// 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSEC

CISA to Issue Mandatory AI Security Directive for Federal Agencies by Friday

CISA Acting Director Nick Andersen announced that a Binding Operational Directive (BOD) implementing the new AI Executive Order will b…

Jun 04, 2026views - 150

malware

TA4922 Targets Europe with New Atlas RAT and AI-Assisted Malware Development

Proofpoint tracks the European expansion of TA4922, a Chinese-speaking cybercrime group deploying the new Atlas RAT, RomulusLoader, an…

Jun 03, 2026views - 213

VULNCVE

CVE-2026-48095: 7-Zip NTFS Handler Heap Overflow

A heap overflow in 7-Zip’s NTFS handler allows for RCE via crafted files. The vulnerability involves signature-based file routing that…

Jun 03, 2026views - 273

ai

AI Agents: Only 11% Secure as 'Lethal Trifecta' Exposes 98% of Market

Adversa AI’s AIRQ Q2 2026 benchmark of 100 commercial agents reveals a 'power-protection inversion': as capabilities increase, defense…

Jun 03, 2026views - 239

routerZERO-DAY

Acer Wave 7: Critical Zero-Days Exposed, Patch Not Expected Until Late June

Acer confirms two vulnerabilities (CVSS 10.0 and 9.8) in its Wave 7 router, involving cleartext credential leaks and a persistent back…

Jun 03, 2026views - 130

VULN

Microsoft Refuses to Patch Windows Search URI Flaw Enabling NTLM Hash Theft

Huntress has disclosed an unpatched vulnerability in the Windows search: URI handler that allows attackers to steal NTLMv2 hashes via…

Jun 03, 2026views - 241

ai

Trump Signs AI Executive Order: 30-Day Voluntary Review for Frontier Models

The executive order establishes a voluntary framework for pre-release government access to advanced AI models, tasking the NSA with mo…

Jun 03, 2026views - 201

cybersec

SI-CERT: How a 13-Person Team Manages 6,000 Annual Incidents

Slovenia’s national CSIRT, SI-CERT, processes 6,000 cyber incidents annually with a core staff of just 13. By deploying a specialized…

Jun 03, 2026views - 225

CYBERSECCRITICAL

Kemp LoadMaster API Flaw Enables Authenticated RCE: CVSS 8.8 Vulnerability Patched

CVE-2026-3517 in Progress Software Kemp LoadMaster allows authenticated users to execute arbitrary code via command injection in the c…

Jun 03, 2026views - 158

VULNCVE

CVE-2026-0826: Root RCE Vulnerability Hits HP Poly Enterprise VoIP Phones

A critical stack-based buffer overflow in HP Poly Voice's SDP parsing allows unauthenticated remote code execution with root privilege…

Jun 03, 2026views - 204

CYBERSECZERO-DAY

AI Zero-Days and OT Vulnerabilities: ESET’s May 2026 Security Briefing

Tony Anscombe’s latest roundup highlights critical failures in Polish water plants, Google’s discovery of the first AI-generated zero-…

Jun 03, 2026views - 141

CYBERSECZERO-DAY

Tuskira Unveils Quell: AI Agent Designed to Mitigate Zero-Days Before Patches Exist

Tuskira has launched Quell, an AI agent that maps attack paths and orchestrates compensating controls to neutralize zero-day threats a…

Jun 02, 2026views - 165

CYBERSECCVE

Gamaredon APT Weaponizes WinRAR Path Traversal Bug for Ukrainian Espionage

The Gamaredon APT group is exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to deploy a modular malware suite again…

Jun 02, 2026views - 168

CYBERSECCVE

CISA Warns of Active Exploitation for Two-Year-Old Oracle WebLogic Flaw

CISA has added CVE-2024-21182 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of an Oracle WebLog…

Jun 02, 2026views - 206

CYBERSEC

Cybanetix Launches Managed AI Service: AI-Native MDR Powered by Four-Vendor Stack

Cybanetix has unveiled its Managed AI Service, integrating NOMA, SentinelOne, Microsoft, and Exabeam under a unified 24/7 SOC with a s…

Jun 02, 2026views - 186

CYBERSEC

BadBone: Dormant AI Backdoor Evades Six Major Security Defenses

BadBone research demonstrates that backdoors in pre-trained AI models remain invisible until customized, maintaining a 0.10% attack su…

Jun 02, 2026views - 269

CYBERSEC

Gitea Bug Exposed Private Container Images for Four Years

CVE-2026-27771: A critical flaw in Gitea’s container registry left approximately 31,750 instances vulnerable for nearly four years. Di…

Jun 02, 2026views - 166

anthropic

Anthropic Grants ENISA Access to Mythos: A Strategic Shift for EU Cybersecurity

Anthropic is granting ENISA access to its Mythos model for vulnerability discovery. As the first EU entity to join Project Glasswing,…

Jun 02, 2026views - 156