// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

CISA Contractor Exposed AWS GovCloud Credentials and Plaintext Passwords on GitHub for Months

A federal contractor at Nightwing exposed administrative AWS GovCloud credentials and internal passwords in plaintext on GitHub for ov…

May 18, 2026views - 289

VULNCRITICAL

Safari Regex Engine Vulnerability Allows Remote Code Execution via Duplicate Named Groups

Apple has patched a high-severity (CVSS 8.8) remote code execution vulnerability in Safari. The flaw involves a heap-based buffer over…

May 18, 2026views - 169

VULNCRITICAL

Apple Safari WebCore Vulnerability: ZDI-26-312 Enables Remote Code Execution

A use-after-free vulnerability in Safari’s WebCore style resolver allows for remote code execution through user interaction, affecting…

May 16, 2026views - 224

patchCRITICAL

May 2026 Patch Tuesday: 137 Vulnerabilities Addressed, No Zero-Days Found Despite Critical DNS RCE

Microsoft has patched 137 vulnerabilities in its May 2026 security update. While no active exploits have been detected, critical unaut…

May 16, 2026views - 230

CYBERSEC

Microsoft Patch Tuesday: Legacy MSMQ Flaw Enables Local SYSTEM Escalation

The May 12, 2026, security update addresses CVE-2026-33838, an elevation-of-privilege vulnerability in Windows Message Queuing (MSMQ).…

May 15, 2026views - 258

zeroEXPLOIT

Apple Fixes WebKit Zero-Days Exploited in 'Extremely Sophisticated' Attacks

Apple has issued emergency security updates for Safari 26.2 and iOS 18.7.3 to remediate two critical WebKit vulnerabilities (CVE-2025-…

May 15, 2026views - 286

CYBERSECZERO-DAY

Microsoft Exchange Zero-Day Exploited: Permanent Patch Restricted to ESU Customers

Microsoft has confirmed active in-the-wild exploitation of CVE-2026-42897 affecting Exchange on-premise servers. CISA has issued a hig…

May 15, 2026views - 233

CYBERSEC

May Patch Tuesday: AI-Driven Discovery Pushes 2026 Vulnerability Count Past 500

Microsoft's May 12, 2026, update addresses more than 130 vulnerabilities, revealing the impact of its internal MDASH AI system. The to…

May 14, 2026views - 214

CYBERSEC

May 2026 Patch Tuesday: AI-Driven Discovery Marks a Turning Point in Vulnerability Management

Microsoft and industry partners address over 130 vulnerabilities as AI systems like MDASH and Project Glasswing accelerate the discove…

May 13, 2026views - 197

CYBERSECCRITICAL

Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents

Microsoft’s MDASH, an agentic multi-model system, discovered 16 vulnerabilities—including four critical RCEs—patched in the May 2026 u…

May 13, 2026views - 1.3k

zeroZERO-DAY

BitLocker Zero-Day: Encrypted Drives Unlocked via USB and WinRE — No Credentials Needed

A new proof-of-concept named YellowKey enables BitLocker bypasses on Windows 11 and Server editions by exploiting the Windows Recovery…

May 13, 2026views - 688

patchCRITICAL

Microsoft May Patch Tuesday Fixes 120 Flaws, but DNS and Dynamics 365 Bugs Demand Priority

Microsoft’s May 2026 update fixes roughly 120 vulnerabilities, targeting critical gaps in DNS, Dynamics 365, and Office components. Wh…

May 13, 2026views - 180