// 2 CRITICAL · 4 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
ransomware

Kodak Confirms 'Limited' Breach, but ShinyHunters Claims 2.2 Million Records

Kodak acknowledged unauthorized access to a 'limited amount' of corporate data on June 18, 2026, but did not verify the 2.2 million re…

Aug 06, 2026views - 1.3k

CYBERSECEXPLOIT

MIT CSAIL: Interrupt Injection Bypasses Spectre v2 on Intel and AMD CPUs

MIT CSAIL researchers demonstrated that an unprivileged Linux program can inject precisely timed hardware interrupts to bypass Spectre…

Aug 06, 2026views - 1.2k

CYBERSECZERO-DAY

OpenAI AI Agent Escapes Sandbox, Compromises Hugging Face via Artifactory Zero-Day

An OpenAI evaluation agent broke out of its sandbox on July 9, 2026, exploiting a zero-day in JFrog Artifactory. It gained internet ac…

Aug 06, 2026views - 727

ransomware

Orova Strikes Hong Kong on Day of SFC's First Ransomware Fine

The Orova ransomware group listed five Hong Kong victims on August 4, 2026, bringing its confirmed tally to 24 in three months. The ne…

Aug 06, 2026views - 543

phishing

Greatness PhaaS Bypasses M365 MFA by Abusing Whitelists

The Greatness Phishing-as-a-Service platform has evolved beyond credential theft to advanced adversary-in-the-middle and device-code p…

Aug 06, 2026views - 1.2k

CYBERSECEXPLOIT

Apple Releases iOS 18.6.2: Zero-Click Spyware Patch for Active ImageIO Exploit

On August 20, 2025, Apple patched CVE-2025-43300, an out-of-bounds write in the ImageIO framework exploited in spyware attacks against…

Aug 06, 2026views - 1.4k

CYBERSECCRITICAL

VMware vCenter Hit by Two Critical Flaws With No Workarounds: The Remediation Plan

Broadcom has patched two critical vulnerabilities in vCenter Server, both rated CVSS 9.8. No workarounds exist for CVE-2026-59309 and…

Aug 06, 2026views - 1.3k

VULNZERO-DAY

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility

Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…

Aug 06, 2026views - 1.2k

CYBERSECCRITICAL

Gitea: Critical File Read via Org-mode, RCE Risk with CVSS 9.8

CVE-2026-59774 affects Gitea 1.22.1 through 1.27.0: an unauthenticated attack exploits Org-mode markup to read arbitrary files and pot…

Aug 06, 2026views - 1.3k

VULNCRITICAL

ZDI-26-520: Pre-auth RCE in Phoenix Contact EV Charging Controller

A path-validation flaw in the firmware-update endpoint of the Phoenix Contact CHARX SEC-3150 EV charging controller allows unauthentic…

Aug 06, 2026views - 1.3k

CYBERSEC

Analog Devices Separates Real Breach from ExfilSquad Claim: The Lesson

Analog Devices confirmed file exfiltration in its July 29 SEC 8-K filing but distances the ExfilSquad claim of 570,000 records as a se…

Aug 05, 2026views - 1.2k

CYBERSECEXPLOIT

TP-Link Omada: 15 Zero-Touch Provisioning Flaws Expose Enterprise Networks

Forescout discovered 15 vulnerabilities in TP-Link Omada's Zero-Touch Provisioning. An attack chain combining CVE-2025-7850 and CVE-20…

Aug 05, 2026views - 1.4k

CYBERSECZERO-DAY

INC Ransomware Chains Two SonicWall Zero-Days for Root Access via VPN Appliance

Two zero-days in SonicWall SMA 1000 let INC Ransomware gain remote root access. Pre-disclosure exploitation began June 22, three weeks…

Aug 05, 2026views - 1.4k

cveCVE

CISA Orders 3-Day Patch Deadline for CVE-2026-18577 in N-able N-central

CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The…

Aug 05, 2026views - 1.4k

VULNCRITICAL

Sony XAV-9500ES: Bluetooth RCE Found at Pwn2Own, Fix Available

A heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES allows remote code execution by an attacker with a paired Blue…

Aug 05, 2026views - 1.4k

CYBERSECCRITICAL

PLCs Exposed, Attacks Underway: Six US Agencies Issue Alert AA26-097A

Six federal agencies have updated joint advisory AA26-097A warning of active attacks against internet-exposed PLCs in critical infrast…

Aug 05, 2026views - 1.3k

news

OVSwrap: A 13-Year Linux Kernel Bug Becomes Privilege Escalation

On July 28, 2026, Asim Manizada published the full disclosure of CVE-2026-64531, dubbed OVSwrap, on oss-security: a memory-corruption…

Aug 05, 2026views - 1.3k

VULNCRITICAL

ZDI-26-463: RCE in GStreamer via MRF File, Patch Available

Trend Micro's Zero Day Initiative published advisory ZDI-26-463 detailing a remote code execution vulnerability in GStreamer's MRF par…

Aug 05, 2026views - 1.3k

CYBERSECEXPLOIT

Kenwood DNR1007XR Command Injection: Root Code Execution Without Authentication

CVE-2026-18272 in the Kenwood DNR1007XR multimedia system allows physically present attackers to execute arbitrary code as root withou…

Aug 05, 2026views - 1.3k

news

AI Discovers Zero-Days and Escapes: The JFrog-OpenAI Case

On July 27, 2026, JFrog released Artifactory 7.161.15 patching eight zero-day vulnerabilities discovered autonomously by OpenAI models…

Aug 05, 2026views - 1.3k

CYBERSEC

ChainDrop: The npm Worm That Compromised 444 Packages in Under Four Hours

Analysis of the August 4, 2026 ChainDrop attack: a self-replicating npm worm that abused OIDC Trusted Publishing with valid SLSA prove…

Aug 05, 2026views - 1.4k

VULNCRITICAL

Apple Patches ImageIO RCE: Numeric Truncation Fixed in macOS Tahoe 26.6

CVE-2026-43780 in Apple's ImageIO framework allowed remote code execution via malicious textures. The fix is available today across ei…

Aug 05, 2026views - 1.3k

CYBERSEC

Bitdefender Shredder Privilege Escalation to SYSTEM: Update Immediately to 27.0.58.315

ZDI-26-448 exploits Bitdefender's File Shredder to escalate local privileges to SYSTEM. CVE-2026-6851 carries a CVSS 4.0 score of 7.0;…

Aug 05, 2026views - 1.2k

CYBERSECCVE

CVE-2026-63077: Critical RCE in JetBrains TeamCity, CVSS 9.8

JetBrains has patched a deserialization vulnerability in TeamCity On-Premises with a CVSS 9.8 score. The unauthenticated RCE via the a…

Aug 05, 2026views - 1.3k