// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
rceCVE

CVE-2026-3854: Critical GitHub RCE Leaves 88% of On-Premise Servers Exposed

Wiz Research has detailed CVE-2026-3854, a critical RCE vulnerability in GitHub’s internal Git pipeline. While GitHub.com was patched…

May 13, 2026views - 195

phishing

Active OAuth Redirection Attacks Targeting Government Entities via Entra ID

Microsoft has identified a phishing campaign exploiting OAuth 2.0 flows to deliver multi-stage malware to public sector organizations,…

May 12, 2026views - 200

CYBERSEC

Why an Active Directory Password Reset Isn't Enough to Evict an Attacker

A simple Active Directory password reset often fails to eliminate persistence. Valid Kerberos tickets, local hash caching, and ACL-bas…

May 11, 2026views - 365

CYBERSEC

Weaponized OAuth: Government and Public Sector Targeted in Malicious Redirection Campaign

Microsoft researchers have identified active campaigns abusing OAuth redirection to steer government and public sector entities toward…

May 10, 2026views - 300

CYBERSECEXPLOIT

Google Raises Android Bug Bounty to $15M — Chrome AI Rewards Cut

Google has overhauled its Vulnerability Reward Programs, offering up to $1.5 million for sophisticated Pixel exploits while reducing p…

May 05, 2026views - 235

cybersecCRITICAL

RCE Vulnerability in Gemini CLI and Cursor AI: Details and Patches

Details on the critical severity vulnerability in Gemini CLI, the flaw in Cursor AI, and the hijacking of the Gemini panel in Chrome.…

Apr 30, 2026views - 159

cybersecZERO-DAY

Microsoft Zero-day: The Risk of the Faulty Patch Revealed

Discover the impact of the faulty Microsoft patch that left a new zero-click backdoor in Windows Shell. What to know about CVE-2026-32…

Apr 30, 2026views - 227