// 2 CRITICAL · 4 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
VULNZERO-DAY

ZDI-26-573: Pre-Auth Linux Kernel KSMBD Vulnerability Scores CVSS 9.3

A critical flaw in the in-kernel KSMBD SMB server allows unauthenticated out-of-bounds reads leading to information disclosure and pot…

Aug 17, 2026views - 386

ransomware

Ransomware Q2 2026: 2,139 Victims and Payment Rate Crashes to 23%

Ransomware isn't slowing down — it's fragmenting. Q2 2026 saw 93 active groups, up from 71 at the start of the year. The top-10 share…

Aug 17, 2026views - 1.2k

CYBERSEC

Rubrik Zero Labs Unveils RPE: From Word Document to Shell on Copilot

Remote Prompt Execution turns prompt injection into full enterprise identity compromise on Microsoft 365 Copilot. The five-stage chain…

Aug 17, 2026views - 975

CYBERSECCRITICAL

Attackers Shut Down Polish Turbine via Private APN: First Real-World OT Case

CERT Polska documented the first real-world attack on critical infrastructure through a misconfigured private cellular APN. A Polish c…

Aug 17, 2026views - 1.2k

ransomwareEXPLOIT

DeadLock: The Ransomware Using Polygon to Evade Infrastructure Seizures

DeadLock leverages Polygon smart contracts to rotate proxy servers and host its data leak site, rendering the infrastructure-seizure s…

Aug 17, 2026views - 1.1k

malware

Mustang Panda Arms CoolClient with Signed Rootkit: EDR in the Kernel Crosshairs

HoneyMyte deploys msagent.sys, a kernel-mode rootkit driver signed with an expired 2013 certificate. It hides processes, files, and C2…

Aug 17, 2026views - 1.1k

malware

AmnesiaStealer: The macOS Malware That Hijacks Victim Browser Sessions in Real Time

Jamf Threat Labs has documented AmnesiaStealer, a Rust-based macOS infostealer that clones the victim's Chromium profile, launches it…

Aug 17, 2026views - 1.2k

CYBERSECZERO-DAY

ShieldBreak: Zero-Day Exploit Targets Windows Defender for SYSTEM Privilege Escalation

Nightmare Eclipse released ShieldBreak, a zero-day exploit achieving SYSTEM privileges on fully patched Windows via Microsoft Defender…

Aug 17, 2026views - 1.2k

CYBERSEC

Generative AI as a Cyber Force Multiplier: Three North Korean Groups, Three Tactics

Famous Chollima (47% of state-backed tech attacks), Kimsuky (HelloDoor malware with AI assistance), and APT45 (recursive prompting): t…

Aug 17, 2026views - 1.2k

CYBERSECZERO-DAY

Clop Claims Theft of Technical Data from 43 Organizations; Shell Investigates

The Clop group stole technical data from 43 organizations by exploiting CVE-2026-12569 in PTC Windchill. Shell is investigating a pote…

Aug 17, 2026views - 1.3k

CYBERSECCVE

CVE-2026-62911: Exchange Authentication Bypass Enables Full Mailbox Takeover

Discovered at Pwn2Own by Orange Tsai, ZDI-26-534 hits on-premises Exchange with a CVSS 8.0 score. Microsoft released the patch after 8…

Aug 17, 2026views - 1.4k

news

SafePal Breach Exposes 39,798 Customers: Wallet Secure, Supply Chain Not

SafePal disclosed a data breach on August 16, 2026, exposing order details for nearly 40,000 customers. The incident stemmed from an a…

Aug 17, 2026views - 1.2k

linux

ZDI-26-575: TOCTOU in Linux Kernel Net Scheduler Enables Local Privilege Escalation

A TOCTOU race condition in the Linux kernel's Net Scheduler packet classifier API allows local privilege escalation. The fix introduce…

Aug 16, 2026views - 1.2k

CYBERSECCRITICAL

Cisco ISE: Authenticated RCE in invokeScript With Root Escalation Path

CVE-2026-20147 enables authenticated remote code execution as the iseadminportal user on Cisco Identity Services Engine, with a docume…

Aug 16, 2026views - 1.2k

VULNCRITICAL

NGINX WebDAV: Pre-Auth RCE Disclosed in ZDI-26-578

The ZDI-26-578 advisory reveals a critical RCE flaw in the NGINX HTTP DAV module. It is exploitable without authentication via an inte…

Aug 16, 2026views - 1.4k

CYBERSECCRITICAL

WordPress 7.0.3 Fixes Login XSS That Can Lead to RCE via Social Engineering

CVE-2026-64638 is a pre-authentication reflected XSS in the WordPress login screen, discovered by pwn.ai using AI-assisted systems. Ex…

Aug 16, 2026views - 1.1k

VULNCRITICAL

NVIDIA Transformers4Rec Exposed to RCE: ML Checkpoint Turns Weapon

A deserialization flaw in NVIDIA's ML library enables remote code execution via malicious checkpoints. A documented discrepancy betwee…

Aug 16, 2026views - 1.2k

VULNZERO-DAY

dnsmasq: DNSSEC Bug Enables Unauthenticated Remote DoS

A vulnerability in dnsmasq's NSEC/NSEC3 DNSSEC record parsing allows remote denial-of-service attacks without authentication. The flaw…

Aug 16, 2026views - 1.3k

CYBERSEC

Criminals Buy Expired Domains to Inherit Reputation and Traffic

A single threat actor spent nearly $7 million on over 10,000 expired domains, weaponizing their inherited trust signals for illegal st…

Aug 16, 2026views - 1.2k

CYBERSEC

Beacon CRM: The Cloud Revealed as a Lock With the Key Left in the Door

Beacon CRM confirmed the total theft of its customer database covering 1,500+ UK charities. The cause: an AWS access key exposed in pu…

Aug 16, 2026views - 1.2k

CYBERSECCVE

CVE-2026-65400: From Patch to Exploit in 4 Hours on macOS Screen Sharing

The Dutch NCSC confirms active exploitation of CVE-2026-65400: a pre-authentication bypass in macOS Screen Sharing granting root acces…

Aug 16, 2026views - 1.2k

CYBERSECEXPLOIT

Keyv Compromised: Malware Exploits Signed Provenance and AI Agent Config Files

The August 4, 2026 supply chain attack on keyv delivered malware with valid SLSA attestations and OIDC provenance signatures. AI agent…

Aug 16, 2026views - 1.1k

CYBERSEC

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Greatness phishing-as-a-service toolkit has integrated device code phishing, abusing the OAuth 2.0 Device Authorization Grant to b…

Aug 16, 2026views - 1.3k

CYBERSECCVE

CVE-2026-3854: One git push RCE in GitHub, 88% of GHES instances exposed

Wiz Research disclosed a critical RCE in GitHub Enterprise Server exploitable with a single git push command. GitHub patched GitHub.co…

Aug 15, 2026views - 1.2k