ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
4 stories in the last 7 days
The latest security news, distilled by AI into sharp ~100-word summaries. ByteBrief tracks security across dozens of tech sources and brings you only what matters, updated hourly. Tap any story for the full brief, or open the original source.
An attacker stole $23.75 million from Ostium's liquidity provider vault by compromising off-chain price feed infrastructure. The attacker submitted fake price reports and opened large positions to generate artificial profits. Trader collateral and existing positions were not affected. Trading remains paused.
Attackers are exploiting two WordPress vulnerabilities chained together for pre-authentication remote code execution. Security researchers reproduced CVE-2026-63030 within minutes of disclosure. The bugs were likely reproduced with AI assistance, according to watchTowr principal security researcher Jake Knott.
A Linux kernel 0-day in the red network scheduler turns a limited slab use-after-free into physical memory read/write. The bug, introduced in commit 3f14b37 (January 2024) and fixed in commit a8a0289 (June 2026), affects Red Hat systems with unprivileged user namespaces enabled. The missing TC_ACT_CONSUMED case in tcf_qevent_handle allows a dangling pointer write via fragmented packets.

Apple is rolling out a sixth release candidate for macOS Sonoma 14.8.8 and macOS Sequoia 15.7.8. The updates likely include important security fixes, following Apple's recent release of iOS, iPadOS, and macOS 26.5.2 with fixes originally planned for version 26.6 due to risks from new AI-powered tools.
Summaries by ByteBrief