// 2 CRITICAL · 3 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSEC

Klue Supply Chain Compromised, Icarus Hacked, Data in Circulation

The Klue-Salesforce supply chain breach now spans roughly two dozen confirmed victims. The extortion group Icarus, which claimed respo…

Jun 27, 2026views - 1.6k

CYBERSEC

Burnyard: Local Malware Analysis Beats Cloud on Speed, But Accuracy Remains Unverified

Ohio State University's Burnyard project challenges VirusTotal and Sophos Intelix with user-space emulation on local hardware, deliver…

Jun 26, 2026views - 806

ransomware

Ransomware: Europe Overtakes US as Top Target With 55% Surge in Attacks

Black Kite's first Europe-focused report reveals 684 ransomware attacks in the first four months of 2026, a 55.1% year-over-year incre…

Jun 25, 2026views - 1.3k

CYBERSEC

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack

Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

Jun 25, 2026views - 704

VULN

macOS: Standard Users Disable EDR/MDM Without Admin Rights

A privilege escalation technique on macOS exploits CDHash caching and NIB injection to silently disable enterprise security tools. App…

Jun 24, 2026views - 975

ransomware

Bajaj Auto’s Silent Ransomware: What Lies Behind the ‘Successful Mitigation’ Claim

Bajaj Auto disclosed a June 23, 2026 ransomware incident without naming the threat actor, strain, or impact. The case exposes the limi…

Jun 24, 2026views - 760

VULNCVE

Path Traversal in Allegra: CVE-2026-11442 Exposes Arbitrary Files

The ZDI-26-357 vulnerability in Allegra's exportReport method allows an authenticated remote attacker to read arbitrary files via path…

Jun 24, 2026views - 915

CYBERSECEXPLOIT

TTP-Chain Validation: Proving Exploitability Without an Exploit

A Picus Security engineer proposes TTP-chain validation to test CVE exploitability without live exploits, as the disclosure-to-exploit…

Jun 23, 2026views - 1.4k

CYBERSEC

LastPass Breached via Klue Supply-Chain Attack: Customer Data Stolen, Vaults Intact

LastPass confirms a supply-chain breach through market-intelligence vendor Klue: stolen OAuth tokens granted access to LastPass's Sale…

Jun 23, 2026views - 1.5k

openai

OpenAI Shifts the Remediation Paradox: From Finding Bugs to Patching Them

OpenAI releases GPT-5.5-Cyber and the Patch the Planet initiative. AI has solved vulnerability discovery, creating a larger problem: t…

Jun 23, 2026views - 1.1k

phishing

Xsolis Phishing Breach Exposes 1.4 Million PHI Records

Xsolis took five months to disclose the full scope of a January 2026 phishing attack. The HHS breach tracker revealed 1,396,519 affect…

Jun 23, 2026views - 953

CYBERSEC

SonicWall: CVE Patched, but Risk Persists Across All 14 Audited Firewalls

A SANS audit of 14 SonicWall Gen7 firewalls shows the CVE-2024-40766 firmware patch fixed the bug, but 12 of 14 devices retained stale…

Jun 23, 2026views - 1.1k