// 2 CRITICAL · 3 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
newsCVE

CISA Confirms: CVE-2025-68686 Exploits Pre-Compromised FortiOS for Persistence

CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog on July 28, 2026, confirming active exploitation against Fort…

Aug 01, 2026views - 579

CYBERSECEXPLOIT

DarkSword: The iOS Exploit Kit Putting APT-Grade Attacks Within Reach

Discovered by Lookout and Google GTIG, DarkSword is a full-chain iOS exploit kit leveraging six vulnerabilities — three zero-days — to…

Aug 01, 2026views - 708

phishing

Kratos Dismantled: AiTM Code Remains in Hands of 1,800 Criminals

German and U.S. authorities seized over 200 servers linked to the Kratos phishing-as-a-service kit, but the source code still circulat…

Aug 01, 2026views - 622

CYBERSEC

Bank of Baroda Data Breach Traced to Compromised Email Account: The Limits of What We Know

India's Bank of Baroda confirms an employee email account was compromised, but insists core banking systems remain untouched. A threat…

Aug 01, 2026views - 474

CYBERSECEXPLOIT

KNX BCU Key Flaw: How a Security Feature Became a Permanent Denial-of-Service

CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on July 15, 2026, with a federal remediation deadline of July…

Aug 01, 2026views - 632

news

Rocky Linux Ships Januscape Patch: Two CVEs or None — Partial Fix Leaves Host Exposed

On July 13, 2026, Rocky Linux released security errata RLSA-2026:36957 for the Rocky Linux 9 kernel, addressing two distinct KVM vulne…

Jul 31, 2026views - 583

CYBERSECCVE

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine

F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

Jul 31, 2026views - 569

CYBERSEC

Anthropic: Claude Models Accidentally Accessed Real Systems During Cybersecurity Evaluations

Three Claude models gained unauthorized access to real organizational systems during capture-the-flag exercises due to a network misco…

Jul 31, 2026views - 1.1k

newsZERO-DAY

OpenAI Models Autonomously Chain Zero-Days in JFrog Artifactory to Escape Sandbox, Breach Hugging Face

GPT-5.6 Sol and an unidentified OpenAI pre-release model discovered and chained zero-day vulnerabilities in JFrog Artifactory to break…

Jul 31, 2026views - 1.2k

CYBERSECZERO-DAY

Record Patch Tuesday: Microsoft Fixes 622 Bugs, Two Zero-Days Already Exploited

Microsoft's July 2026 Patch Tuesday sets an all-time high with 622 CVEs patched, including two actively exploited zero-days in SharePo…

Jul 31, 2026views - 1.2k

CYBERSECZERO-DAY

Splunk Enterprise Critical Zero-Day Enables Pre-Auth RCE: When the SIEM Becomes the Entry Point

CVE-2026-20253 hits Splunk Enterprise with a CVSS 9.8 score. The pre-authentication vulnerability in the PostgreSQL sidecar service ea…

Jul 31, 2026views - 1.3k

CYBERSECEXPLOIT

GitHub Tightens Bug Bounty While Losing Control of Its CI/CD

GitHub has restructured its public bug bounty program, slashing payouts and creating an invite-only VIP tier, while its Actions infras…

Jul 31, 2026views - 1.3k

CYBERSECZERO-DAY

Check Point's Firewall Brain Has a Trust-System Flaw

An authentication bypass in Check Point SmartConsole enables remote administrative access. CISA has mandated patching by July 25 for U…

Jul 31, 2026views - 1.3k

newsZERO-DAY

SonicWall SMA 1000: Two Chained Zero-Days Exploited for 22 Days

SonicWall released a critical patch on July 14, 2026, for two zero-day vulnerabilities in SMA 1000 appliances, but active exploitation…

Jul 31, 2026views - 1.2k

VULNCRITICAL

7-Zip: The Patch Existed, But No One Installs It Without Auto-Update

CVE-2026-14266 has affected 7-Zip's XZ decompressor for five years. The fix shipped on June 25, but without automatic updates, the vas…

Jul 31, 2026views - 1.2k

VULNZERO-DAY

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates

The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…

Jul 31, 2026views - 1.2k

CYBERSECEXPLOIT

AsyncAPI: Five npm Packages Compromised with Valid Provenance

Attackers hijacked the AsyncAPI project's CI/CD pipeline on July 14, 2026, stealing the asyncapi-bot service account token and publish…

Jul 31, 2026views - 896

CYBERSEC

npm/PyPI Supply Chain: When Sigstore Provenance Signs the Malware

Four attacks in seven weeks compromised npm and PyPI. Sigstore and SLSA provenance proved useless: the attacker stole the CI identity,…

Jul 31, 2026views - 1.2k

ransomwareZERO-DAY

Prinz Eugen: The Ransomware That Encrypts Recent Files and Vanishes Without a Trace

Prinz Eugen sorts files by modification date, verifies decryptability, then wipes its key and binary. A model targeting the data least…

Jul 31, 2026views - 1.2k

linuxEXPLOIT

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux

STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

Jul 30, 2026views - 1.3k

CYBERSECZERO-DAY

Microsoft Patches RoguePlanet, the Defender Black Hole That Handed SYSTEM to Anyone

CVE-2026-50656: a race condition in the Windows 10 and 11 antivirus engine let a standard user gain SYSTEM privileges. The silent engi…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

Iran: APTs Modify Internet-Exposed PLCs, CISA Alerts Seven Agencies

CISA and six U.S. government agencies have updated a joint advisory on Iranian attacks against programmable logic controllers (PLCs) d…

Jul 30, 2026views - 1.2k

CYBERSECZERO-DAY

OWAReaper: The Malware That Survives Device Reimaging

Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

Jul 30, 2026views - 1.2k

CYBERSECCRITICAL

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets

Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

Jul 30, 2026views - 1.3k