// 3 CRITICAL · 5 ZERO-DAY · 10 CVE · 6 EXPLOIT · 1 ADVISORY IN THE LAST 24H
microsoftZERO-DAY

Microsoft July 2026 Patch Tuesday: Record Vulnerability Volume Forces a Reckoning

Microsoft's July 2026 Patch Tuesday delivers a record-breaking number of vulnerabilities. Two zero-days are already under active explo…

Jul 14, 2026views - 1.4k

CYBERSECZERO-DAY

SonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough

SonicWall patched two zero-days under active exploitation in SMA 1000 Series appliances, but the vendor mandates full re-imaging or re…

Jul 14, 2026views - 1.3k

newsCRITICAL

Progress Orders ShareFile Shutdown: Third Critical Incident in Three Years

Progress Software confirmed a high-severity zero-day in the ShareFile Storage Zone Controller that forced an emergency shutdown order…

Jul 14, 2026views - 1.5k

CYBERSEC

Microsoft Revokes 11 Legacy UEFI Shims: Secure Boot Bypassed via Signed Bootloaders

Eleven Microsoft-signed UEFI shim bootloaders allowed Secure Boot bypass on any trusting system. Revocation arrived with the June 2026…

Jul 14, 2026views - 1.6k

CYBERSECZERO-DAY

SharePoint JWT Bypass and the AI Agent That Rewrites Zero-Day Discovery

Microsoft patched a SharePoint authentication bypass (CVE-2026-55040) discovered by Rapid7 using agentic AI. The CVSS 5.3 rating masks…

Jul 14, 2026views - 1.4k

vpn

US Sanctions First VPN Provider: Anonymity as Criminal Infrastructure

The Treasury Department sanctions First VPN Service and its Ukrainian administrator for supporting ransomware groups. It marks the fir…

Jul 14, 2026views - 1.8k

CYBERSECZERO-DAY

FortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day

FortiBleed hits already-patched FortiGate devices: credentials stolen in prior incidents enable administrative access without exploiti…

Jul 14, 2026views - 1.4k

CYBERSEC

Security Vendor Jscrambler Becomes Supply-Chain Vector: 5 Malicious npm Versions

Threat actors compromised Jscrambler's npm publishing credentials and released five malicious versions of the jscrambler package conta…

Jul 13, 2026views - 1.3k

news

CrashStealer: The macOS Malware That Fooled Apple Itself

CrashStealer, a native C++ macOS infostealer, was distributed via a dropper signed and notarized by Apple, bypassing Gatekeeper checks…

Jul 13, 2026views - 1.4k

CYBERSECZERO-DAY

CISA Adds Two Joomla Zero-Days to KEV Catalog: Deadline July 13

On July 10, 2026, CISA added two actively exploited zero-day vulnerabilities in Joomla extensions to its Known Exploited Vulnerabiliti…

Jul 13, 2026views - 1.4k

malware

RedHook RAT: Android Malware Gains Shell Access Without Root or PC

The RedHook trojan upgrades its arsenal by abusing Wireless ADB, Shizuku, and Accessibility Service to obtain shell privileges on non-…

Jul 12, 2026views - 1.4k

newsZERO-DAY

AnyDesk 0Day ZDI-26-401: No Patch After 15 Months, DoS Remains Active

Trend Micro's Zero Day Initiative disclosed ZDI-26-401, a zero-day vulnerability in AnyDesk enabling local denial-of-service via NTFS…

Jul 12, 2026views - 1.3k

CYBERSECZERO-DAY

ZDI Publishes 0-Day in Glary Utilities: LPE via Junction, No Patch

Trend Micro's Zero Day Initiative has disclosed ZDI-26-402, a local privilege escalation vulnerability in Glarysoft Glary Utilities. T…

Jul 12, 2026views - 1.3k

newsCRITICAL

BeyondTrust Patches Four Critical Flaws: The AI That Finds Bugs Risks Becoming the Weapon That Exploits Them

BeyondTrust released patches on July 7, 2026 for four vulnerabilities in Remote Support and Privileged Remote Access. Two carry CVSS 9…

Jul 11, 2026views - 1.3k

exploitEXPLOIT

Metasploit Arms FlowiseAI and macOS: Two Exploits Land in the Framework

Metasploit has merged exploit modules for CVE-2026-41264, an unauthenticated RCE in FlowiseAI's CSV Agent, and CVE-2024-27822, a local…

Jul 11, 2026views - 1.3k

cveCRITICAL

Adobe ColdFusion: 10 Critical CVEs With In-the-Wild RCE, Forced Update

Adobe patched 10 ColdFusion vulnerabilities, including CVE-2026-48282 with a CVSS 10.0 score and confirmed exploitation. The legacy RD…

Jul 11, 2026views - 1.3k

ransomware

The Gentlemen Climbs RaaS Rankings: 90% Payout and 580 Victims in One Year

The Gentlemen, tracked as Storm-2697, has become the second most active RaaS operation of 2026 with over 6x growth and a 90% affiliate…

Jul 10, 2026views - 1.5k

ransomware

GodDamn Ransomware Uses Microsoft-Signed Driver to Disable EDR

The GodDamn ransomware, a rebrand of the Hyadina family, leverages the PoisonX driver — signed with a valid Microsoft Windows Hardware…

Jul 10, 2026views - 1.1k

aiCRITICAL

Friendly Fire: Defensive AI Agents Turn into RCE Attack Vectors

The AI Now Institute's Friendly Fire report, published July 8, 2026, demonstrates that Anthropic's Claude Code and OpenAI's Codex — to…

Jul 10, 2026views - 1.4k

news

Security AI Agents Turned Into Attack Vectors: The Report That Stops You Cold

The Friendly Fire report published by the AI Now Institute on July 8, 2026 proves that Anthropic's Claude Code and OpenAI's Codex CLI…

Jul 10, 2026views - 1.3k

CYBERSECCRITICAL

Zimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG

Zimbra released ZCS 10.1.19 on July 7, 2026 to fix a stored cross-site scripting vulnerability in the Classic Web Client reported by G…

Jul 10, 2026views - 987

blockchain

Ill Bloom: 431 Wallets Drained for $3.1M via Insecure PRNG

The Ill Bloom vulnerability exposed 2,114 crypto addresses due to weak pseudorandom number generators. No patch exists: the only defen…

Jul 10, 2026views - 1.7k

CYBERSECEXPLOIT

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America

Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…

Jul 10, 2026views - 1.3k

malware

Operation Muck and Load: 222 GitHub Repositories Weaponized to Distribute Windows Malware

A threat actor built a network of 222 GitHub repositories across 190 accounts to distribute Windows malware via malicious Go modules.…

Jul 10, 2026views - 1.8k