// 1 CRITICAL · 4 ZERO-DAY · 7 CVE · 9 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

Cisco Confirms FMC Zero-Day: Static Credentials Under Attack, CISA Sets August 1 Deadline

Cisco confirms active exploitation of CVE-2026-20316 in Secure Firewall Management Center. CISA adds the flaw to its KEV catalog, mand…

Aug 03, 2026views - 1.2k

CYBERSECZERO-DAY

F5 Races Against Its Own Stolen Code: 45 Vulnerabilities Disclosed in a Single Quarter

Nation-state actors compromised F5's internal systems, exfiltrating portions of BIG-IP proprietary source code and details on undisclo…

Aug 03, 2026views - 1.1k

CYBERSECCRITICAL

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8

Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

Aug 03, 2026views - 1.1k

CYBERSEC

Estée Lauder's 10-Month Oracle EBS Breach: The Suspected Patch Gap That Let Clop In

Estée Lauder disclosed a 10-month breach of its Oracle E-Business Suite HR system. The Clop ransomware group exploited CVE-2025-61882,…

Aug 02, 2026views - 1.1k

CYBERSECCVE

TrendAI Vision One and the 'Historical' CVE-2025-71387: Patched in December

Trend Micro published bulletin KA-0023937 for CVE-2025-71387, a privilege escalation vulnerability in TrendAI Vision One that was alre…

Aug 02, 2026views - 1.1k

CYBERSEC

Kemp LoadMaster: Hard-Coded Key in enablexroot Exposes Appliance to Root

Progress Software has patched CVE-2026-59689, a CVSS 8.0 privilege-escalation vulnerability in Kemp LoadMaster caused by a hard-coded…

Aug 02, 2026views - 1.1k

CYBERSEC

TransUnion, the SaaS Periphery Paradox: 4.4 Million SSNs Exposed via Third-Party OAuth App

Credit bureau TransUnion disclosed a data breach exposing 4,461,511 unredacted Social Security Numbers. The vector was not a direct in…

Aug 02, 2026views - 1.2k

CYBERSECCRITICAL

Adobe Campaign Classic: Critical CVSS 10.0 Patch for On-Premise Deployments

Adobe has fixed CVE-2026-48449, a maximum-severity vulnerability in Campaign Classic that allows unauthenticated remote code execution…

Aug 01, 2026views - 1.2k

phishing

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365

Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Aug 01, 2026views - 651

ransomware

Ransomware in Vietnam: A 2.56% Drop Masks a More Insidious Threat

Kaspersky's Q1 2026 report shows fewer Vietnamese SMEs hit by ransomware, but experts warn the threat has shifted to earlier intrusion…

Aug 01, 2026views - 608

CYBERSECCVE

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine

F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

Jul 31, 2026views - 583

CYBERSECZERO-DAY

Check Point's Firewall Brain Has a Trust-System Flaw

An authentication bypass in Check Point SmartConsole enables remote administrative access. CISA has mandated patching by July 25 for U…

Jul 31, 2026views - 1.3k