// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECEXPLOIT

Trend Micro: CISA Adds Exploited Apex One Zero-Day to KEV Catalog with June 4 Deadline

CVE-2026-34926 affects on-premise Apex One installations. This directory traversal zero-day is under active exploitation, prompting CI…

May 25, 2026views - 263

CYBERSEC

DocketWise Data Breach: 143,480 Impacted via Third-Party Repository Exposure

Legal-tech platform DocketWise has notified 143,480 individuals of a data breach involving cloned third-party repositories. The incide…

May 25, 2026views - 204

CYBERSEC

The Oncology Institute Discloses Patient Data Breach Linked to Third-Party Vendor

The Oncology Institute (TOI) confirmed in an SEC filing that unauthorized actors accessed patient data through a third-party software…

May 25, 2026views - 243

VULNCRITICAL

CISA Adds Critical Langflow Vulnerability (CVE-2025-34291) to KEV Catalog Following Active Exploitation

CISA has added CVE-2025-34291, a critical origin validation flaw in the Langflow platform, to its Known Exploited Vulnerabilities cata…

May 24, 2026views - 261

ransomware

Ransomware 2026: Post-Quantum Ciphers, Encryptionless Extortion, and the Rise of EDR-Killers

The 2026 ransomware landscape is defined by the adoption of post-quantum algorithms and a shift toward encryptionless extortion, with…

May 23, 2026views - 307

CYBERSEC

GitLab 19.0 Debuts Native Secrets Management and Air-Gapped AI

GitLab 19.0 integrates native secrets management, agentic merge request workflows, and self-hosted AI models, reinforcing its 'single…

May 22, 2026views - 219

CYBERSEC

30-Minute Lateral Breakouts: Why the SOC is Losing the Race Against AI-Driven Threats

Average breakout times have accelerated by 29%, with the fastest recorded exfiltration dropping from over four hours to just six minut…

May 22, 2026views - 226

CYBERSEC

PoC Zealot: Autonomous AI Executes End-to-End GCP Cloud Attack

Unit 42’s Zealot project demonstrates how multi-agent AI systems can autonomously chain SSRF, credential theft, and BigQuery exfiltrat…

May 21, 2026views - 228

ai

Trust3 AI Launches MCP Security: A Hardened Control Plane or Just Another Promise?

Trust3 AI has announced MCP Security to protect enterprise agentic workloads, focusing on connection verification, isolated tokens, an…

May 20, 2026views - 230

CYBERSEC

AI-Driven Mobile Attacks Hit New Record: Apps Compromised Within Two Hours of Release

The Digital.ai 2026 App Security Threat Report reveals that 87% of client-facing applications are now under systematic attack, with th…

May 20, 2026views - 220

CYBERSEC

CISA Faces Congressional Scrutiny After Months-Long AWS GovCloud Credential Leak on GitHub

Senator Maggie Hassan has demanded a classified briefing from CISA following the discovery of a public GitHub repository that exposed…

May 20, 2026views - 258

agentic

AI Agents in Production: Addressing the Confused-Deputy Threat in Operational Automation

New research identifies a critical architectural gap in operational AI agents where a lack of separation between reasoning and executi…

May 20, 2026views - 186