// 1 CRITICAL · 6 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

Zapscape: Hyunwoo Kim's Third KVM Escape Raises Systemic Security Questions

CVE-2026-64561 is a use-after-free in the KVM/x86 shadow MMU discovered by Hyunwoo Kim. It allows a kernel-privileged L1 guest to brea…

Aug 07, 2026views - 986

phishing

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'

Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Aug 03, 2026views - 1.1k

CYBERSECCRITICAL

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8

Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

Aug 03, 2026views - 1.1k

CYBERSECCVE

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine

F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

Jul 31, 2026views - 576

CYBERSECCVE

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action

Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Jul 28, 2026views - 1.1k

infostealerEXPLOIT

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector

Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

Jul 27, 2026views - 1.1k

infostealer

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches

On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

Jul 25, 2026views - 1.3k

ransomware

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware

The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Jul 24, 2026views - 1.3k

CYBERSEC

NVIDIAScape: Container Escape in Three Lines of Code in the NVIDIA Toolkit

CVE-2025-23266, rated CVSS 9.0, affects 37% of AI cloud environments. An old-school bug in the NVIDIA Container Toolkit enables privil…

Jul 22, 2026views - 1.2k

CYBERSEC

Accenture Confirms 'Isolated Matter' After Threat Actor '888' Lists 35GB of Data for Sale

Threat actor '888' claims to be selling roughly 35GB of Accenture data, including source code, Azure tokens, and SSH keys. Accenture a…

Jul 21, 2026views - 1.3k

CYBERSECCRITICAL

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter

CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Jul 20, 2026views - 1.4k

agentic

Agentic AI: A Lone Attacker Compromises Enterprise AWS in 72 Hours

Sygnia documents the first operational case of a lone threat actor using AI-assisted workflows to compress an enterprise AWS attack fr…

Jul 08, 2026views - 1.4k