// 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSEC

APT29 Hits Hotel Wi-Fi: Steals M365 Credentials with Malware

Microsoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard sub-group, which compromises hotel captive portals…

Aug 10, 2026views - 983

CYBERSECEXPLOIT

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them

In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

Aug 10, 2026views - 1.1k

phishing

The Microsoft 365 Account Takeover That Leaves No Trace

Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…

Aug 10, 2026views - 1.1k

CYBERSECZERO-DAY

June 2026 Patch Tuesday: Microsoft's Largest Ever, With Three Publicly Disclosed Zero-Days

Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, the most voluminous monthly cycle in the company's history.…

Aug 07, 2026views - 1.1k

CYBERSECZERO-DAY

Chrome's Fifth 2026 Zero-Day: Google Issues Emergency Patch for Actively Exploited V8 Flaw

Google released an emergency update on June 8, 2026, for CVE-2026-11645, an out-of-bounds vulnerability in the V8 JavaScript engine al…

Aug 07, 2026views - 1.1k

CYBERSEC

Swiss Federal SharePoint Breach Compromises 200 Accounts

The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

Aug 07, 2026views - 1k

CYBERSECEXPLOIT

DarkSword Exposes the Hidden iOS Exploit Market: Zero-Days in the Wild

DarkSword exploits six Apple vulnerabilities — three zero-days — to achieve full iPhone takeover. Three threat groups of differing geo…

Aug 07, 2026views - 1k

CYBERSEC

Amazon Attributes Four NPM Supply-Chain Attacks to North Korean Hackers

Amazon Threat Intelligence links the compromise of axios, debug, chalk, and typo-crypto to a North Korean group tracked as SAPPHIRE SL…

Aug 07, 2026views - 1.1k

CYBERSEC

CaptiveCrunch: Midnight Blizzard Turns Hotel Wi-Fi into an APT Delivery Vector

Microsoft Threat Intelligence has exposed CaptiveCrunch, a Storm-2945 campaign that weaponizes hotel captive portals to deliver the Co…

Aug 06, 2026views - 1.1k

phishing

Greatness PhaaS Bypasses M365 MFA by Abusing Whitelists

The Greatness Phishing-as-a-Service platform has evolved beyond credential theft to advanced adversary-in-the-middle and device-code p…

Aug 06, 2026views - 1.1k

CYBERSECEXPLOIT

Apple Releases iOS 18.6.2: Zero-Click Spyware Patch for Active ImageIO Exploit

On August 20, 2025, Apple patched CVE-2025-43300, an out-of-bounds write in the ImageIO framework exploited in spyware attacks against…

Aug 06, 2026views - 1.3k

VULNZERO-DAY

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility

Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…

Aug 06, 2026views - 1.1k