// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Microsoft Patch Tuesday: Legacy MSMQ Flaw Enables Local SYSTEM Escalation

The May 12, 2026, security update addresses CVE-2026-33838, an elevation-of-privilege vulnerability in Windows Message Queuing (MSMQ).…

May 15, 2026views - 258

VULNCRITICAL

GitHub Enterprise RCE: A Single 'git push' Puts Corporate Backends at Risk

CVE-2026-3854 allows Remote Code Execution on GitHub Enterprise Server via user-controlled push options. Reports indicate that 88% of…

May 15, 2026views - 171

CYBERSECZERO-DAY

Microsoft Exchange Zero-Day Exploited: Permanent Patch Restricted to ESU Customers

Microsoft has confirmed active in-the-wild exploitation of CVE-2026-42897 affecting Exchange on-premise servers. CISA has issued a hig…

May 15, 2026views - 233

CYBERSEC

Mistral AI Hit by Supply Chain Attack; 450 Repositories Put Up for Sale

Mistral AI has confirmed a supply chain compromise involving contaminated SDKs and abused SLSA provenance. The threat actor TeamPCP is…

May 14, 2026views - 264

zeroZERO-DAY

Cisco SD-WAN Zero-Day: 'Ghost Peers' Infiltrated Controllers Since 2023

CVE-2026-20127 in Cisco Catalyst SD-WAN controllers allowed a sophisticated threat actor to impersonate trusted peers for over three y…

May 14, 2026views - 252

VULNCRITICAL

GitHub RCE: Crafted 'git push' Commands Compromised Backend Servers

CVE-2026-3854: An X-Stat header injection vulnerability in GitHub enabled remote code execution via a single push operation. Approxima…

May 14, 2026views - 165

CYBERSECCRITICAL

Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents

Microsoft’s MDASH, an agentic multi-model system, discovered 16 vulnerabilities—including four critical RCEs—patched in the May 2026 u…

May 13, 2026views - 1.3k

VULNCRITICAL

Exim 'Dead.Letter' Vulnerability: Critical RCE Risk for GnuTLS-Based Builds

CVE-2026-45185 is a use-after-free vulnerability in the Exim SMTP BDAT parser that allows unauthenticated RCE on GnuTLS-compiled serve…

May 13, 2026views - 185

ransomware

Foxconn Confirms North American Cyberattack; Nitrogen Ransomware Group Claims 8TB Data Breach

Foxconn has confirmed a cyberattack affecting several of its North American facilities. The Nitrogen ransomware group claims to have e…

May 13, 2026views - 201

ransomware

West Pharmaceutical Services Hit by Ransomware, Disrupting Global Operations

West Pharmaceutical Services has confirmed a ransomware attack involving data exfiltration and systemic encryption, causing significan…

May 13, 2026views - 179

VULNCRITICAL

Critical GitHub RCE: A Single Git Push Can Trigger Remote Code Execution

A critical RCE vulnerability (CVE-2026-3854) affecting GitHub.com and Enterprise Server allows arbitrary code execution via crafted gi…

May 13, 2026views - 207

phishing

Active OAuth Redirection Attacks Targeting Government Entities via Entra ID

Microsoft has identified a phishing campaign exploiting OAuth 2.0 flows to deliver multi-stage malware to public sector organizations,…

May 12, 2026views - 200