// 3 CRITICAL · 6 ZERO-DAY · 11 CVE · 7 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECZERO-DAY

ZDI-26-393: Stack Buffer Overflow in X.Org Server XKB Subsystem Enables Local Root Escalation

The Zero Day Initiative disclosed ZDI-26-393 on June 24, 2026, detailing a local privilege escalation vulnerability in X.Org Server. A…

Jun 28, 2026views - 1.4k

aiCVE

CVE-2026-12957: Cloud Credential Theft via Amazon Q Developer

A high-severity vulnerability (CVSS 8.5) in the Amazon Q Developer extension for VS Code allowed automatic execution of malicious MCP…

Jun 27, 2026views - 1.4k

CYBERSEC

SBU and FBI Expose Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts

Ukraine's SBU and the FBI disclosed a long-running Russian operation that uses morning-timed SMS phishing to steal verification codes…

Jun 27, 2026views - 1.4k

cloud

Unit 42 Uncovers Universal Bucket Hijacking Across Multiple Clouds

Unit 42/Palo Alto Networks research: globally unique bucket names in Google Cloud, AWS, and Azure allow data-flow hijacking without co…

Jun 27, 2026views - 1.3k

linux

Masquerading Linux: When ps Lies and eBPF Exposes the Truth

A SANS ISC post demonstrates how prctl and argv overwriting make ps and top unreliable on Linux, and why only eBPF tools like Kunai ca…

Jun 27, 2026views - 1.5k

CYBERSEC

Klue Supply Chain Compromised, Icarus Hacked, Data in Circulation

The Klue-Salesforce supply chain breach now spans roughly two dozen confirmed victims. The extortion group Icarus, which claimed respo…

Jun 27, 2026views - 1.6k

CYBERSECEXPLOIT

Miasma: The Malware Turning npm Into a Developer Trap

Miasma compromised 109 npm packages and GitHub Actions using Phantom Gyp and the Bun runtime. It extracts CI/CD secrets from memory an…

Jun 26, 2026views - 1.7k

web3

Polymarket Loses $3M in Frontend Supply-Chain Attack

On June 25, 2026, Polymarket lost roughly $3 million after a third-party vendor compromise injected malicious JavaScript into its fron…

Jun 26, 2026views - 1.9k

CYBERSEC

SharkLoader: The Malware That Bypasses Loader Lock to Hide Cobalt Strike

Kaspersky has identified SharkLoader, a new loader that exploits Perfect DLL Hijacking to bypass Windows Loader Lock and deploy Cobalt…

Jun 26, 2026views - 1.5k

CYBERSEC

CL-STA-1062: From Taiwanese Web Hosting to Power Plants with TinyRCT Backdoor

Unit 42 reveals CL-STA-1062's escalation: from web hosting to state energy infrastructure in Southeast Asia with a custom .NET backdoo…

Jun 26, 2026views - 1k

CYBERSEC

Turla's STOCKSTAY Backdoor Has Targeted Ukraine Since 2022

Google Threat Intelligence Group disclosed STOCKSTAY, a multi-component backdoor from the Turla APT active since December 2022 against…

Jun 26, 2026views - 1.1k

linuxCVE

CVE-2026-46331: Linux 'pedit COW' Exploit Gains Root in 24 Hours

A Linux kernel bug corrupts the page cache of setuid binaries such as /bin/su without touching disk, bypassing all integrity checks.

Jun 26, 2026views - 1.2k

VULNEXPLOIT

DirtyClone: The Fourth Variant in the DirtyFrag Family

CVE-2026-43503, the fourth variant in the DirtyFrag family, exploits cloned packets to corrupt file-backed memory. JFrog published a f…

Jun 26, 2026views - 951

CYBERSEC

Linux Foundation Launches Akrites: A Shared SIRT for Open Source Software

Akrites brings 19 tech giants under one shared SIRT for open source vulnerabilities. A 5% patch rate and Dolan's admission: the road a…

Jun 26, 2026views - 1.2k

VULNCRITICAL

Synology MailPlus: Three Critical CVEs, 2,100+ Servers Exposed

Synology released MailPlus Server 4.0.1-31663 to fix three critical vulnerabilities enabling arbitrary file read/write and internal se…

Jun 26, 2026views - 768

CYBERSECCRITICAL

PTC Windchill: First In-the-Wild Exploitation of a PLM System

CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

Jun 26, 2026views - 1.1k

CYBERSEC

Burnyard: Local Malware Analysis Beats Cloud on Speed, But Accuracy Remains Unverified

Ohio State University's Burnyard project challenges VirusTotal and Sophos Intelix with user-space emulation on local hardware, deliver…

Jun 26, 2026views - 843

CYBERSEC

Ex-Huntress Analyst Accuses Company of Covering Up Insider Who Allegedly Fed FBI Data to DevMan Ransomware Gang

A former SOC analyst claims Huntress concealed an insider who passed U.S. law enforcement communications to the DevMan ransomware grou…

Jun 26, 2026views - 795

phishing

Shopify's Shop App Abused for Callback Phishing, 50 Million Users at Risk

Fake invoices with phone numbers are being injected into the Shopify Shop app. Researchers say the insertion mechanism remains unknown…

Jun 25, 2026views - 759

CYBERSEC

Beyond IOCs: Talos Unveils Vision for LLMs in Threat Intelligence

Cisco Talos explores how large language models transcend traditional indicators of compromise by indexing strategic reports in natural…

Jun 25, 2026views - 1.2k

ransomware

Ransomware: Europe Overtakes US as Top Target With 55% Surge in Attacks

Black Kite's first Europe-focused report reveals 684 ransomware attacks in the first four months of 2026, a 55.1% year-over-year incre…

Jun 25, 2026views - 1.4k

CYBERSEC

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack

Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

Jun 25, 2026views - 759

CYBERSEC

ThreatsDay June 2026: Miasma Toolkit Leaked, Claude Code Patched, AI Agent Phishing

The June 2026 ThreatsDay Bulletin, published June 11 by Rescana, is an aggregated cyber threat digest. This analysis relies primarily…

Jun 25, 2026views - 1k

malware

Gaslight: macOS Malware Tricks AI Analyzers with Prompt Injection

SentinelOne researchers have documented Gaslight, a previously unknown Rust-based macOS implant that embeds a prompt-injection payload…

Jun 25, 2026views - 768