// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNEXPLOIT

Multi-vendor patch day: public exploit for Firefox, four critical vendors

Mozilla confirms public exploit code for two Firefox flaws. Google, Adobe, and VMware ship critical patches on July 15, 2026. No activ…

Jul 24, 2026views - 1.3k

CYBERSEC

SEBI Fines CDSL ₹1 Crore: LockBit Attack Was 'Foreseeable Outcome' of Systemic Failures

India's securities regulator SEBI has fined Central Depository Services Limited (CDSL) ₹1 crore for cybersecurity lapses that enabled…

Jul 24, 2026views - 1.8k

CYBERSECZERO-DAY

Microsoft Patch Tuesday July 2026: Two Zero-Days, and the CVSS 5.3 Is More Dangerous Than the 7.8

Microsoft's July 2026 Patch Tuesday addressed 570 CVEs, including two actively exploited zero-days: CVE-2026-56164 in SharePoint Serve…

Jul 23, 2026views - 1.6k

zeroZERO-DAY

AnyDesk 0-Day ZDI-26-400: Vendor Ignored 16 Months of Coordinated Disclosure

ZDI published advisory ZDI-26-400 for CVE-2026-15681, a local denial-of-service vulnerability in AnyDesk rated CVSS 4.7. The vendor re…

Jul 23, 2026views - 1.5k

CYBERSEC

NVIDIAScape: Container Escape in Three Lines of Code in the NVIDIA Toolkit

CVE-2025-23266, rated CVSS 9.0, affects 37% of AI cloud environments. An old-school bug in the NVIDIA Container Toolkit enables privil…

Jul 22, 2026views - 1.3k

CYBERSEC

CISA Overhauls Vulnerability Management: 72-Hour Deadline for High-Risk KEVs

The new CISA directive abandons the one-size-fits-all model of BOD 22-01 and introduces four risk-based variables for prioritizing kno…

Jul 22, 2026views - 1.3k

oracleZERO-DAY

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks

The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

Jul 22, 2026views - 1.4k

CYBERSEC

Accenture Confirms 'Isolated Matter' After Threat Actor '888' Lists 35GB of Data for Sale

Threat actor '888' claims to be selling roughly 35GB of Accenture data, including source code, Azure tokens, and SSH keys. Accenture a…

Jul 21, 2026views - 1.4k

ransomware

Fairlife Halts All U.S. Milk Production: The Ransomware the SEC Didn't Classify as Material

On July 16, 2026, Fairlife, a ~$4 billion Coca-Cola subsidiary, suspended every U.S. plant after ransomware hit 'production-related sy…

Jul 21, 2026views - 1.2k

CYBERSECCRITICAL

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter

CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Jul 20, 2026views - 1.4k

CYBERSECCVE

Zoom Patches CVE-2026-53412: Critical Remote Account Takeover on Windows, CVSS 9.8

Zoom has patched a critical vulnerability in its Windows client that allows unauthenticated, zero-interaction account takeover. The fl…

Jul 20, 2026views - 1.5k

CYBERSECCVE

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files

A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

Jul 20, 2026views - 1.4k