// 2 CRITICAL · 4 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
nvidiaCRITICAL

NVIDIA TensorRT: ONNX Parsing Flaw Enables RCE with CVSS 7.8

CVE-2026-24268 strikes the ONNX parser in NVIDIA TensorRT. A heap-based buffer overflow with CVSS 7.8, minimal user interaction, and a…

Aug 25, 2026views - 994

bluetoothCRITICAL

BlueZ: A2DP Buffer Overflow Enables Root RCE After Pairing

ZDI-26-589 discloses a stack-based buffer overflow in the BlueZ Bluetooth stack's A2DP module, allowing remote code execution as root…

Aug 25, 2026views - 1.2k

CYBERSECCRITICAL

libwebsockets: RCE via HTTP/2 HPACK, Single-Line Patch Available

ZDI-26-590 discloses an unauthenticated remote code execution vulnerability in libwebsockets. A missing bounds check in the HTTP/2 HPA…

Aug 24, 2026views - 1k

CYBERSECZERO-DAY

Windows Compatibility Appraiser: LPE Bug Escalates from LOCAL SERVICE to SYSTEM

ZDI-26-606 discloses a local privilege escalation vulnerability in the Microsoft Windows Compatibility Appraiser. Symbolic link manipu…

Aug 24, 2026views - 1.1k

VULNCRITICAL

Home Assistant Green: Root RCE via Localhost Exploit Disclosed by ZDI

ZDI-26-561 reveals a command injection in the Home Assistant Green go2rtc process. The flaw allows arbitrary code execution as root fo…

Aug 24, 2026views - 1.2k

news

SynkLoader Revives the Fake Lock Screen: How the Malware Works

Marcus Hutchins and Expel's research team discovered and analyzed SynkLoader, a modular malware combining Python, C, C# and PowerShell…

Aug 24, 2026views - 1.1k

CYBERSECCVE

CVE-2026-65775: Microsoft Patches win32kfull UAF Discovered at Pwn2Own

Microsoft fixed CVE-2026-65775, a Use-After-Free in the Windows win32kfull driver discovered by Kentaro Kawane at Pwn2Own. The flaw en…

Aug 24, 2026views - 1.1k

VULNCVE

CVE-2026-18963: Keycloak Account Takeover in Seconds, Bypassing MFA

A critical flaw in Keycloak's password-reset flow lets an unauthenticated attacker seize any account — including admins — in roughly f…

Aug 24, 2026views - 2.9k

CYBERSEC

AMD Confirms Two TPM 2.0 Flaws: False Attestations on Ryzen from 3000 Series to AI

Two vulnerabilities in AMD's TPM 2.0 firmware jeopardize the hardware attestation chain on Ryzen processors. Patched firmware has been…

Aug 24, 2026views - 1.1k

CYBERSECZERO-DAY

ShinyHunters Hits 100+ Universities with Oracle Zero-Day CVSS 9.8

The ShinyHunters group exploited CVE-2026-35273, an unauthenticated RCE in Oracle PeopleSoft, against more than 100 organizations befo…

Aug 24, 2026views - 2.3k

CYBERSECCVE

CVE-2026-18294: RCE in OriginLab Origin Viewer via Malformed OGW File

The CVE-2026-18294 vulnerability in OriginLab Origin Viewer's OGW parser enables remote code execution with a CVSS 7.8 score. Exploita…

Aug 24, 2026views - 1.1k

CYBERSEC

Parallels RAS Client: Local Vulnerability Allows Escalation to SYSTEM

CVE-2026-18263 affects the RAS RDP Backend Service with a CVSS 7.8 score. An exposed dangerous function allows low-privilege code to e…

Aug 24, 2026views - 1k

CYBERSECEXPLOIT

TeamPCP Exploits AI Supply Chain to Steal One Terabyte of Credentials

The TeamPCP campaign compromised GitHub Actions and PyPI packages between March and April 2026. Over 2,500 organizations potentially e…

Aug 24, 2026views - 1.2k

zeroZERO-DAY

Exploitarium: The 'Recruitment by Chaos' That Shatters the CVD Model

Pseudonymous researcher 'bikini' dumped over 30 zero-day PoC exploits on GitHub on June 27, 2026, without any vendor coordination. CVE…

Aug 24, 2026views - 1.1k

ransomwareADVISORY

Medusa Tops 500 Victims: CISA Updates Advisory on 24-Hour Exploit Window

CISA, FBI, and HHS updated advisory AA25-071A on August 18, 2026, documenting over 500 Medusa ransomware victims since June 2021, with…

Aug 24, 2026views - 1.3k

CYBERSECCVE

CISA Adds CVE-2025-62593 to KEV Catalog: Ray at Risk of RCE

CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, 2026. The critical flaw in the Ray framework ex…

Aug 24, 2026views - 1.1k

news

Iran Targets Exposed PLCs: U.S. Intrusions Confirmed, U.K. Case Unverified

The FBI, CISA, and six other U.S. federal agencies confirmed on July 22, 2026, that Iranian actors have compromised internet-exposed p…

Aug 24, 2026views - 1.1k

CYBERSEC

SilkParasite Exposes the Line Between AI-Assisted and AI-Generated Malware

Bitdefender uncovered SilkParasite, a cyber-espionage campaign using seven RAT families and AI-assisted development to target governme…

Aug 24, 2026views - 1.1k

supply

Trivy and LiteLLM Compromised: 2,100+ Organizations Exposed via Security Tools

TeamPCP compromised the CI/CD pipelines of Trivy and LiteLLM between March 19 and March 24, 2026. Six confirmed breaches hit European…

Aug 23, 2026views - 1.1k

CYBERSECCRITICAL

The Blackout That Wasn't: When PLC Doubt Shuts Down a Power Plant

An alleged four-day shutdown at an unnamed UK power plant remains officially unconfirmed as of August 23, 2026. The original source, d…

Aug 23, 2026views - 1k

VULNCVE

CVE-2026-4342: A Five-Day Window, Technical Debt With No Exit

The ingress-nginx vulnerability CVE-2026-4342 (CVSS 8.8) was patched in March 2026 but remains unapplied in thousands of clusters. The…

Aug 23, 2026views - 1.2k

CYBERSECCRITICAL

Threat Actors Use AI to Attack Siemens PLCs in Critical Infrastructure

U.S. federal agencies warn that AI-generated exploit scripts are actively targeting internet-exposed Siemens S7 PLCs. No OT expertise…

Aug 23, 2026views - 1.1k

newsCVE

CVE-2026-58231: Active Exploits Hit SAP Commerce Cloud Three Days After Patch

Exploit attempts detected on August 14 against CVE-2026-58231, a CVSS 10.0 vulnerability in SAP Commerce Cloud. The race to reverse-en…

Aug 23, 2026views - 1.2k

CYBERSEC

Noodlophile Stealer: Malware Rides the AI Hype Wave Through Fake Video-Generation Platforms

Threat actors are distributing the previously undocumented Noodlophile Stealer via bogus AI video-generation sites, luring victims to…

Aug 23, 2026views - 1.2k