// 1 CRITICAL · 2 ZERO-DAY · 4 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

Docker MCP Plugin: RCE via OCI Label, Urgent Patch

ZDI-26-363: The YAML label io.docker.server.metadata in the Docker MCP Gateway enables remote code execution as root. The fix isolates…

Jun 25, 2026views - 936

CYBERSECCRITICAL

ZDI-26-376: RCE in Quest NetVault Backup with Authentication Bypass

Command injection in NVBULogDaemon enables remote code execution as SYSTEM. Patch available but no CVE or CVSS assigned.

Jun 25, 2026views - 713

VULNCVE

CVE-2026-9779: RCE in ATEN Unizon via Flawed Cryptographic Signature Check

The ZDI-26-383 vulnerability enables remote code execution with SYSTEM privileges by exploiting a signature verification error in ATEN…

Jun 25, 2026views - 713

CYBERSECZERO-DAY

Fuji Electric Tellus: Kernel Driver Bug Enables SYSTEM Privilege Escalation

CVE-2026-8108 in the Fuji Electric Tellus pcid64 driver allows local privilege escalation to SYSTEM via Registry APIs with excessive p…

Jun 24, 2026views - 843

CYBERSECCRITICAL

Unraid: Command Injection in ToggleState.php Enables RCE

CVE-2026-9773 in the Unraid web server: command injection in ToggleState.php allows authenticated remote code execution. CVSS 8.8, fix…

Jun 24, 2026views - 668

newsZERO-DAY

Cisco SD-WAN Zero-Day Exploited for Root Access at Telecom Provider

Threat actors exploited CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to gain root-level control over a communications service provi…

Jun 24, 2026views - 711

news

Operation Endgame Dismantles 326 Amadey and StealC Servers, First RICO Case Against Dual Malware Families

An international law-enforcement and private-sector operation dismantled the shared infrastructure of the Amadey loader and StealC inf…

Jun 24, 2026views - 730

linux

Linux Process Masquerading Tricks ps and top

On Linux, malicious processes mask their name and command line by abusing prctl and argv memory overwrites. Standard tools like ps and…

Jun 24, 2026views - 787

malware

Mistic: KongTuke's In-Memory Backdoor Challenges EDR Defenses

Operational since April 2026, the stealthy Mistic backdoor leverages DLL sideloading and in-memory BOF execution for long-term persist…

Jun 24, 2026views - 1.1k

VULN

macOS: Standard Users Disable EDR/MDM Without Admin Rights

A privilege escalation technique on macOS exploits CDHash caching and NIB injection to silently disable enterprise security tools. App…

Jun 24, 2026views - 923

ransomware

Bajaj Auto’s Silent Ransomware: What Lies Behind the ‘Successful Mitigation’ Claim

Bajaj Auto disclosed a June 23, 2026 ransomware incident without naming the threat actor, strain, or impact. The case exposes the limi…

Jun 24, 2026views - 718

CYBERSECEXPLOIT

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries

Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

Jun 24, 2026views - 996

VULNCVE

Path Traversal in Allegra: CVE-2026-11442 Exposes Arbitrary Files

The ZDI-26-357 vulnerability in Allegra's exportReport method allows an authenticated remote attacker to read arbitrary files via path…

Jun 24, 2026views - 896

CYBERSEC

Railway Cybersecurity: The IT/OT Boundary Has Collapsed

Rail systems are abandoning isolated SCADA for IP networks and AI. DNV's Jorge Aldegunde explains why security is now an active interf…

Jun 24, 2026views - 1.2k

CYBERSEC

The Fake kworker: How APTs Masquerade Linux Processes

Ps and top become unreliable: APTs overwrite argv[0] and use prctl to impersonate kworker. eBPF tools like Kunai detect the real binar…

Jun 24, 2026views - 692

aiZERO-DAY

Mythos AI Finds Vulnerabilities in Classified U.S. Systems in Hours

Anthropic's Mythos model identified vulnerabilities in classified U.S. government systems during a Project Glasswing test, completing…

Jun 24, 2026views - 715

CYBERSECEXPLOIT

TTP-Chain Validation: Proving Exploitability Without an Exploit

A Picus Security engineer proposes TTP-chain validation to test CVE exploitability without live exploits, as the disclosure-to-exploit…

Jun 23, 2026views - 1.3k

CYBERSEC

LastPass Breached via Klue Supply-Chain Attack: Customer Data Stolen, Vaults Intact

LastPass confirms a supply-chain breach through market-intelligence vendor Klue: stolen OAuth tokens granted access to LastPass's Sale…

Jun 23, 2026views - 1.5k

malware

ClickFix macOS: When Users Bypass Gatekeeper Themselves

Microsoft has documented the latest evolution of ClickFix campaigns on macOS: operators have ditched manual DMG installers for Termina…

Jun 23, 2026views - 902

CYBERSECZERO-DAY

Microsoft Confirms RoguePlanet Zero-Day: Defender Becomes Attack Vector

CVE-2026-50656: Microsoft confirms zero-day vulnerability in Defender that elevates privileges to SYSTEM. Patch in development, public…

Jun 23, 2026views - 1.5k

CYBERSEC

GitHub Hardens Actions Checkout Against Pwn Request Attacks

GitHub ships actions/checkout v7 with default blocking for malicious forks. Workflows pinned to a specific SHA remain exposed — here's…

Jun 23, 2026views - 678

CYBERSEC

London Hydro Breach Exposes 160k Customers, Fuels Targeted Phishing Risk

London Hydro disclosed a data breach on June 20. Customer account data was exposed — no payment cards — but the details are ideal for…

Jun 23, 2026views - 839

openai

OpenAI Shifts the Remediation Paradox: From Finding Bugs to Patching Them

OpenAI releases GPT-5.5-Cyber and the Patch the Planet initiative. AI has solved vulnerability discovery, creating a larger problem: t…

Jun 23, 2026views - 1.1k

phishing

Xsolis Phishing Breach Exposes 1.4 Million PHI Records

Xsolis took five months to disclose the full scope of a January 2026 phishing attack. The HHS breach tracker revealed 1,396,519 affect…

Jun 23, 2026views - 934