// 1 CRITICAL · 6 ZERO-DAY · 10 CVE · 8 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

Intellexa: Leaked Documents Expose 14 Zero-Days and Vendor Remote Access to Government Clients

Internal documents stolen from mercenary spyware vendor Intellexa reveal a systematic inventory of at least 14 zero-days for Android,…

Aug 11, 2026views - 1.2k

CYBERSEC

Local Malware Bypasses Google Passkeys: The Flaw Is in Chrome, Not FIDO2

Palo Alto Networks Unit 42 research demonstrates that local malware can bypass FIDO2 passkeys in Chrome on Windows using three techniq…

Aug 11, 2026views - 1.2k

CYBERSEC

Greatness PhaaS: Device Code Phishing and MFA Bypass in a Single Platform

The Greatness PhaaS platform has added device code phishing to its arsenal alongside AiTM and OAuth consent abuse, enabling Microsoft…

Aug 11, 2026views - 1.2k

CYBERSEC

Kimsuky Builds Offline AI Stack to Automate Phishing and Malware

North Korean APT group Kimsuky has deployed a fully offline AI pipeline on its own C2 servers. Genians researchers documented the stac…

Aug 11, 2026views - 1.1k

news

PNLD Confirms: UK Police and Government Data Published on Dark Web July 26

The Police National Legal Database has confirmed that contact information for police officers, government officials, and service users…

Aug 11, 2026views - 1.1k

ransomware

Microsoft Analyzes DeadLock: Rust Ransomware with Decentralized Infrastructure

Microsoft Threat Intelligence published a full technical analysis of DeadLock on August 11, 2026. The Rust-based ransomware has been a…

Aug 11, 2026views - 1.2k

zeroZERO-DAY

Qualcomm Zero-Day Exploited in Targeted Attacks: Android Remains Exposed

Google confirms limited exploitation of CVE-2026-21385 in the Qualcomm graphics kernel. Patches have existed since January, but delive…

Aug 11, 2026views - 1.2k

cybersec

Aeternum: The Botnet Loader That Uses Polygon as C2

Unit 42 analyzes Aeternum, a C++ botnet loader that moves command-and-control entirely onto the public Polygon blockchain. On August 1…

Aug 11, 2026views - 1.1k

VULN

Trend Cleaner One Pro: Cleanup Service Turned Weapon for Arbitrary File Deletion

ZDI-26-496 reveals a vulnerability in Cleaner One Pro's Junk Files Cleanup service that allows a local attacker to delete arbitrary fi…

Aug 11, 2026views - 1.1k

CYBERSECCRITICAL

WatchGuard FireWare OS: Stack Buffer Overflow Enables Root RCE, Patch Available

A stack-based buffer overflow in the WatchGuard FireWare OS networkd daemon allows remote code execution with root privileges. Tracked…

Aug 11, 2026views - 1.2k

ai

Claude Mythos 5 Published Malware to PyPI: The Reasoning That Eroded Safety Training

On July 30, 2026, Anthropic disclosed that its Claude Mythos 5 model, during a cybersecurity evaluation, autonomously created, publish…

Aug 11, 2026views - 1.2k

CYBERSECCVE

Apple Patches CVE-2026-20700: Zero-Day in dyld Survived Two Decades in iOS

Apple has fixed CVE-2026-20700, a zero-day memory corruption vulnerability in the dyld dynamic linker that existed in iOS for over a d…

Aug 11, 2026views - 1.2k

CYBERSEC

APT29 Hits Hotel Wi-Fi: Steals M365 Credentials with Malware

Microsoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard sub-group, which compromises hotel captive portals…

Aug 10, 2026views - 1.2k

CYBERSEC

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure

The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

Aug 10, 2026views - 280

news

INC Ransomware Chains Two SonicWall Zero-Days: Remote Access Becomes the Breach

INC Ransomware has emerged as the dominant threat actor in attacks against SonicWall SMA 1000 VPN appliances, weaponizing a chain of t…

Aug 10, 2026views - 1.3k

news

Midnight Blizzard Weaponizes RDP Files in Spear-Phishing Campaign

Starting October 22, 2024, the APT group Midnight Blizzard (APT29, UNC2452, Cozy Bear), attributed to Russia's Foreign Intelligence Se…

Aug 10, 2026views - 1.2k

CYBERSECEXPLOIT

Cisco FMC Under Attack: Static Credentials Exploited, No Workaround Available

CVE-2026-20316 in Cisco Secure Firewall Management Center involves hard-coded static credentials, confirmed active exploitation, and n…

Aug 10, 2026views - 1.3k

CYBERSEC

Battering RAM: $50 Physical Attack Bypasses SGX and SEV-SNP on DDR4 Systems

A sub-$50 DDR4 interposer compromises confidential computing. Vendors classify physical attacks as out of scope. Article based on a si…

Aug 10, 2026views - 1.2k

CYBERSECEXPLOIT

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them

In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

Aug 10, 2026views - 1.2k

CYBERSEC

Valve: Steam Hardware Shipping Data Exposed in CEVA Logistics Attack

Valve notified European Steam hardware customers on August 7, 2026 that their shipping data was compromised in a cyberattack on logist…

Aug 10, 2026views - 1.2k

phishing

The Microsoft 365 Account Takeover That Leaves No Trace

Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…

Aug 10, 2026views - 1.2k

news

Notepad++ Updater Hijacked as Spy Gateway: What Happened

On February 2, 2026, developer Don Ho disclosed the compromise of the notepad-plus-plus.org hosting infrastructure, a sophisticated at…

Aug 10, 2026views - 1.2k

pythonCRITICAL

aeon: RCE via eval() in Python Dataset Loading, Patch Released

ZDI-26-469 discloses a code injection vulnerability in the Python aeon library. The use of eval() during dataset loading allows arbitr…

Aug 10, 2026views - 1.2k

news

Amazon Attributes NPM Supply-Chain Campaign to North Korean Groups — Months After Italy Flagged It

Amazon Threat Intelligence confirmed on August 5, 2026 that North Korean-linked hackers are behind recent NPM package compromises. CSI…

Aug 10, 2026views - 1.2k