// 2 CRITICAL · 4 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
news

Fulcrumsec Publishes Second Novo Nordisk Leak Tranche: 1.05 TB of AI Models, Datasets, and Microscopy Images

The Fulcrumsec extortion group released "Stage 2" of its attack on Novo Nordisk on August 13, 2026, publishing what it claims are 30 H…

Aug 19, 2026views - 1.3k

supply

Shai-Hulud Hits npm: 440+ Packages Compromised with Valid Provenance

The Shai-Hulud campaign has infected over 440 npm packages with 2+ billion monthly downloads. The worm exploits signed GitHub Actions…

Aug 19, 2026views - 1.2k

newsZERO-DAY

Nightmare Eclipse Drops ShieldBreak: Windows Defender Zero-Day With No Warning

Security researcher Nightmare Eclipse published details of ShieldBreak on August 12, 2026 — a zero-day in Windows Defender that enable…

Aug 19, 2026views - 1.2k

VULNZERO-DAY

Copy Fail: The 732-Byte Linux Kernel Bug That Slept Since 2017

An unprivileged local user gains root deterministically. The exploit weighs 732 bytes. The bug had been in the kernel since 2017. This…

Aug 19, 2026views - 1.2k

news

Red Hat ACM: Namespace Edit Privilege Escalates to Cluster-Admin via Confused Deputy Flaw

On August 5, 2026, Red Hat published advisory CVE-2026-10090 detailing a vulnerability in the Advanced Cluster Management for Kubernet…

Aug 18, 2026views - 1.2k

CYBERSEC

Interrupt Injection: MIT Attack Bypasses Spectre v2 Defenses on Intel and AMD

MIT CSAIL researchers Daniël Trujillo and Mengjia Yan presented the Interrupt Injection technique at Black Hat USA 2026, demonstrating…

Aug 18, 2026views - 1.2k

news

Home Assistant Green: SSRF via SSDP Disclosed at Pwn2Own

ZDI advisory ZDI-26-563 documents a Server-Side Request Forgery vulnerability in the SSDP implementation of Home Assistant Green. The…

Aug 18, 2026views - 1.2k

VULNZERO-DAY

Apple Patches Decade-Old iOS Zero-Day: dyld Exposed to Commercial Spyware

Apple has fixed CVE-2026-20700, a vulnerability in dyld present for over a decade and exploited in targeted attacks. The exploit chain…

Aug 18, 2026views - 1.5k

CYBERSEC

Underground Markets Sell AI Tools to Orchestrate Ransomware Without Expertise

Trellix researchers have uncovered LLM-powered hacking tools for sale on underground forums that dramatically lower the technical barr…

Aug 18, 2026views - 1.2k

CYBERSECEXPLOIT

Unisoc VoLTE Video-Call Exploit Chain Reaches Android Kernel — No Patch, No CVE

SSD Secure Disclosure details a two-stage exploit chain on Unisoc chipsets that starts with a malicious VoLTE video call and ends with…

Aug 18, 2026views - 1.1k

CYBERSECCVE

Minnesota Under Attack: The Unpatchable CVE-2021-22681 Flaw

A coordinated cyberattack on July 26–27, 2026 struck more than 30 Minnesota water systems. The offensive exploited internet-exposed Ro…

Aug 18, 2026views - 1.2k

cybersec

DGFiP Data Breach Exposes 678,000 French Taxpayers; CNIL Weighs Enforcement

The French Finance Ministry confirmed on August 17, 2026, that the DGFiP suffered a breach exposing sensitive tax data for 678,000 ind…

Aug 18, 2026views - 1.2k

VULN

Parallels RAS Client: LPE to SYSTEM After 168 Days of Waiting

ZDI-26-556 reveals an exposed dangerous function in the RAS RDP Backend Service. Local escalation to SYSTEM after 168 days of coordina…

Aug 18, 2026views - 1.1k

newsEXPLOIT

FBI and CISA: Gunra Expands RaaS with Fortinet Exploits and MFA Bypass

On August 10, 2026, the FBI, CISA, NSA, Secret Service, DC3, and South Korea's KNPA released joint advisory AA26-222A on Gunra, a rans…

Aug 18, 2026views - 1.2k

malware

Lumma Stealer Hides in Pirated 'The Odyssey' Downloads: The Hidden Extension Trick

Cybercriminals are distributing Lumma Stealer via Windows executables disguised as pirated copies of The Odyssey (2026) on torrent tra…

Aug 18, 2026views - 1.1k

VULNCVE

CVE-2026-19478: GitLab Patches Critical GraphQL Flaw CVSS 9.4 for Self-Managed Instances

GitLab issued an out-of-cycle patch on August 17, 2026 for CVE-2026-19478, a GraphQL vulnerability rated CVSS 9.4 that allows an unaut…

Aug 18, 2026views - 1.1k

news

Check Point: Global Attacks Near 2,000 Per Week as AI Rewrites the Kill Chain

Global cyberattacks averaged 1,968 per week in 2025, a 70% jump from 2023, according to Check Point's Cyber Security Report 2026 relea…

Aug 18, 2026views - 1.2k

CYBERSEC

RingCentral Breach Exposes 1.6 Million Records via Vishing Call

ShinyHunters compromised RingCentral with a single phone call, exposing 1.6 million records and leaking 280 GB of data. The real-time…

Aug 18, 2026views - 1.2k

linuxEXPLOIT

GhostLock: Public Exploit Grants Root in 5 Seconds on Linux Since 2011

CVE-2026-43499 has existed in the Linux kernel for 15 years. The public proof-of-concept requires only a local user to obtain root in…

Aug 17, 2026views - 1.2k

CYBERSEC

Copilot Autofix Introduces Vulnerability in Snowflake CI/CD, Then an AI Agent Finds It

GitHub Copilot Autofix introduced a script injection flaw into a Snowflake GitHub Actions workflow. Five days later, Wiz's autonomous…

Aug 17, 2026views - 1.2k

CYBERSEC

Trump Authorizes Private Cyber Offensives: The New NSPM of August 12, 2026

On August 12, 2026, Trump signed an NSPM authorizing vetted private companies to conduct offensive cyber operations against transnatio…

Aug 17, 2026views - 1.2k

CYBERSEC

Passkey Bypass: Three Attacks Demolish Phishing-Resistant Authentication

Three independent studies published in August 2026 demonstrate post-compromise attack chains that bypass passkey-based phishing-resist…

Aug 17, 2026views - 1.9k

VULN

AMD Confirms Two High-Severity TPM 2.0 Flaws in Ryzen: Fixes Were Circulating Since May 2026

AMD published advisory AMD-SB-7064 on August 11, 2026, disclosing two high-severity TPM 2.0 vulnerabilities (CVE-2026-6726 and CVE-202…

Aug 17, 2026views - 1.1k

CYBERSECEXPLOIT

Evooo1Bot: The Botnet Turning Routers and Edge Devices into SOCKS5 Proxies

Fortinet discovers Evooo1Bot, a modular Mirai-based Linux botnet active since July 2026 that exploits 10 known CVEs to build a distrib…

Aug 17, 2026views - 1.2k