// 3 CRITICAL · 2 ZERO-DAY · 10 CVE · 5 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

MindsDB Exposed to 0-Day RCE: OpenBBtable Class Executes Python Code Without Validation

ZDI-26-707 (CVE-2026-92207, CVSS 8.8) enables remote code execution on MindsDB via Python injection in the OpenBBtable class. The vend…

Sep 16, 2026views - 1.3k

VULNCVE

CVE-2026-89026: Hard-Coded JWT Key Enables RCE on Issabel PBX

A hard-coded cryptographic key in the Issabel Framework allows unauthenticated remote code execution on PBX phone systems. The Shadows…

Sep 16, 2026views - 1.8k

aiZERO-DAY

CrewAI Zero-Day RCE: Malicious Agents Execute Arbitrary Code via Repository

CVE-2026-92206 hits the CrewAI framework with a CVSS 8.8 score. Unsafe reflection in load_agent_from_repository enables remote code ex…

Sep 16, 2026views - 1.2k

phishing

N0va Turns Phishing Into Invisible Enterprise Access

N0va targets organizations in North America and Europe by abusing legitimate OAuth flows to capture access tokens and establish persis…

Sep 16, 2026views - 1.3k

CYBERSEC

A Quote in a Folder Name Opens Root on Mac: The Parallels Bug

CVE-2026-90894: The most widely used virtualization software on Mac runs a root daemon with a world-writable socket. The fix lands in…

Sep 16, 2026views - 1.4k

VULNCVE

Acronis Patches CVE-2026-87886: In-the-Wild Exploit in cPanel Plugin

Acronis has released urgent patches for CVE-2026-87886, a local privilege escalation vulnerability with a CVSS 7.8 score that is alrea…

Sep 16, 2026views - 1.5k

CYBERSECZERO-DAY

TP-Link Tapo C200: Two Zero-Days Allow Video Feed Access for Adjacent Attackers

OPSWAT disclosed two zero-day vulnerabilities in the TP-Link Tapo C200 camera that break local authentication. An attacker with adjace…

Sep 16, 2026views - 1.6k

CYBERSECEXPLOIT

Google Patches Actively Exploited Android Zero-Day on Pixel: 110 Flaws Fixed

Google released the September 2026 Pixel security bulletin addressing 110 vulnerabilities. CVE-2026-58704, a zero-day in the Cellular…

Sep 16, 2026views - 1.6k

VULNEXPLOIT

Active Exploits Target WooCommerce Wholesale Lead Capture Plugin: The Patch Gap

Threat actors are exploiting CVE-2026-27540 in the WordPress WooCommerce Wholesale Lead Capture plugin. A patch has existed since Febr…

Sep 16, 2026views - 1.3k

CYBERSECEXPLOIT

Active WSO2 API Manager Exploit: JWT Bypass with Forged Admin Tokens

CVE-2026-5430, a critical vulnerability in the JWT component of WSO2 API Manager, is under active exploitation. Forged tokens with adm…

Sep 16, 2026views - 1.3k

CYBERSEC

Google Workspace Attacks Now Start With OAuth, Not Email

The Google Workspace attack chain has shifted from email-first to OAuth-first. Stolen OAuth tokens survive password resets, never expi…

Sep 16, 2026views - 1.8k

news

TED Backdoor Turns HAProxy Into a Spy: Load Balancers Are the New Blind Spot

Rapid7 researchers have uncovered TED, a Linux toolkit that compiles a persistent espionage backdoor directly into victims' HAProxy 2.…

Sep 16, 2026views - 1.3k

ransomware

Switzerland: Ukrainian Ransomware Developer Sentenced to 12 Years, 9 Months

A Zurich district court sentenced a 52-year-old Ukrainian developer to 12 years and 9 months in prison for creating the LockerGoga, Me…

Sep 16, 2026views - 1.3k

VULNCVE

CVE-2026-46300 Fragnesia: Linux Kernel Bug Exposed on GKE Since May

Fragnesia exploits a flaw in skb_try_coalesce() to corrupt the page cache and gain root. Disclosed May 13, with public PoC and patch i…

Sep 16, 2026views - 1.7k

CYBERSEC

Ransomware Recovery in 24–48 Hours Remains Out of Reach: 4 Cases Out of 800+

Fenix24's State of Recoverability 2026, based on 500+ ransomware recoveries, shows only 0.5% of clients neared their 24–48 hour restor…

Sep 16, 2026views - 1.3k

news

DPRK APT Infiltrates South Korean Firms via Backdoor Embedded in HAProxy Code

Rapid7 disclosed on September 3, 2026, a previously undocumented Linux toolkit—TED and curlRAT—used by North Korean APT groups for lon…

Sep 16, 2026views - 1.3k

CYBERSECZERO-DAY

Zero-Day Time Compressed to Hours: The Patch-Exploit Model No Longer Holds

Claude Mythos has collapsed discovery-to-exploit timelines. For CISOs, the only option left is breaking the attack chain before a work…

Sep 16, 2026views - 1.4k

news

China's Spy Chief Names Claude Mythos and GPT-5.5-Cyber as National Security Threats

Chen Yixin, head of China's Ministry of State Security, explicitly identified two U.S. commercial AI models as risks to critical infra…

Sep 15, 2026views - 1.1k

CYBERSEC

Luciferus: The AI Service Killing Jailbreaks in Cybercrime

Sophos researchers have uncovered Luciferus, a subscription-based service sold on underground hacking forums that generates malware vi…

Sep 15, 2026views - 1.6k

news

Iran's Chosen Brick Malware Targets Journalists and Dissidents on Windows

A joint advisory from the FBI, UK NCSC, and Dutch AIVD exposes Chosen Brick, a sophisticated malware that surveils dissidents, activis…

Sep 15, 2026views - 1.1k

malware

KREMLIN Banking Malware Bypasses Chrome and Edge Using Ethereum Smart Contracts

The Brazilian KREMLIN toolkit installs malicious extensions on Chrome and Edge by subverting Chromium's Secure Preferences integrity c…

Sep 15, 2026views - 1.1k

CYBERSECZERO-DAY

Linux Kernel: usbnet Race Condition Enables Privilege Escalation via Physical USB

CVE-2025-22050 in the Linux kernel's usbnet driver allows a physically present attacker to escalate privileges. The race condition, fi…

Sep 15, 2026views - 1.6k

CYBERSECZERO-DAY

Chrome Zero-Day Attack: APT31 Exploits Patch Gap, Google Patches in 48 Hours

China-linked UTA0560 and JungleBamboo targeted NGOs with a three-vulnerability zero-day chain across Chrome and Windows between August…

Sep 15, 2026views - 1.4k

malware

BambooToken: Malware Framework Uses MQTT for C2 on Windows and Linux

Black Lotus Labs has identified BambooToken, a malware framework active since 2023 that adopts the MQTT protocol for command and contr…

Sep 15, 2026views - 1.1k