want this Sleepwalker backdoor on your Windows machine; CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw; CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks. 344 new CVEs in 24h. Vendor batches: DrayTek Corporation (40), WordPress (24), Unknown (18), getgrav (15), Red Hat (11)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Monday, August 24, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-24/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-24/</guid>
    <pubDate>Mon, 24 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Hackers Infect Android Car Screens Through Their Built-In Software Update System; AWS Network Firewall Now Displays Count of Triggered Security Rules; New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File; Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot; TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit. 67 new CVEs in 24h. Vendor batches: EmilStenstrom (10), Unknown (10), itsourcecode (5), Microsoft (5), SourceCodester (4)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Sunday, August 23, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-23/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-23/</guid>
    <pubDate>Sun, 23 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot; Apple Detected Something on These iPhones | Threat Wire; Top 10 Best Wireless / Wi-Fi Security Solutions in 2026; Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet; AWS Security makes an inscrutable choice. 245 new CVEs in 24h. Vendor batches: Linux (138), fabrikar.com (17), WordPress (16), nltk (11), Unknown (9)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Saturday, August 22, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-22/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-22/</guid>
    <pubDate>Sat, 22 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot; Apple Detected Something on These iPhones | Threat Wire; Top 10 Best Wireless / Wi-Fi Security Solutions in 2026; Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet; AWS Security makes an inscrutable choice. 291 new CVEs in 24h. Vendor batches: WordPress (37), Unknown (36), Apache (21), Combodo (18), lxc (17)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Friday, August 21, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-21/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-21/</guid>
    <pubDate>Fri, 21 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Grok exfiltrates user data when malicious instructions are encrypted; Apple’s Private Find My People Reversed to Decrypt Live Shared Locations on Linux; AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure; The invisible passenger in your car; Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials. 481 new CVEs in 24h. Vendor batches: IBM (75), Microsoft (27), Red Hat (16), n8n-io (16), Unknown (15)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Thursday, August 20, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-20/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-20/</guid>
    <pubDate>Thu, 20 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18); NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology; ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud; CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway; Hackers Hide Malware Code Inside English Words to Infect Windows Users. 634 new CVEs in 24h. Vendor batches: Splunk (110), IBM (107), Wireshark Foundation (25), Dell (23), Unknown (19)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Wednesday, August 19, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-19/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-19/</guid>
    <pubDate>Wed, 19 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18); Apple plugs image-processing hole ripe for spyware abuse; Hackers Use Fake Claude Install Guide to Deploy MacSync Stealer and Trojanize Crypto Wallet Apps; Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000; BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges. 1481 new CVEs in 24h. Vendor batches: Oracle (891), Mozilla (58), WordPress (48), Unknown (37), mybb (18)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Tuesday, August 18, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-18/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-18/</guid>
    <pubDate>Tue, 18 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Windows 11 File Explorer Gets Faster, Customizable Right-Click Menu With App Extension Controls; 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets; Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks; Video Call Exploit Chains Two Flaws in Unisoc Modems; Crook hawks millions of records allegedly plundered from corporate Azure tenants. 377 new CVEs in 24h. Vendor batches: Mozilla (58), Unknown (35), Apple (35), JetBrains (18), ArcadeData (14)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Monday, August 17, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-17/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-17/</guid>
    <pubDate>Mon, 17 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw; Hacker claims 3.6 million Azure account records stolen from major companies; Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection; Apple Patches iOS and macOS, (Mon, Aug 17th); Video Call Exploit Chains Two Flaws in Unisoc Modems. 77 new CVEs in 24h. Vendor batches: scriban (15), WordPress (12), Unknown (6), Edimax (5), GL.iNet (5)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Sunday, August 16, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-16/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-16/</guid>
    <pubDate>Sun, 16 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Vulnerability giving attackers full control of Macs is under active exploitation; Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication; VINclarity Publishes Investigation Into Alleged Scam and Fraud Reputation Attack Across Search and AI; New Evooo1Bot Linux botnet turns routers into traffic relay nodes; Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC. 252 new CVEs in 24h. Vendor batches: Linux (127), WordPress (56), siyuan-note (10), Unknown (8), code-projects (7)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Saturday, August 15, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-15/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-15/</guid>
