// 2 CRITICAL · 4 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSEC

Trend Micro Cleaner One Pro: File Cleanup Turns Into a SYSTEM-Level Attack

A vulnerability in the Junk Files Cleanup component of Trend Micro Cleaner One Pro allows a local attacker to delete arbitrary files w…

Aug 05, 2026views - 1.3k

CYBERSECCRITICAL

WatchGuard FireWare OS: Directory Traversal in sigd Service Opens Path to Code Execution

A directory traversal vulnerability in the sigd service of WatchGuard FireWare OS allows an authenticated remote attacker to create ar…

Aug 05, 2026views - 1.3k

phishing

Authorities Dismantle Kratos Phishing Kit, but the Code Lives On With 1,800 Customers

German and U.S. law enforcement seized over 200 servers and took down the Kratos phishing-as-a-service platform on July 21, 2026, whil…

Aug 05, 2026views - 1.3k

newsCVE

Microsoft Patches CVE-2026-50656: Defender Engine Turned Weapon Against Windows

Microsoft released an out-of-band patch on July 9, 2026 for CVE-2026-50656, a zero-day vulnerability in the Microsoft Malware Protecti…

Aug 04, 2026views - 1.4k

VULNCVE

CVE-2026-66066: Unauthenticated RCE in Rails via Active Storage, Public Metasploit Exploit

A critical Ruby on Rails vulnerability enables arbitrary file read and unauthenticated RCE through Active Storage when using libvips.…

Aug 04, 2026views - 1.3k

CYBERSEC

Three Decades of Forensic DNA Evidence Left Without Digital Signatures

A CVSS 8.2 vulnerability in Thermo Fisher Applied Biosystems software allows tampering with forensic DNA files. The patch adds digital…

Aug 04, 2026views - 1.3k

smartphone

Android 17 Locks Down PINs: Hard Cap Drops From 1,800 Attempts to 20

Android 17 introduces an absolute hard cap of 20 failed PIN attempts with duplicate-guess detection. Google drastically shrinks the br…

Aug 04, 2026views - 1.2k

linux

Arch Linux Halts AUR Package Adoptions: Third Supply-Chain Attack in Two Months

On July 30, 2026, Arch Linux suspended package adoptions in the Arch User Repository to stop an active supply-chain campaign. It is th…

Aug 04, 2026views - 1.3k

malware

QLNX: The Linux RAT Targeting Software Supply Chain Keys

Trend Micro discovered QLNX, a previously undocumented Linux RAT that combines a dual-tier rootkit, PAM backdoor, and P2P network to s…

Aug 04, 2026views - 1.2k

CYBERSECZERO-DAY

Exploitarium Turns Zero-Day Disclosure into Permanent Infrastructure

The Exploitarium repository has published 204 zero-day exploits for open-source projects without vendor notification. CVE-2026-55200 a…

Aug 04, 2026views - 1.2k

CYBERSECCVE

Fortinet CVE-2026-24858: Active Exploitation, SSO Bypass, CVSS 9.8

Fortinet has patched CVE-2026-24858, a critical authentication bypass with a CVSS 9.8 score that is under active exploitation. CISA ha…

Aug 04, 2026views - 1.3k

CYBERSEC

AI Agent Prompt Injection: SOCs Are Blind to Language as a Weapon

Gartner and OWASP confirm prompt injection as the top AI threat for 2026. Traditional SOCs cannot detect attacks that weaponize natura…

Aug 04, 2026views - 1.4k

CYBERSECEXPLOIT

GhostLock: The Exploit That Unlocks Linux in 5 Seconds — 15 Years in the Shadows

On July 7, 2026, Nebula Security disclosed GhostLock, a working exploit for CVE-2026-43499, a use-after-free in the Linux kernel's fut…

Aug 04, 2026views - 1.2k

VULNCRITICAL

7-Zip XZ Decoder RCE: Silent Patch Leaves Users Exposed

CVE-2026-14266 enables code execution via a crafted XZ archive. The fix landed in 7-Zip 26.02 on June 25, but the lack of automatic up…

Aug 04, 2026views - 1.2k

ransomware

CRPx0 Lists Hyundai Turkey: The Credibility Gap in Dark Web Claims

Ransomware group CRPx0 has listed Hyundai Turkey on its dark web leak site. With no official confirmation and no independent verificat…

Aug 04, 2026views - 1.1k

CYBERSECCRITICAL

Intel and AMD Patch 70 Flaws: Two Critical CVSS 9.3 and 9.2 Bugs in GPU Drivers

On May 13, 2026, Intel and AMD released 28 advisories covering 69 vulnerabilities. Two critical flaws hit chip software drivers, not t…

Aug 04, 2026views - 1.2k

CYBERSEC

PNLD Data Breach: UK Police Contacts Published on Dark Web July 26

The Police National Legal Database confirms the exfiltration of names, organizations, and work emails of officers, government staff, a…

Aug 04, 2026views - 1.3k

CYBERSEC

Pass-ta-key Exposes the Gap Between FIDO2 Cryptography and Windows Implementation

Unit 42 reveals three post-compromise techniques that bypass PIN and biometrics on Chrome for Windows. Passkeys resist phishing, not m…

Aug 04, 2026views - 1.2k

ransomwareCVE

Data-Theft Campaign Targets Windchill and FlexPLM via CVE-2026-12569 RCE

A data-theft extortion campaign is exploiting CVE-2026-12569, a critical unauthenticated RCE in PTC Windchill and FlexPLM, to deploy h…

Aug 04, 2026views - 1.2k

CYBERSEC

Notepad++ Compromised: Lotus Blossom Hijacked Updates for Months

Chinese threat actors compromised Notepad++'s shared hosting infrastructure to selectively deliver malware to telecom and financial or…

Aug 03, 2026views - 1.6k

CYBERSECZERO-DAY

INC Ransomware Dominates SonicWall Zero-Day Chain: When the VPN Appliance Becomes an Unmonitored Bridge

INC Ransomware has emerged as the dominant threat actor actively weaponizing a chain of two zero-day vulnerabilities in SonicWall SMA…

Aug 03, 2026views - 1.3k

phishing

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'

Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Aug 03, 2026views - 1.2k

CYBERSEC

Iranian APTs Hit Rockwell PLCs: Over 30 Minnesota Water Systems Compromised

Iran-affiliated APT actors are exploiting CVE-2021-22681 in Rockwell, Schneider, and Siemens PLCs. The joint CISA-FBI advisory updated…

Aug 03, 2026views - 1.3k

CYBERSECEXPLOIT

APT28 FrostArmada: The SOHO Router Is the New Invisible Perimeter of State-Sponsored Espionage

The GRU compromised 18,000 home routers to steal Microsoft 365 credentials without deploying malware. No EDR can detect this attack: t…

Aug 03, 2026views - 1.3k