// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Grafana Labs Breach: Forgotten Workflow Token Exposes Internal Repositories

Grafana Labs has disclosed a security breach involving its GitHub repositories after an overlooked CI/CD token—missed during an emerge…

May 20, 2026views - 193

agentic

Zealot: How Autonomous AI Orchestrates Multi-Stage Cloud Compromise

Palo Alto Networks’ Unit 42 has demonstrated Zealot, a multi-agent PoC capable of executing end-to-end cloud attack chains without hum…

May 20, 2026views - 189

CYBERSEC

Microsoft Neutralizes Fox Tempest: Malware-Signing-as-a-Service Operation Dismantled

Microsoft has disrupted Fox Tempest, a sophisticated 'Malware-Signing-as-a-Service' operation that leveraged stolen identities to expl…

May 20, 2026views - 183

CYBERSEC

7-Eleven Confirms Data Breach After ShinyHunters Leaks 9.4GB of Files

7-Eleven has officially confirmed a cyberattack originating in April 2026. Following a failed ransom negotiation with the ShinyHunters…

May 19, 2026views - 512

zeroZERO-DAY

Active Exchange Zero-Day: Unpatched OWA Vulnerability Under Exploitation

Microsoft has confirmed CVE-2026-42897, a zero-day XSS vulnerability in on-premise Exchange servers currently under active attack. Wit…

May 18, 2026views - 251

CYBERSEC

CISA Contractor Exposed AWS GovCloud Credentials and Plaintext Passwords on GitHub for Months

A federal contractor at Nightwing exposed administrative AWS GovCloud credentials and internal passwords in plaintext on GitHub for ov…

May 18, 2026views - 289

CYBERSEC

ShinyHunters: A Serial Extortion Campaign Targets Enterprise SaaS (May 2026)

Between May 7 and May 18, 2026, ShinyHunters targeted Canvas, 7-Eleven, and Grafana in a high-profile data extortion spree. While Inst…

May 18, 2026views - 210

CYBERSEC

Grafana Refuses Ransom Following GitHub Token Theft and Codebase Breach

Grafana Labs has confirmed that a stolen GitHub access token allowed attackers to exfiltrate its source code. Despite extortion attemp…

May 18, 2026views - 210

CYBERSECCRITICAL

GitHub Enterprise RCE: Critical Vulnerability (CVE-2026-3854) Demands Immediate Updates

A flaw in GitHub’s push options handling allows for Remote Code Execution on Enterprise Server instances. With technical details now p…

May 17, 2026views - 235

CYBERSECEXPLOIT

Grafana Labs Hit by GitHub Breach: Source Code Stolen, Ransom Demands Rejected

Grafana Labs has confirmed a breach of its GitHub environment via a 'Pwn Request' vulnerability. While attackers exfiltrated proprieta…

May 17, 2026views - 739

VULNCRITICAL

Ivanti EPMM RCE Under Active Exploitation as Federal Patch Deadline Lapses

CVE-2026-6973, a critical RCE vulnerability in Ivanti EPMM on-premise, is currently being exploited in the wild. The CISA remediation…

May 16, 2026views - 171

patchCRITICAL

May 2026 Patch Tuesday: 137 Vulnerabilities Addressed, No Zero-Days Found Despite Critical DNS RCE

Microsoft has patched 137 vulnerabilities in its May 2026 security update. While no active exploits have been detected, critical unaut…

May 16, 2026views - 230