// 1 CRITICAL · 6 ZERO-DAY · 11 CVE · 12 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECEXPLOIT

APT28 FrostArmada: The SOHO Router Is the New Invisible Perimeter of State-Sponsored Espionage

The GRU compromised 18,000 home routers to steal Microsoft 365 credentials without deploying malware. No EDR can detect this attack: t…

Aug 03, 2026views - 1.2k

CYBERSEC

Midnight Blizzard Turns Hotel Wi-Fi Into a Trap for Corporate Travelers

Storm-2945, a Midnight Blizzard sub-cluster, compromises captive portal networks worldwide to deliver the CornFlake RAT and steal Micr…

Aug 03, 2026views - 1.2k

CYBERSEC

Miasma Hits Red Hat npm: Malware with Valid SLSA Provenance

On June 1, 2026, 32 npm packages in the @redhat-cloud-services namespace were compromised via a Red Hat employee's personal GitHub acc…

Aug 03, 2026views - 1.2k

CYBERSEC

Hotel DNS Attacks: Corporate VPNs Aren't Enough to Protect Microsoft 365

ReliaQuest has documented an active campaign since June 2026 that compromises hotel Wi-Fi gateways to redirect Microsoft 365 logins to…

Aug 03, 2026views - 1.2k

CYBERSECZERO-DAY

Cisco Confirms FMC Zero-Day: Static Credentials Under Attack, CISA Sets August 1 Deadline

Cisco confirms active exploitation of CVE-2026-20316 in Secure Firewall Management Center. CISA adds the flaw to its KEV catalog, mand…

Aug 03, 2026views - 1.2k

CYBERSECZERO-DAY

F5 Races Against Its Own Stolen Code: 45 Vulnerabilities Disclosed in a Single Quarter

Nation-state actors compromised F5's internal systems, exfiltrating portions of BIG-IP proprietary source code and details on undisclo…

Aug 03, 2026views - 1.1k

cybersec

Phishing Tops 50% of IR Cases: Cisco Talos Flags Perimeter Collapse

In Q2 2026, phishing became the leading initial access vector in over half of Cisco Talos Incident Response engagements, up from rough…

Aug 03, 2026views - 1.1k

newsZERO-DAY

WhatsApp Patches Zero-Day Zero-Click: The Apple Combo That Exposes

Updated August 3, 2026 — WhatsApp has released emergency updates to fix CVE-2025-55177, an insufficient authorization vulnerability in…

Aug 03, 2026views - 1.3k

CYBERSECCRITICAL

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8

Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

Aug 03, 2026views - 1.2k

CYBERSECCRITICAL

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure

An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

Aug 03, 2026views - 1.2k

CYBERSECZERO-DAY

May 2026 Patch Tuesday: 161 CVEs, No Zero-Days, But Wormable Risks Loom

Microsoft's May 2026 Patch Tuesday fixes 161 vulnerabilities with no actively exploited zero-days — the first such month since June 20…

Aug 03, 2026views - 1.1k

VULNCRITICAL

GStreamer RCE Flaw in rtpsbcdepay Codec: Patch Available

ZDI-26-467 (CVE-2026-18299) details a use-after-free in GStreamer's RTP SBC depayloader enabling remote code execution. The primary ri…

Aug 03, 2026views - 1.1k

VULNCRITICAL

SSRF in Phoenix Contact MQTT Broker: The Assault on EV Chargers Starts Here

ZDI-26-518 reveals a flaw in the MQTT service of Phoenix Contact CHARX SEC-3150 EV chargers. An unauthenticated, network-adjacent atta…

Aug 03, 2026views - 1.1k

CYBERSEC

Estée Lauder's 10-Month Oracle EBS Breach: The Suspected Patch Gap That Let Clop In

Estée Lauder disclosed a 10-month breach of its Oracle E-Business Suite HR system. The Clop ransomware group exploited CVE-2025-61882,…

Aug 02, 2026views - 1.2k

pythonCVE

CVE-2026-6100: CPython Use-After-Free in Decompressors Rated CVSS 9.1 Critical

CVE-2026-6100 affects CPython with a use-after-free in the lzma, bz2, and gzip decompressors. The CVSS 4.0 score is 9.1 CRITICAL, thou…

Aug 02, 2026views - 1k

ransomware

AnMed Ransomware: 72-Hour Criminal Deadline Collides With 72-Hour CIRCIA Mandate

AnMed Health suffered a ransomware attack starting July 26, 2026, with a patient reporting a 72-hour ransom demand. The health system…

Aug 02, 2026views - 1.1k

malware

SourTrade: The Browser Becomes an In-Memory Malware Factory

The SourTrade malvertising campaign assembles malware directly in the victim's browser memory using legitimate web APIs. The technique…

Aug 02, 2026views - 1.1k

VULNCRITICAL

Aeon RCE via Pickle Dataset: ML Pipeline Risk

CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

Aug 02, 2026views - 1.1k

CYBERSECCVE

TrendAI Vision One and the 'Historical' CVE-2025-71387: Patched in December

Trend Micro published bulletin KA-0023937 for CVE-2025-71387, a privilege escalation vulnerability in TrendAI Vision One that was alre…

Aug 02, 2026views - 1.1k

CYBERSECCRITICAL

Heimdall Data Database Proxy: Root RCE via Directory Traversal in uploadJar

ZDI-26-479 reveals a critical flaw in the uploadJar method of Heimdall Data Database Proxy. An authenticated attacker can achieve arbi…

Aug 02, 2026views - 193

CYBERSEC

Kemp LoadMaster: Hard-Coded Key in enablexroot Exposes Appliance to Root

Progress Software has patched CVE-2026-59689, a CVSS 8.0 privilege-escalation vulnerability in Kemp LoadMaster caused by a hard-coded…

Aug 02, 2026views - 1.2k

CYBERSECCRITICAL

WordPress wp2shell: In-the-Wild RCE Within 24 Hours of AI-Assisted Discovery

The wp2shell vulnerability chain in WordPress Core is under active in-the-wild exploitation with pre-authentication RCE. Wiz Research…

Aug 02, 2026views - 1.1k

CYBERSECZERO-DAY

Heap Overflow in Kenwood DNR1007XR: Malicious vCard Grants Root Code Execution

ZDI-26-488 discloses a vulnerability in the Kenwood infotainment system: a physically present attacker achieves a root shell via a hea…

Aug 02, 2026views - 1.1k

CYBERSEC

VoidStealer Bypasses Chrome Encryption by Attacking Memory

VoidStealer circumvents Chrome's App-Bound Encryption by extracting the master key from memory during decryption. The MaaS infostealer…

Aug 02, 2026views - 1.1k