    <pubDate>Sat, 15 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: VINclarity Publishes Investigation Into Alleged Scam and Fraud Reputation Attack Across Search and AI; Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication; Vulnerability giving attackers full control of Macs is under active exploitation; Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals; ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability. 918 new CVEs in 24h. Vendor batches: Linux (657), WordPress (26), Apple (25), IBM (18), HashiCorp (17)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Friday, August 14, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-14/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-14/</guid>
    <pubDate>Fri, 14 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Download More RAM Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing; Passwords stored in public Google Doc then showed up in search results; Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals; HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel; AWS key exposed in JavaScript may have lit way to Beacon's charity data. 612 new CVEs in 24h. Vendor batches: IBM (74), Elastic (48), Gitea (47), Unknown (36), RsyncProject (28)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Thursday, August 13, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-13/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-13/</guid>
    <pubDate>Thu, 13 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor; Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks; Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor; Passwords stored in public Google Doc then showed up in search results; Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA. 393 new CVEs in 24h. Vendor batches: IBM (68), jfrog (25), Unknown (24), siyuan-note (22), Red Hat (17)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Wednesday, August 12, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-12/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-12/</guid>
    <pubDate>Wed, 12 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery; Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability; Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing; CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure; Top 10 Best Business VPN Solutions in 2026. 983 new CVEs in 24h. Vendor batches: Microsoft (483), Adobe (52), WordPress (39), Unknown (36), Red Hat (31)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Tuesday, August 11, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-11/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-11/</guid>
    <pubDate>Tue, 11 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition; BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins; China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw; Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo; Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development. 769 new CVEs in 24h. Vendor batches: Linux (316), WordPress (51), Unknown (49), Red Hat (33), SAP (33)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Monday, August 10, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-10/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-10/</guid>
    <pubDate>Mon, 10 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry Leakage; Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption; Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach; Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails; Levi Strauss & Co. says hackers stole corporate data in cyberattack. 99 new CVEs in 24h. Vendor batches: WordPress (47), code-projects (5), Apple (4), Unknown (3), MingSoft (3)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Sunday, August 9, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-09/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-09/</guid>
    <pubDate>Sun, 09 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default; 18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host; CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges; AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day; ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets. 96 new CVEs in 24h. Vendor batches: WordPress (33), D-Link (15), MSI (11)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Saturday, August 8, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-08/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-08/</guid>
    <pubDate>Sat, 08 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets; ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets; Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer; Attacker phished way into US defense supplier's Microsoft 365 account; Flaws in Google APK for Python Unlock Agent-to-Agent Attack. 186 new CVEs in 24h. Vendor batches: Tobit Laboratories AG (21), HashiCorp (12), Sonatype (11), Unknown (8), WordPress (7)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Friday, August 7, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-07/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-07/</guid>
    <pubDate>Fri, 07 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets; Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses; Attacker phished way into US defense supplier's Microsoft 365 account; Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails; Flaws in Google APK for Python Unlock Agent-to-Agent Attack. 513 new CVEs in 24h. Vendor batches: WordPress (87), Google (45), Microsoft (21), Apache (18), Unknown (17)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Thursday, August 6, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-06/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-06/</guid>
    <pubDate>Thu, 06 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Flaws in Google APK for Python Unlock Agent-to-Agent Attack; Anthropic’s AI used fake identities, malware in rogue attack on GitHub project; Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools; CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild; Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses. 389 new CVEs in 24h. Vendor batches: Unknown (35), WordPress (32), IBM (32), Cisco (23), Jenkins (23)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Wednesday, August 5, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-05/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-05/</guid>
