// 2 CRITICAL · 2 ZERO-DAY · 3 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECCRITICAL

X.Org Server: Critical Glamor Font Bug Allows Root Privilege Escalation

CVE-2026-55999 in the Glamor Font component of X.Org Server and Xwayland lets any local user with an X connection escalate to root. Pa…

Jul 26, 2026views - 1.1k

supply

LiteLLM Open-Source LLM Gateway Distributes Credential-Stealing Malware

Two PyPI versions of the litellm package were compromised by malware that abuses Python .pth files to exfiltrate credentials to an att…

Jul 26, 2026views - 1.1k

CYBERSECEXPLOIT

GitHub Actions Unwittingly Became an ISP for Criminals

Threat actors turned GitHub Actions runners into botnet nodes for large-scale cPanel/WHM scanning and exploitation. The campaign gener…

Jul 26, 2026views - 1.2k

ransomware

Stadler Rejects $12.3M Ransom: Everest Fails to Leak Data

Swiss rail manufacturer Stadler Rail publicly refused a 10 million Swiss franc ($12.3 million) ransom demand from the Everest ransomwa…

Jul 26, 2026views - 1.2k

cybersecZERO-DAY

LegacyHive: Zero-Day Windows Flaw Patched by 0Patch Before Microsoft

The LegacyHive vulnerability in the Windows User Profile Service enables local privilege escalation. ACROS Security has released free…

Jul 26, 2026views - 1.1k

ai

Autonomous AI vs. a Water Network: How Claude Mapped an OT Environment Without a Manual

An unknown threat actor used Anthropic's Claude and OpenAI's GPT to autonomously conduct discovery, enumeration, and password spraying…

Jul 26, 2026views - 1.2k

CYBERSEC

SleeperGem: The Day RubyGems Became an npm-Style Target

Three malicious RubyGems packages compromised developer workstations through require-time execution and CI evasion. The campaign marks…

Jul 26, 2026views - 1.2k

CYBERSEC

dYdX Hit by Third Supply-Chain Attack: Compromised npm and PyPI Packages Deliver Wallet Stealer and RAT

DeFi protocol with $1.5T cumulative volume compromised on npm and PyPI. Wallet stealer and remote access trojan distributed via mainta…

Jul 26, 2026views - 1.2k

CYBERSECCVE

CVE-2026-3888: LPE to Root in snapd Hits Ubuntu LTS Since 2016

Qualys discovered a local privilege escalation vulnerability in snapd that lets a local attacker gain root on Ubuntu 16.04 through 24.…

Jul 26, 2026views - 1.2k

nvidiaCRITICAL

NVIDIA NVTabular: RCE via Pickle, CVE-2026-24237 Rated CVSS 7.8

A deserialization flaw in NVIDIA NVTabular enables remote code execution through malicious pickle files. User interaction is required;…

Jul 26, 2026views - 1.2k

VULNZERO-DAY

ZDI-26-419: AdobeUpdateService Bug Allows Local Privilege Escalation to SYSTEM

The ZDI-26-419 vulnerability (CVE-2026-48272) in Adobe Creative Cloud Desktop enables local privilege escalation to SYSTEM via CWE-427…

Jul 26, 2026views - 1.2k

VULN

MSI Center's Ghost Driver: Local Escalation to SYSTEM in One Command

ZDI-26-430 discloses an origin validation flaw in the MSI Center kernel driver NTIOLib_X64.sys, tracked as CVE-2026-6102 (CVSS 7.8). A…

Jul 26, 2026views - 1.2k

VULNZERO-DAY

ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Enables Local Privilege Escalation at CVSS 8.8

An integer overflow in the Linux kernel's vmwgfx graphics driver allows local privilege escalation to kernel context. Published July 1…

Jul 26, 2026views - 1.1k

CYBERSECEXPLOIT

Public Scanner Released for NGINX Map Regex Flaw; Full RCE Exploit Expected Around August 5

Researcher Stan Shaw (cyberstan) has published an open-source static scanner for CVE-2026-42533, a heap buffer overflow in the NGINX s…

Jul 26, 2026views - 1.1k

CYBERSECZERO-DAY

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies

A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Jul 26, 2026views - 1.1k

VULNCRITICAL

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough

CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Jul 26, 2026views - 1k

CYBERSECCRITICAL

Autel Wallbox Exposed to Pre-Auth RCE: The Pwn2Own Bug Hitting Home EV Chargers

Trend Micro's Zero Day Initiative published advisory ZDI-26-437 on July 15, 2026, detailing a pre-authentication remote code execution…

Jul 26, 2026views - 1.1k

phishing

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365

A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Jul 25, 2026views - 1.1k

VULNCRITICAL

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE

Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Jul 25, 2026views - 1.1k

phishing

Joint Operation Dismantles Kratos: The AiTM Phishing Kit That Bypasses MFA

German, U.S., and Indonesian authorities have taken down over 200 servers powering the Kratos phishing kit. The code survives among ro…

Jul 25, 2026views - 1.2k

ai

Iran Weaponizes Its Asymmetric Playbook With Commercial AI

Recorded Future documents how generative AI has become a force multiplier across Iranian cyber and influence operations — compressing…

Jul 25, 2026views - 1.1k

CYBERSECCRITICAL

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft

The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

Jul 25, 2026views - 1.4k

VULNCVE

Twenty-Day Gap: 7-Zip Patch for CVE-2026-14266 Exists, But No Auto-Update Means It Stays Unapplied

7-Zip version 26.02, released June 25, 2026, fixes a heap-based buffer overflow in the XZ decompressor tracked as CVE-2026-14266 and Z…

Jul 25, 2026views - 1.4k

CYBERSECEXPLOIT

DarkSword: The iOS Kit That Armed Three Spy Groups With Six Flaws

Google Threat Intelligence Group uncovered DarkSword, a full-chain iOS exploit kit written in JavaScript that has been active since No…

Jul 25, 2026views - 1.4k