Zero Days, Breaches, and LockBit Fallout

Charm · October 7, 2026 · 1 min read · 5 sources

News

Mozilla Foundation Confirms Breach, Source Code and Data Stolen

Mozilla Foundation email servers got popped by an unknown attacker who stole source code and internal data. If the org maintaining Firefox and open source infrastructure gets hit, it should make you re-evaluate your own posture.

FreeType Zero-Day Under Active Attack Allows Code Execution

Azero-Day (CVE-2025-27363) in FreeType is under active exploitation, allowing code execution via malicious font files. If your stack uses this widely deployed library (Android, Linux, etc.), you are exposed.

Lazarus Group Uses TraderTraitor Attack on Bybit Exchange

The Lazarus Group is linked to a $1.5B hack of the Bybit exchange, using the new 'TraderTraitor' toolkit. This isn't just about crypto; it shows state actors are combining social engineering with highly technical supply chain attacks at scale.

LockBit Ransomware Gang Leaks Internal Chat Logs

The LockBit ransomware gang is leaking internal chat logs after their admin was allegedly doxxed. If you're in threat intel or defense, these logs provide a rare inside look at their TTPs and the dark web drama surrounding them.

Tools

SAP NetWeaver RCE (10.0 CVSS) PoC Available After Active Exploitation

New PoC exploit dropped for CVE-2025-31324, the critical command injection flaw in SAP NetWeaver (CVSS 10.0). This is a priority patch for anyone running SAP systems; the implementation details are now public.

Stay Ahead

Delivered each morning.