// 2 CRITICAL · 2 ZERO-DAY · 8 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSEC

PNLD Data Breach: UK Police Contacts Published on Dark Web July 26

The Police National Legal Database confirms the exfiltration of names, organizations, and work emails of officers, government staff, a…

Aug 04, 2026views - 1.3k

CYBERSEC

Pass-ta-key Exposes the Gap Between FIDO2 Cryptography and Windows Implementation

Unit 42 reveals three post-compromise techniques that bypass PIN and biometrics on Chrome for Windows. Passkeys resist phishing, not m…

Aug 04, 2026views - 1.2k

phishing

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'

Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Aug 03, 2026views - 1.2k

CYBERSEC

Midnight Blizzard Turns Hotel Wi-Fi Into a Trap for Corporate Travelers

Storm-2945, a Midnight Blizzard sub-cluster, compromises captive portal networks worldwide to deliver the CornFlake RAT and steal Micr…

Aug 03, 2026views - 1.2k

CYBERSEC

Hotel DNS Attacks: Corporate VPNs Aren't Enough to Protect Microsoft 365

ReliaQuest has documented an active campaign since June 2026 that compromises hotel Wi-Fi gateways to redirect Microsoft 365 logins to…

Aug 03, 2026views - 1.3k

CYBERSEC

May 2026 Patch Tuesday: 161 CVEs, No Zero-Days, But Wormable Risks Loom

Microsoft's May 2026 Patch Tuesday fixes 161 vulnerabilities with no actively exploited zero-days — the first such month since June 20…

Aug 03, 2026views - 1.2k

CYBERSECCRITICAL

Apple Patches ImageIO: Parsing Bug Opens Door to RCE Across Eight Operating Systems

A flaw in Apple's ImageIO framework allows remote code execution via malformed image files. Patches are available for eight operating…

Aug 02, 2026views - 1.2k

phishing

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365

Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Aug 01, 2026views - 734

phishing

Kratos Dismantled: AiTM Code Remains in Hands of 1,800 Criminals

German and U.S. authorities seized over 200 servers linked to the Kratos phishing-as-a-service kit, but the source code still circulat…

Aug 01, 2026views - 709

CYBERSECEXPLOIT

Record Patch Tuesday: Microsoft Fixes 622 Bugs, Two Zero-Days Already Exploited

Microsoft's July 2026 Patch Tuesday sets an all-time high with 622 CVEs patched, including two actively exploited zero-days in SharePo…

Jul 31, 2026views - 1.3k

VULNZERO-DAY

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates

The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…

Jul 31, 2026views - 1.3k

CYBERSECZERO-DAY

Microsoft Patches RoguePlanet, the Defender Black Hole That Handed SYSTEM to Anyone

CVE-2026-50656: a race condition in the Windows 10 and 11 antivirus engine let a standard user gain SYSTEM privileges. The silent engi…

Jul 30, 2026views - 1.4k