// 3 CRITICAL · 6 ZERO-DAY · 11 CVE · 7 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECZERO-DAY

DarkSword and Coruna: Government-Grade Spyware Turns Mass Crime on iOS

Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click…

Jul 22, 2026views - 1.2k

CYBERSECZERO-DAY

Landfall: Military-Grade Spyware Targeted Samsung Galaxy Devices for Months

Palo Alto Networks Unit 42 uncovered Landfall, a commercial-grade modular Android spyware that exploited the Samsung zero-day CVE-2025…

Jul 22, 2026views - 1.4k

oracleZERO-DAY

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks

The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

Jul 22, 2026views - 1.3k

VULNCVE

CVE-2026-31431 "Copy Fail": 732 Bytes of Code Breaks the Linux Kernel Since 2017

A vulnerability in the algif_aead module enables root privilege escalation via a 732-byte exploit. CISA has added CVE-2026-31431 to th…

Jul 21, 2026views - 1.6k

CYBERSEC

Accenture Confirms 'Isolated Matter' After Threat Actor '888' Lists 35GB of Data for Sale

Threat actor '888' claims to be selling roughly 35GB of Accenture data, including source code, Azure tokens, and SSH keys. Accenture a…

Jul 21, 2026views - 1.3k

CYBERSECEXPLOIT

GhostApproval, 14 UniFi CVEs, and Roundcube Espionage: A Triple Threat Convergence

Three critical attack vectors converged in July 2026: the GhostApproval symlink vulnerability in six AI coding assistants, 14 new crit…

Jul 21, 2026views - 1.3k

ransomware

Fairlife Halts All U.S. Milk Production: The Ransomware the SEC Didn't Classify as Material

On July 16, 2026, Fairlife, a ~$4 billion Coca-Cola subsidiary, suspended every U.S. plant after ransomware hit 'production-related sy…

Jul 21, 2026views - 1.1k

CYBERSEC

ViteVenom: Seven npm Packages Use Blockchain as Unstoppable C2

The ViteVenom campaign distributes malware via npm using Tron, Aptos, and Binance Smart Chain as command-and-control infrastructure. A…

Jul 21, 2026views - 1.3k

newsZERO-DAY

Dell RecoverPoint: CVSS 10 Zero-Day Exploited for 18 Months by China-Nexus APT

A maximum-severity vulnerability in Dell RecoverPoint for Virtual Machines allowed a suspected China-linked APT cluster to operate und…

Jul 21, 2026views - 1.9k

news

Telepuz: The Modular Malware Turning VIDAR into a Criminal Platform

Elastic Security Labs analyzes Telepuz, a modular malware under active development and distributed as Malware-as-a-Service via a Click…

Jul 21, 2026views - 1.4k

CYBERSECCVE

From VPN Bypass to Encrypted Domain: How CVE-2026-0257 Fuels Qilin Ransomware

Arctic Wolf Labs confirms active exploitation of CVE-2026-0257 to deploy Qilin ransomware. Specific TTPs reveal shared infrastructure…

Jul 21, 2026views - 1.2k

newsCVE

RabbitMQ CVE-2026-5721: Obsolete Endpoint Exposed OAuth Secret, Went Undetected

An obsolete endpoint in RabbitMQ's management panel exposed the OAuth client secret. CVE-2026-5721 carries a CVSS 8.7 score.

Jul 21, 2026views - 1.4k

CYBERSEC

Atomic Arch: 1,500 AUR Packages Hijacked, Targeting Developers and CI

The Atomic Arch operation hijacked over 1,500 Arch User Repository packages via orphaned-package ownership transfers to deliver a Rust…

Jul 21, 2026views - 1.4k

CYBERSECZERO-DAY

Apple Patches Zero-Day in dyld: A Flaw Hidden for Over a Decade

CVE-2026-20700 carries a CVSS 7.8 rating and is actively exploited against targeted individuals. Apple released patches on February 11…

Jul 21, 2026views - 1.4k

news

NFCShare: The Campaign Turning GitHub Into a Distribution Pipeline for Fake Banking Apps

NFCShare steals payment-card data via NFC and captures PINs through spoofed banking apps hosted on GitHub. The European campaign produ…

Jul 21, 2026views - 1.4k

CYBERSECEXPLOIT

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery

The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

Jul 21, 2026views - 1.5k

CYBERSECCRITICAL

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter

CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Jul 20, 2026views - 1.4k

news

Misconfigured Server Exposes Three Evilginx Phishing Campaigns

A server with directory listing enabled revealed the full arsenal of three phishing operators targeting Microsoft 365 accounts using d…

Jul 20, 2026views - 1.3k

CYBERSECEXPLOIT

DarkSword: JavaScript iOS Exploit Kit Strikes via Compromised Legitimate Sites

DarkSword chains six CVEs to compromise iPhones through compromised legitimate websites. The fileless, in-memory chain self-erases aft…

Jul 20, 2026views - 1.3k

news

Vietnam's Ransomware Dip Masks an Underestimated Threat

In Q1 2026, 2.56% of Vietnamese SMEs were hit by ransomware, a slight decline from 2.91% in Q1 2025. The figure, published July 16 by…

Jul 20, 2026views - 1.4k

CYBERSECCVE

CISA Adds CVE-2008-4128 to KEV: An 18-Year-Old Cisco IOS Bug Resurfaces

CISA's Known Exploited Vulnerabilities catalog now includes CVE-2008-4128, an 18-year-old CSRF flaw in Cisco IOS 12.4. Federal agencie…

Jul 20, 2026views - 1.3k

CYBERSECEXPLOIT

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware

On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

Jul 20, 2026views - 1.4k

CYBERSEC

AsyncAPI: The Supply Chain That Trusted Its Own Signatures

On July 14, 2026, an attacker compromised the AsyncAPI release pipeline. Five malicious versions of four npm packages, with over two m…

Jul 20, 2026views - 1.4k

CYBERSECEXPLOIT

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes

On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

Jul 20, 2026views - 1.3k