// 1 CRITICAL · 3 ZERO-DAY · 6 CVE · 4 EXPLOIT IN THE LAST 24H
VULNZERO-DAY

Trend Micro VPN: Local Privilege Escalation Flaw Allows SYSTEM Takeover

A local privilege escalation vulnerability in Trend Micro VPN, tracked as ZDI-26-577 and CVE-2026-67212, lets an attacker with low-pri…

Aug 20, 2026views - 976

CYBERSECCRITICAL

NGINX DAV: Pre-Auth RCE Discovered by Calif.io in Collaboration with

CVE-2026-27654 in the NGINX HTTP DAV module: an integer underflow triggered by an alias in a prefix location enables unauthenticated r…

Aug 20, 2026views - 950

VULN

Notepad++: Institutional Alert Arrives Four Months After the Fix

Singapore's Cyber Security Agency published an advisory on CVE-2026-3008, a string injection flaw in Notepad++ 8.9.3 with a CVSS 6.6 s…

Aug 20, 2026views - 1.1k

ransomware

Ransom Busters: The Double-Cross Undermining the RaaS Model From Within

A ransomware affiliate operates as a fake recovery firm, contacting victims before attacks are published. GuidePoint Security GRIT doc…

Aug 19, 2026views - 1.1k

CYBERSECCVE

Cisco ISE: Patch Available for Directory Traversal CVE-2026-20148

A path traversal vulnerability in Cisco Identity Services Engine allows an authenticated remote attacker to read arbitrary files. A pa…

Aug 19, 2026views - 1.1k

CYBERSECCRITICAL

Private APN Emerges as New OT Attack Vector: Polish Cogeneration Plant Compromised

CERT Polska has documented the first real-world case of a private APN being used as an attack vector against operational technology. A…

Aug 19, 2026views - 1.1k

ransomware

Akira in Safe Mode: Blind EDR and the Ransomware That Collapsed From Memory Starvation

An Akira affiliate disabled EDR by forcing a reboot into Safe Mode with Networking, but the ransomware payload crashed with "Out of Vi…

Aug 19, 2026views - 1.1k

ai

TeamPCP/UNC6780: Six Enterprise Breaches From Trivy to LiteLLM

The TeamPCP/UNC6780 campaign compromised Trivy to poison LiteLLM on PyPI. According to Hudson Rock, six enterprise breaches resulted w…

Aug 19, 2026views - 1.2k

CYBERSECEXPLOIT

Digital Garbage Hits the Cloud Core: Indiscriminate Scanning

SANS Dean of Research Johannes Ullrich documented widespread, untargeted scanning against the Cloud Metadata Service address 169.254.1…

Aug 19, 2026views - 1.1k

CYBERSECZERO-DAY

SharePoint On-Prem Under Attack: Rapid7 PoC Weaponized Within 24 Hours

Threat actors are actively exploiting CVE-2026-55040 on Microsoft SharePoint on-premises servers using Rapid7's proof-of-concept code.…

Aug 19, 2026views - 1.1k

CYBERSECZERO-DAY

GeoServer Zero-Day Under Fire: Hundreds of Exploit Attempts in Hours, Patches Released

A zero-day SQL injection in GeoServer was massively probed within hours of disclosure. The flaw is a regression of a 2023 vulnerabilit…

Aug 19, 2026views - 1.1k

cybersec

DecryptAds Exposes the Invisible: The Ad Supply Chain Under the Microscope

DecryptAds parses ads.txt and sellers.json files, revealing hidden links between mainstream sites, data brokers, and geopolitical acto…

Aug 19, 2026views - 1k

CYBERSEC

UNC6671: Personal Phones Become the Gateway to Steal SaaS Data

The UNC6671 group uses vishing on personal smartphones to bypass MFA and steal SaaS sessions. Google has tracked over $10 million in e…

Aug 19, 2026views - 1.1k

CYBERSEC

NFV and 5G: The Paradox of European Digital Sovereignty

An intelligence report highlights systemic privilege-escalation vectors in European 5G SA networks. The MANO orchestration plane has b…

Aug 19, 2026views - 1.1k

news

Fulcrumsec Publishes Second Novo Nordisk Leak Tranche: 1.05 TB of AI Models, Datasets, and Microscopy Images

The Fulcrumsec extortion group released "Stage 2" of its attack on Novo Nordisk on August 13, 2026, publishing what it claims are 30 H…

Aug 19, 2026views - 1.1k

supply

Shai-Hulud Hits npm: 440+ Packages Compromised with Valid Provenance

The Shai-Hulud campaign has infected over 440 npm packages with 2+ billion monthly downloads. The worm exploits signed GitHub Actions…

Aug 19, 2026views - 1k

newsZERO-DAY

Nightmare Eclipse Drops ShieldBreak: Windows Defender Zero-Day With No Warning

Security researcher Nightmare Eclipse published details of ShieldBreak on August 12, 2026 — a zero-day in Windows Defender that enable…

Aug 19, 2026views - 1.1k

VULNZERO-DAY

Copy Fail: The 732-Byte Linux Kernel Bug That Slept Since 2017

An unprivileged local user gains root deterministically. The exploit weighs 732 bytes. The bug had been in the kernel since 2017. This…

Aug 19, 2026views - 1.1k

news

Red Hat ACM: Namespace Edit Privilege Escalates to Cluster-Admin via Confused Deputy Flaw

On August 5, 2026, Red Hat published advisory CVE-2026-10090 detailing a vulnerability in the Advanced Cluster Management for Kubernet…

Aug 18, 2026views - 1.1k

CYBERSEC

Interrupt Injection: MIT Attack Bypasses Spectre v2 Defenses on Intel and AMD

MIT CSAIL researchers Daniël Trujillo and Mengjia Yan presented the Interrupt Injection technique at Black Hat USA 2026, demonstrating…

Aug 18, 2026views - 1.1k

news

Home Assistant Green: SSRF via SSDP Disclosed at Pwn2Own

ZDI advisory ZDI-26-563 documents a Server-Side Request Forgery vulnerability in the SSDP implementation of Home Assistant Green. The…

Aug 18, 2026views - 1.1k

VULNZERO-DAY

Apple Patches Decade-Old iOS Zero-Day: dyld Exposed to Commercial Spyware

Apple has fixed CVE-2026-20700, a vulnerability in dyld present for over a decade and exploited in targeted attacks. The exploit chain…

Aug 18, 2026views - 1.3k

CYBERSEC

Underground Markets Sell AI Tools to Orchestrate Ransomware Without Expertise

Trellix researchers have uncovered LLM-powered hacking tools for sale on underground forums that dramatically lower the technical barr…

Aug 18, 2026views - 1.1k

CYBERSECEXPLOIT

Unisoc VoLTE Video-Call Exploit Chain Reaches Android Kernel — No Patch, No CVE

SSD Secure Disclosure details a two-stage exploit chain on Unisoc chipsets that starts with a malicious VoLTE video call and ends with…

Aug 18, 2026views - 1k