// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Why an Active Directory Password Reset Isn't Enough to Evict an Attacker

A simple Active Directory password reset often fails to eliminate persistence. Valid Kerberos tickets, local hash caching, and ACL-bas…

May 11, 2026views - 365

zeroZERO-DAY

Google Report: Enterprise Tech Hit by Record 48% of Zero-Day Exploits in 2025

Google’s GTIG report tracks 90 zero-days exploited in 2025, revealing a strategic pivot toward enterprise infrastructure. Chinese APT…

May 11, 2026views - 245

rceCVE

CVE-2026-3854: Critical RCE Vulnerability in GitHub Triggered via Single ‘git push’

A specifically crafted git push command can execute remote code on GitHub.com and GitHub Enterprise Server. While the cloud environmen…

May 11, 2026views - 528

exploitCRITICAL

Weaver E-cology Under Attack: Critical RCE Exploited via Debug Endpoint

CVE-2026-22679 in Weaver E-cology allows unauthenticated RCE via an exposed debug API. With active exploitation documented since March…

May 09, 2026views - 146

CYBERSEC

NVIDIA Confirms GeForce NOW Data Breach via Armenian Partner

NVIDIA has confirmed that a regional partner in the GeForce NOW Alliance suffered a breach exposing user personal data. While central…

May 09, 2026views - 184

CYBERSEC

Trellix Confirms Source Code Breach as RansomHouse Claims Attack on Internal Infrastructure

Cybersecurity giant Trellix has confirmed unauthorized access to its source code repository following an extortion claim by RansomHous…

May 09, 2026views - 278

CYBERSEC

Zara Data Breach: 197,000 Emails Exposed via Compromised Anodot Tokens

Threat actor ShinyHunters has published a 140 GB Zara dataset allegedly obtained via compromised Anodot authentication tokens. Have I…

May 08, 2026views - 208

CYBERSECZERO-DAY

Ivanti EPMM Zero-Days Under Attack: CISA Mandates Unprecedented 3-Day Patch Deadline

Two unauthenticated RCE zero-days in Ivanti Endpoint Manager Mobile (EPMM) have prompted CISA to issue a rare 72-hour remediation mand…

May 07, 2026views - 203

CYBERSEC

DAEMON Tools Supply Chain Attack: Official Installers Trojanized Since April

Signed installers for DAEMON Tools Lite were caught distributing multi-stage malware for nearly a month. While thousands were infected…

May 06, 2026views - 230

CYBERSEC

MuddyWater Mimics Chaos Ransomware to Conceal Targeted Espionage Operations

A Rapid7 investigation reveals that Iranian threat actor MuddyWater impersonated a Chaos ransomware affiliate in early 2026 to mask es…

May 06, 2026views - 191

malware

BRICKSTORM: CISA and NSA Alert on Evolving Rust Backdoor Targeting vSphere

Cybersecurity agencies have updated their Malware Analysis Report for BRICKSTORM, a sophisticated ELF backdoor targeting VMware vSpher…

May 06, 2026views - 219

CYBERSEC

Multi-Ecosystem Sleeper Packages Target CI Pipelines for Credential Theft and Persistence

At least two distinct campaigns have deployed malicious sleeper packages across RubyGems, npm, and Go modules to harvest developer cre…

May 06, 2026views - 151