// 1 CRITICAL · 2 ZERO-DAY · 6 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

Microsoft Defender Zero-Days Under Active Attack; CISA Mandates Patching by June 3

Microsoft has confirmed that two vulnerabilities in Microsoft Defender are being actively exploited in the wild. CISA has added both f…

May 21, 2026views - 215

microsoft

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agent Workflows

Microsoft has unveiled two open-source security tools for AI agents: RAMPART, a Pytest-native framework for build-time testing, and Cl…

May 20, 2026views - 180

CYBERSEC

1Password and OpenAI Partner to Provide Just-in-Time Credentials for AI Agents

1Password integrates its Environments MCP Server into OpenAI's Codex, enabling just-in-time credentialing for AI coding agents to prev…

May 20, 2026views - 171

CYBERSEC

GitHub Breach: 3,800 Internal Repositories Stolen via Malicious VS Code Extension

GitHub has confirmed a security breach affecting approximately 3,800 internal repositories after an employee device was compromised by…

May 20, 2026views - 519

CYBERSECZERO-DAY

BitLocker Bypassed: New Zero-Day Trio Targets Windows Following Patch Tuesday

An analysis of the YellowKey, GreenPlasma, and MiniPlasma vulnerabilities disclosed shortly after the May 2026 Patch Tuesday, impactin…

May 20, 2026views - 219

CYBERSEC

Microsoft Neutralizes Fox Tempest: Malware-Signing-as-a-Service Operation Dismantled

Microsoft has disrupted Fox Tempest, a sophisticated 'Malware-Signing-as-a-Service' operation that leveraged stolen identities to expl…

May 20, 2026views - 107

cybersec

Microsoft Dismantles Fox Tempest: The Takedown of a Global Malware-Signing Syndicate

Microsoft’s Digital Crimes Unit has seized the infrastructure of Fox Tempest, a major 'malware-signing-as-a-service' provider that ena…

May 19, 2026views - 114

patchZERO-DAY

May Patch Tuesday: A Rare Zero-Day Break Amid Record AI Discovery Volumes

Microsoft’s May 2026 update ends a two-year streak of active zero-days, patching approximately 137 vulnerabilities. However, the integ…

May 19, 2026views - 151

zeroZERO-DAY

Active Exchange Zero-Day: Unpatched OWA Vulnerability Under Exploitation

Microsoft has confirmed CVE-2026-42897, a zero-day XSS vulnerability in on-premise Exchange servers currently under active attack. Wit…

May 18, 2026views - 169

CYBERSEC

CISA Contractor Exposed AWS GovCloud Credentials and Plaintext Passwords on GitHub for Months

A federal contractor at Nightwing exposed administrative AWS GovCloud credentials and internal passwords in plaintext on GitHub for ov…

May 18, 2026views - 219

VULNCRITICAL

Safari Regex Engine Vulnerability Allows Remote Code Execution via Duplicate Named Groups

Apple has patched a high-severity (CVSS 8.8) remote code execution vulnerability in Safari. The flaw involves a heap-based buffer over…

May 18, 2026views - 107

VULNCRITICAL

Apple Safari WebCore Vulnerability: ZDI-26-312 Enables Remote Code Execution

A use-after-free vulnerability in Safari’s WebCore style resolver allows for remote code execution through user interaction, affecting…

May 16, 2026views - 147