// 1 CRITICAL · 6 ZERO-DAY · 10 CVE · 8 EXPLOIT IN THE LAST 24H
CYBERSEC

Why CVSS Scores Fail the Factory Floor: A New Framework for OT Vulnerability Management

An OT security practitioner has introduced a five-step framework to evaluate the actual exploitability of vulnerabilities in manufactu…

Jun 04, 2026views - 336

CYBERSEC

CISA to Issue Mandatory AI Security Directive for Federal Agencies by Friday

CISA Acting Director Nick Andersen announced that a Binding Operational Directive (BOD) implementing the new AI Executive Order will b…

Jun 04, 2026views - 190

malware

TA4922 Targets Europe with New Atlas RAT and AI-Assisted Malware Development

Proofpoint tracks the European expansion of TA4922, a Chinese-speaking cybercrime group deploying the new Atlas RAT, RomulusLoader, an…

Jun 03, 2026views - 274

VULNCVE

CVE-2026-48095: 7-Zip NTFS Handler Heap Overflow

A heap overflow in 7-Zip’s NTFS handler allows for RCE via crafted files. The vulnerability involves signature-based file routing that…

Jun 03, 2026views - 356

ai

AI Agents: Only 11% Secure as 'Lethal Trifecta' Exposes 98% of Market

Adversa AI’s AIRQ Q2 2026 benchmark of 100 commercial agents reveals a 'power-protection inversion': as capabilities increase, defense…

Jun 03, 2026views - 290

routerCRITICAL

Acer Wave 7: Critical Zero-Days Exposed, Patch Not Expected Until Late June

Acer confirms two vulnerabilities (CVSS 10.0 and 9.8) in its Wave 7 router, involving cleartext credential leaks and a persistent back…

Jun 03, 2026views - 167

VULN

Microsoft Refuses to Patch Windows Search URI Flaw Enabling NTLM Hash Theft

Huntress has disclosed an unpatched vulnerability in the Windows search: URI handler that allows attackers to steal NTLMv2 hashes via…

Jun 03, 2026views - 301

ai

Trump Signs AI Executive Order: 30-Day Voluntary Review for Frontier Models

The executive order establishes a voluntary framework for pre-release government access to advanced AI models, tasking the NSA with mo…

Jun 03, 2026views - 260

cybersec

SI-CERT: How a 13-Person Team Manages 6,000 Annual Incidents

Slovenia’s national CSIRT, SI-CERT, processes 6,000 cyber incidents annually with a core staff of just 13. By deploying a specialized…

Jun 03, 2026views - 271

CYBERSECCRITICAL

Kemp LoadMaster API Flaw Enables Authenticated RCE: CVSS 8.8 Vulnerability Patched

CVE-2026-3517 in Progress Software Kemp LoadMaster allows authenticated users to execute arbitrary code via command injection in the c…

Jun 03, 2026views - 210

VULNCVE

CVE-2026-0826: Root RCE Vulnerability Hits HP Poly Enterprise VoIP Phones

A critical stack-based buffer overflow in HP Poly Voice's SDP parsing allows unauthenticated remote code execution with root privilege…

Jun 03, 2026views - 282

CYBERSECZERO-DAY

AI Zero-Days and OT Vulnerabilities: ESET’s May 2026 Security Briefing

Tony Anscombe’s latest roundup highlights critical failures in Polish water plants, Google’s discovery of the first AI-generated zero-…

Jun 03, 2026views - 190

CYBERSECZERO-DAY

Tuskira Unveils Quell: AI Agent Designed to Mitigate Zero-Days Before Patches Exist

Tuskira has launched Quell, an AI agent that maps attack paths and orchestrates compensating controls to neutralize zero-day threats a…

Jun 02, 2026views - 215

CYBERSECEXPLOIT

Gamaredon APT Weaponizes WinRAR Path Traversal Bug for Ukrainian Espionage

The Gamaredon APT group is exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to deploy a modular malware suite again…

Jun 02, 2026views - 212

CYBERSECEXPLOIT

CISA Warns of Active Exploitation for Two-Year-Old Oracle WebLogic Flaw

CISA has added CVE-2024-21182 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of an Oracle WebLog…

Jun 02, 2026views - 258

CYBERSEC

Cybanetix Launches Managed AI Service: AI-Native MDR Powered by Four-Vendor Stack

Cybanetix has unveiled its Managed AI Service, integrating NOMA, SentinelOne, Microsoft, and Exabeam under a unified 24/7 SOC with a s…

Jun 02, 2026views - 248

CYBERSEC

BadBone: Dormant AI Backdoor Evades Six Major Security Defenses

BadBone research demonstrates that backdoors in pre-trained AI models remain invisible until customized, maintaining a 0.10% attack su…

Jun 02, 2026views - 321

CYBERSEC

Gitea Bug Exposed Private Container Images for Four Years

CVE-2026-27771: A critical flaw in Gitea’s container registry left approximately 31,750 instances vulnerable for nearly four years. Di…

Jun 02, 2026views - 211

anthropic

Anthropic Grants ENISA Access to Mythos: A Strategic Shift for EU Cybersecurity

Anthropic is granting ENISA access to its Mythos model for vulnerability discovery. As the first EU entity to join Project Glasswing,…

Jun 02, 2026views - 210

news

DriveSurge: Thousands of Legitimate Sites Weaponized for Malware Distribution

The threat actor DriveSurge has compromised thousands of websites to automate malware delivery via ClickFix and Fake Update schemes, m…

Jun 01, 2026views - 246

openai

OpenAI Mandates Hardware-Backed Passkeys for Access to Frontier AI Models

Starting June 1, 2026, OpenAI will require Trusted Access for Cyber (TAC) program members to use hardware-backed passkeys, setting a n…

Jun 01, 2026views - 265

cybersec

Tina Peters Released: Election Insider Threat Becomes Political Flashpoint

Colorado Governor Jared Polis commutes the sentence of former clerk Tina Peters. CyberScoop and The Independent detail her release, th…

Jun 01, 2026views - 215

CYBERSECEXPLOIT

Insight Launches Managed Exposure Defense to Combat AI-Driven Exploit Speed

Insight consolidates CTEM, enterprise patching, supply chain risk, surge engineering, and XDR into a unified managed service designed…

Jun 01, 2026views - 224

CYBERSEC

Audit Slams NIST Over NVD Collapse: 27,000 CVE Backlog and $200,000 in Wasted Funds

A Department of Commerce OIG audit documents the systemic failure of the National Vulnerability Database pipeline, revealing a backlog…

Jun 01, 2026views - 294