You're subscribed.
Your first issue of The it-learn Brief will land in your inbox on the next weekday morning.
Every issue includes breaking CVEs, MITRE ATT&CK-mapped deep dives, copy-paste detection queries, and specific defender action items — the technical depth that keeps you sharp in customer conversations and on the job.
📬 Catch up on the latest briefs
700 AI Agents Swarmed Hugging Face — Agent Identity Is
700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.
ServiceNow CVSS 10 Trio — RCE and SQLi in the Wild
Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.
FBI Dismantles QTFY — Chinese Spy Proxy Hit the Fed
FBI takes down QTFY Chinese state proxy that breached Federal Reserve and DOJ. CVE-2026-8452 NetScaler exploited in the wild.
270+ Zimbra Servers Breached — CVE-2026-73570
CVE-2026-73570 breaches 270+ Zimbra servers; CISA flags 100+ water systems targeted via exposed OT; Gitea RCE CVE-2026-60004 hits KEV.
Snowflake Kills Service-Account Passwords — CVE-2026-18963
Snowflake forces NHI migration exposing ownership gaps. Keycloak CVE-2026-18963 CVSS 9.1 RCE. NVIDIA NemoClaw AI agent model poisoning via webpage.