    <pubDate>Wed, 05 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: 1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks; Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation; CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild; 7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen; Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent. 285 new CVEs in 24h. Vendor batches: WordPress (32), FlowiseAI (18), Unknown (17), NVIDIA (16), HashiCorp (14)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Tuesday, August 4, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-04/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-04/</guid>
    <pubDate>Tue, 04 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Google dev kit spurs first-ever agent-on-agent violence; CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks; Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers; Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams; Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access. 231 new CVEs in 24h. Vendor batches: WordPress (22), Microsoft (21), Unknown (19), HashiCorp (12), Red Hat (10)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Monday, August 3, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-03/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-03/</guid>
    <pubDate>Mon, 03 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says; Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft; MacSync macOS Stealer Uses Fake Claude Guide to Steal Passwords and Crypto Wallets; N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete; XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands. 92 new CVEs in 24h. Vendor batches: MediaTek, Inc. (34), Legion of the Bouncy Castle Inc. (31), better-auth (3), ArcadeData (3)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Sunday, August 2, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-02/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-02/</guid>
    <pubDate>Sun, 02 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware; Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies; Windows 11 Gets More Taskbar Control and AI Integration as Microsoft Details Quality Progress; Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction; Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined. 176 new CVEs in 24h. Vendor batches: WordPress (92), FreeRDP (17), better-auth (14), Apple (12), gitpython-developers (5)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Saturday, August 1, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-08-01/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-08-01/</guid>
    <pubDate>Sat, 01 Aug 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware; Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined; Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits; Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction; Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database. 213 new CVEs in 24h. Vendor batches: HashiCorp (48), WordPress (43), Unknown (20), Red Hat (15), pgadmin.org (6)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Friday, July 31, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-07-31/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-07-31/</guid>
    <pubDate>Fri, 31 Jul 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined; Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database; USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports; Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents; Google Earth’s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images. 293 new CVEs in 24h. Vendor batches: HashiCorp (56), WordPress (37), Unknown (25), IBM (23), Red Hat (19)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Thursday, July 30, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-07-30/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-07-30/</guid>
    <pubDate>Thu, 30 Jul 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents; Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data; The Network Has Become the Control Plane for AI Security; North Korean hackers behind major open-source supply chain attacks, Amazon says; Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310). 662 new CVEs in 24h. Vendor batches: Google (370), WordPress (43), Unknown (21), Phoenix Contact (20), Apple (13)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Wednesday, July 29, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-07-29/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-07-29/</guid>
    <pubDate>Wed, 29 Jul 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Apple’s iMessage Scanning Flagged a Video of My Friend's Dog as Nudity; MCP gets an enterprise makeover; Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here; 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack; Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass. 1 newly exploited (KEV). 300 new CVEs in 24h. Vendor batches: Apache (45), WordPress (39), IBM (31), Xen (18), Three Learning (15)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Tuesday, July 28, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-07-28/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-07-28/</guid>
    <pubDate>Tue, 28 Jul 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost; Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit; Tons of Peoples’ Claude Chats and Creations are Exposed on Google; ABB KNX Update Tool; Siemens Desigo CC. 452 new CVEs in 24h. Vendor batches: Apple (167), WordPress (45), Linux (19), Unknown (13), jfrog (11)]]></description>
  </item>
  <item>
    <title><![CDATA[Morning Brief — Monday, July 27, 2026]]></title>
    <link>https://brief.blackmesa.ca/archive/2026-07-27/</link>
    <guid isPermaLink="true">https://brief.blackmesa.ca/archive/2026-07-27/</guid>
    <pubDate>Mon, 27 Jul 2026 13:00:00 +0000</pubDate>
    <description><![CDATA[Top developments: Google goes it alone with a new cybercrime crew taxonomy. 1 newly exploited (KEV). 68 new CVEs in 24h. Vendor batches: WordPress (23), Apache (15), Linux (6), Microsoft (3)]]></description>
  </item>
  </channel>
</rss>
