// 3 CRITICAL · 6 ZERO-DAY · 11 CVE · 7 EXPLOIT · 1 ADVISORY IN THE LAST 24H
ransomware

Europe Overtakes US: 684 Ransomware Attacks in Four Months

Europe has become the fastest-growing ransomware region in 2026, logging 684 publicly known attacks in the first four months — a 55% y…

Jun 25, 2026views - 1k

CYBERSECCVE

Adobe Reader: Patch Now for CVE-2026-27278, RCE via PDF

Adobe has released APSB26-26 for CVE-2026-27278, a Use-After-Free vulnerability in Acrobat Reader DC that enables remote code executio…

Jun 25, 2026views - 1.1k

malware

Edgecution: Malicious Edge Extension Bypasses Sandbox via Native Messaging

Zscaler ThreatLabz documents a campaign where the Edgecution extension abuses Chrome's Native Messaging API to escape the browser sand…

Jun 25, 2026views - 1.2k

CYBERSECCRITICAL

FlowiseAI CSV Agent RCE: Arbitrary Python Code Execution with Authentication Bypass

ZDI-26-365 discloses a remote code execution vulnerability in FlowiseAI's CSV Agent: Python code injection via customReadCSV with auth…

Jun 25, 2026views - 1.3k

CYBERSECCRITICAL

Docker MCP Plugin: RCE via OCI Label, Urgent Patch

ZDI-26-363: The YAML label io.docker.server.metadata in the Docker MCP Gateway enables remote code execution as root. The fix isolates…

Jun 25, 2026views - 1k

CYBERSECCRITICAL

ZDI-26-376: RCE in Quest NetVault Backup with Authentication Bypass

Command injection in NVBULogDaemon enables remote code execution as SYSTEM. Patch available but no CVE or CVSS assigned.

Jun 25, 2026views - 790

VULNCVE

CVE-2026-9779: RCE in ATEN Unizon via Flawed Cryptographic Signature Check

The ZDI-26-383 vulnerability enables remote code execution with SYSTEM privileges by exploiting a signature verification error in ATEN…

Jun 25, 2026views - 797

CYBERSECZERO-DAY

Fuji Electric Tellus: Kernel Driver Bug Enables SYSTEM Privilege Escalation

CVE-2026-8108 in the Fuji Electric Tellus pcid64 driver allows local privilege escalation to SYSTEM via Registry APIs with excessive p…

Jun 24, 2026views - 904

CYBERSECCRITICAL

Unraid: Command Injection in ToggleState.php Enables RCE

CVE-2026-9773 in the Unraid web server: command injection in ToggleState.php allows authenticated remote code execution. CVSS 8.8, fix…

Jun 24, 2026views - 756

newsZERO-DAY

Cisco SD-WAN Zero-Day Exploited for Root Access at Telecom Provider

Threat actors exploited CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to gain root-level control over a communications service provi…

Jun 24, 2026views - 970

news

Operation Endgame Dismantles 326 Amadey and StealC Servers, First RICO Case Against Dual Malware Families

An international law-enforcement and private-sector operation dismantled the shared infrastructure of the Amadey loader and StealC inf…

Jun 24, 2026views - 792

linux

Linux Process Masquerading Tricks ps and top

On Linux, malicious processes mask their name and command line by abusing prctl and argv memory overwrites. Standard tools like ps and…

Jun 24, 2026views - 850

malware

Mistic: KongTuke's In-Memory Backdoor Challenges EDR Defenses

Operational since April 2026, the stealthy Mistic backdoor leverages DLL sideloading and in-memory BOF execution for long-term persist…

Jun 24, 2026views - 1.2k

VULN

macOS: Standard Users Disable EDR/MDM Without Admin Rights

A privilege escalation technique on macOS exploits CDHash caching and NIB injection to silently disable enterprise security tools. App…

Jun 24, 2026views - 1k

ransomware

Bajaj Auto’s Silent Ransomware: What Lies Behind the ‘Successful Mitigation’ Claim

Bajaj Auto disclosed a June 23, 2026 ransomware incident without naming the threat actor, strain, or impact. The case exposes the limi…

Jun 24, 2026views - 810

CYBERSECEXPLOIT

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries

Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

Jun 24, 2026views - 1.1k

VULNCVE

Path Traversal in Allegra: CVE-2026-11442 Exposes Arbitrary Files

The ZDI-26-357 vulnerability in Allegra's exportReport method allows an authenticated remote attacker to read arbitrary files via path…

Jun 24, 2026views - 964

CYBERSEC

Railway Cybersecurity: The IT/OT Boundary Has Collapsed

Rail systems are abandoning isolated SCADA for IP networks and AI. DNV's Jorge Aldegunde explains why security is now an active interf…

Jun 24, 2026views - 1.2k

CYBERSEC

The Fake kworker: How APTs Masquerade Linux Processes

Ps and top become unreliable: APTs overwrite argv[0] and use prctl to impersonate kworker. eBPF tools like Kunai detect the real binar…

Jun 24, 2026views - 751

aiZERO-DAY

Mythos AI Finds Vulnerabilities in Classified U.S. Systems in Hours

Anthropic's Mythos model identified vulnerabilities in classified U.S. government systems during a Project Glasswing test, completing…

Jun 24, 2026views - 768

CYBERSECEXPLOIT

TTP-Chain Validation: Proving Exploitability Without an Exploit

A Picus Security engineer proposes TTP-chain validation to test CVE exploitability without live exploits, as the disclosure-to-exploit…

Jun 23, 2026views - 1.4k

CYBERSEC

LastPass Breached via Klue Supply-Chain Attack: Customer Data Stolen, Vaults Intact

LastPass confirms a supply-chain breach through market-intelligence vendor Klue: stolen OAuth tokens granted access to LastPass's Sale…

Jun 23, 2026views - 1.5k

malware

ClickFix macOS: When Users Bypass Gatekeeper Themselves

Microsoft has documented the latest evolution of ClickFix campaigns on macOS: operators have ditched manual DMG installers for Termina…

Jun 23, 2026views - 972

CYBERSECZERO-DAY

Microsoft Confirms RoguePlanet Zero-Day: Defender Becomes Attack Vector

CVE-2026-50656: Microsoft confirms zero-day vulnerability in Defender that elevates privileges to SYSTEM. Patch in development, public…

Jun 23, 2026views - 1.6k