// 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
VULNZERO-DAY

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates

The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…

Jul 31, 2026views - 1.2k

CYBERSECZERO-DAY

Microsoft Patches RoguePlanet, the Defender Black Hole That Handed SYSTEM to Anyone

CVE-2026-50656: a race condition in the Windows 10 and 11 antivirus engine let a standard user gain SYSTEM privileges. The silent engi…

Jul 30, 2026views - 1.3k

CYBERSECZERO-DAY

OWAReaper: The Malware That Survives Device Reimaging

Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

Jul 30, 2026views - 1.2k

VULNCRITICAL

macOS USD Library Buffer Overflow Enables RCE via Malicious 3D Files

CVE-2026-43729 is a heap-based buffer overflow in Apple's USD library that allows arbitrary code execution through crafted 3D scene fi…

Jul 29, 2026views - 1.3k

VULNZERO-DAY

WhatsApp's CVSS 5.4 Falls Short: Zero-Click Surveillance Lurks Behind the Score

WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization flaw in Linked Devices…

Jul 28, 2026views - 1.1k

CYBERSECCVE

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action

Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Jul 28, 2026views - 1.2k

phishing

Kratos Phishing Kit Dismantled: 200 Servers Seized, but AiTM Code Remains in Circulation

German, U.S., and Indonesian authorities took down the Kratos phishing kit, seizing over 200 servers and arresting the alleged develop…

Jul 28, 2026views - 1.2k

CYBERSEC

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA

Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

Jul 28, 2026views - 1.2k

CYBERSECEXPLOIT

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls

The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Jul 27, 2026views - 1.1k

microsoftZERO-DAY

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint

The July 14, 2026 Patch Tuesday sets a record with 570 CVEs patched, two actively exploited zero-days, and a third publicly disclosed.…

Jul 27, 2026views - 1.1k

VULNZERO-DAY

Apple Patches iOS 26 dyld Zero-Day: Targeted Attacks Already Underway

Apple has released iOS 26.3 to address CVE-2026-20700, a zero-day vulnerability in the dyld component exploited in sophisticated attac…

Jul 27, 2026views - 1.3k

cybersecZERO-DAY

LegacyHive: Zero-Day Windows Flaw Patched by 0Patch Before Microsoft

The LegacyHive vulnerability in the Windows User Profile Service enables local privilege escalation. ACROS Security has released free…

Jul 26, 2026views - 1.1k