// 2 CRITICAL · 3 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

Apple Patches macOS RCE Vulnerability in USD Library (ZDI-26-314)

A critical out-of-bounds write in the macOS USD library could allow remote code execution through malicious 3D files. Apple released a…

May 23, 2026views - 141

VULNZERO-DAY

macOS USD Library Bug ZDI-26-315 Exposes System Memory, Patch Issued May 12

Apple has addressed ZDI-26-315, an out-of-bounds read vulnerability in the macOS Universal Scene Description (USD) library. Rated CVSS…

May 23, 2026views - 148

phishing

M365 Phishing: How Kali365 and EvilTokens Bypass MFA Without Passwords

Two emerging Phishing-as-a-Service (PhaaS) platforms are leveraging device code phishing and OAuth consent abuse to hijack Microsoft 3…

May 22, 2026views - 456

malware

18 Malicious AI Extensions Exposed: Unit 42 Details Email Spying and RAT Risks

Palo Alto Networks Unit 42 has uncovered 18 AI browser extensions that masquerade as productivity tools while deploying RATs and spyin…

May 21, 2026views - 134

CYBERSEC

Chrome Internal Bug Reports Surge to 200+ as Google Leans on AI

Google addressed more than 200 internally discovered vulnerabilities in Chrome between March and May 2026. The spike aligns with the c…

May 21, 2026views - 152

CYBERSECZERO-DAY

Microsoft Defender Zero-Days Under Active Attack; CISA Mandates Patching by June 3

Microsoft has confirmed that two vulnerabilities in Microsoft Defender are being actively exploited in the wild. CISA has added both f…

May 21, 2026views - 202

microsoft

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agent Workflows

Microsoft has unveiled two open-source security tools for AI agents: RAMPART, a Pytest-native framework for build-time testing, and Cl…

May 20, 2026views - 173

CYBERSEC

1Password and OpenAI Partner to Provide Just-in-Time Credentials for AI Agents

1Password integrates its Environments MCP Server into OpenAI's Codex, enabling just-in-time credentialing for AI coding agents to prev…

May 20, 2026views - 162

CYBERSEC

GitHub Breach: 3,800 Internal Repositories Stolen via Malicious VS Code Extension

GitHub has confirmed a security breach affecting approximately 3,800 internal repositories after an employee device was compromised by…

May 20, 2026views - 507

CYBERSECZERO-DAY

BitLocker Bypassed: New Zero-Day Trio Targets Windows Following Patch Tuesday

An analysis of the YellowKey, GreenPlasma, and MiniPlasma vulnerabilities disclosed shortly after the May 2026 Patch Tuesday, impactin…

May 20, 2026views - 195

CYBERSEC

Microsoft Neutralizes Fox Tempest: Malware-Signing-as-a-Service Operation Dismantled

Microsoft has disrupted Fox Tempest, a sophisticated 'Malware-Signing-as-a-Service' operation that leveraged stolen identities to expl…

May 20, 2026views - 99

cybersec

Microsoft Dismantles Fox Tempest: The Takedown of a Global Malware-Signing Syndicate

Microsoft’s Digital Crimes Unit has seized the infrastructure of Fox Tempest, a major 'malware-signing-as-a-service' provider that ena…

May 19, 2026views - 107