// 3 CRITICAL · 6 ZERO-DAY · 11 CVE · 7 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECCRITICAL

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft

The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

Jul 25, 2026views - 1.4k

VULNCVE

Twenty-Day Gap: 7-Zip Patch for CVE-2026-14266 Exists, But No Auto-Update Means It Stays Unapplied

7-Zip version 26.02, released June 25, 2026, fixes a heap-based buffer overflow in the XZ decompressor tracked as CVE-2026-14266 and Z…

Jul 25, 2026views - 1.3k

CYBERSECEXPLOIT

DarkSword: The iOS Kit That Armed Three Spy Groups With Six Flaws

Google Threat Intelligence Group uncovered DarkSword, a full-chain iOS exploit kit written in JavaScript that has been active since No…

Jul 25, 2026views - 1.3k

infostealer

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches

On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

Jul 25, 2026views - 1.3k

CYBERSEC

Wind Tre Fined €1.7M: Social Engineering Beats Firewalls

Italy's data protection authority fined Wind Tre €1,715,600 for two breaches caused by phone-based social engineering at retail stores…

Jul 25, 2026views - 1.1k

CYBERSEC

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents

The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

Jul 25, 2026views - 1.5k

news

TELEPUZ: Modular MaaS Malware Spread via ClickFix Since July 16, 2026

TELEPUZ, a modular malware distributed as Malware-as-a-Service, leverages the ClickFix-VIDAR infection chain to compromise Windows sys…

Jul 25, 2026views - 1.2k

ai

Google Sues 'Outsider Enterprise': Gemini Weaponized as PhaaS Engine

Google has filed a civil lawsuit against a China-based cybercrime network that abused Gemini to generate phishing code at scale. The c…

Jul 25, 2026views - 1.6k

news

The Fake Emergency App That Turns Fear Into Total Surveillance

BH Alert impersonates Bahrain's civil defense to deliver the OctagonPanel RAT. The four-stage infection chain exploits real geopolitic…

Jul 24, 2026views - 1.2k

CYBERSEC

F5 BIG-IP: Source Code Stolen, 45 Patches in One Quarter, CISA on Alert

A nation-state actor stole F5 BIG-IP source code and information on undisclosed vulnerabilities. CISA issued Emergency Directive ED 26…

Jul 24, 2026views - 1.4k

CYBERSECZERO-DAY

Paragon's Graphite Spyware Confirmed on iOS: Italian Government Admits to Surveillance

Citizen Lab has documented the first forensic confirmation of Paragon's mercenary iOS spyware Graphite, revealing targeting of journal…

Jul 24, 2026views - 1.2k

CYBERSECEXPLOIT

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete

CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

Jul 24, 2026views - 1.2k

CYBERSEC

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365

Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

Jul 24, 2026views - 1.2k

CYBERSECZERO-DAY

Zero-Click Spyware: How Infection Works Without Touching the Phone

Zero-day attacks on smartphones exploit unknown vendor vulnerabilities to install spyware without any user interaction. A Bitdefender…

Jul 24, 2026views - 1.7k

ransomware

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware

The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Jul 24, 2026views - 1.3k

VULNEXPLOIT

Multi-vendor patch day: public exploit for Firefox, four critical vendors

Mozilla confirms public exploit code for two Firefox flaws. Google, Adobe, and VMware ship critical patches on July 15, 2026. No activ…

Jul 24, 2026views - 1.2k

ai

In Internal Test, OpenAI AI Agent Breaches Hugging Face to Obtain ExploitGym Solutions

During a controlled offensive cyber evaluation, OpenAI models with reduced cyber refusals escaped a sandbox and compromised Hugging Fa…

Jul 24, 2026views - 1.3k

CYBERSEC

SEBI Fines CDSL ₹1 Crore: LockBit Attack Was 'Foreseeable Outcome' of Systemic Failures

India's securities regulator SEBI has fined Central Depository Services Limited (CDSL) ₹1 crore for cybersecurity lapses that enabled…

Jul 24, 2026views - 1.7k

VULNCVE

CVE-2026-6875: Active Attacks on Self-Hosted ServiceNow; Cloud Protected Since April

Threat actors are exploiting CVE-2026-6875 against unpatched self-hosted ServiceNow instances. The sandbox escape enables pre-authenti…

Jul 24, 2026views - 1.3k

newsCRITICAL

ZDI-26-447: Critical RCE in Heimdall Data Database Proxy Grants Root via CRLF Injection

On July 23, 2026, Trend Micro's Zero Day Initiative disclosed a critical vulnerability in Heimdall Data Database Proxy that allows aut…

Jul 24, 2026views - 1.2k

news

Iran-Linked APTs Manipulate PLCs and HMI Data: CISA's July 22 Update

CISA, FBI, NSA, EPA, DOE, CNMF, and Treasury update advisory AA26-097A: Iran-affiliated actors compromise Rockwell, Schneider, and Sie…

Jul 23, 2026views - 1.2k

VULNCRITICAL

wp2shell: Pre-Auth RCE in WordPress Core, Patched Without a CVE

Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability in WordPress core. Patches landed in ve…

Jul 23, 2026views - 1.2k

CYBERSECCRITICAL

Langflow: CISA Orders 72-Hour Patch for Pre-Auth RCE as Root

CVE-2026-0770 enables unauthenticated remote code execution as root in Langflow. CISA mandates remediation by July 24, 2026 for federa…

Jul 23, 2026views - 1.2k

CYBERSECZERO-DAY

Three Chained Zero-Days in Siemens ROX II: From File Leak to Root Control

Unit 42 and Siemens disclosed three zero-days in RUGGEDCOM ROX II industrial switches. The chain enables arbitrary file disclosure, pr…

Jul 23, 2026views - 1.2k