// 1 CRITICAL · 2 ZERO-DAY · 3 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSECCVE

CVE-2026-17583: Three Decades of DNA Evidence at Risk of Digital Tampering

A vulnerability in Thermo Fisher software allows undetected alteration of forensic DNA files. The patch does not validate 30 years of…

Aug 15, 2026views - 1.2k

CYBERSECZERO-DAY

Metabase Zero-Day CVE-2026-72898: Active Exploitation, CVSS 10.0, Wide Blast Radius

A maximum-severity CVSS 10.0 zero-day struck Metabase on August 2, 2026. The attack, confirmed against the vendor's cloud infrastructu…

Aug 15, 2026views - 1.7k

CYBERSECZERO-DAY

ShinyHunters Exploited Oracle PeopleSoft Zero-Day for Two Weeks

CVE-2026-35273 hit over 100 notified organizations, 68% universities, via an SSRF-to-unauthenticated-RCE chain. CISA added it to the K…

Aug 15, 2026views - 1.1k

ransomware

Ransomware Q2: 1,140 Industrial Attacks, the New Perimeter Lies in IT Systems

Dragos' Q2 2026 report records 1,140 ransomware incidents against industrial organizations. The key finding: production halts without…

Aug 15, 2026views - 1.2k

CYBERSEC

TeamPCP Compromises LiteLLM: 434,000 Pipelines Exposed in 40 Minutes

TeamPCP injected malicious LiteLLM packages onto PyPI for 40 minutes. CloudSEK estimates 2,500+ organizations exposed. Stolen credenti…

Aug 14, 2026views - 1.2k

CYBERSECCRITICAL

Cisco ISE Authenticated RCE Escalates to Root: The 9.9 CVSS Behind the Method

A critical vulnerability in Cisco Identity Services Engine enables authenticated remote code execution with privilege escalation to ro…

Aug 13, 2026views - 1.1k

CYBERSECCVE

Norton Utilities Ultimate: Local Privilege Escalation to SYSTEM via Symlink, CVE-2024-13962

The ZDI-26-567 vulnerability in the NortonUtilitiesSvc service enables local privilege escalation to SYSTEM through a symlink attack.…

Aug 13, 2026views - 1.1k

VULN

Parallels RAS Client: Local Privilege Escalation to SYSTEM via Exposed Dangerous Function

ZDI advisory ZDI-26-556 discloses a local privilege escalation flaw in the Parallels RAS Client RAS RDP Backend Service. An attacker w…

Aug 12, 2026views - 1.2k

CYBERSEC

Red Hat ACM: Subscription Controller Becomes Bridge for Total Privilege Escalation

A vulnerability in Red Hat Advanced Cluster Management allows users with edit permissions on a single namespace to gain full cluster-a…

Aug 12, 2026views - 1.2k

CYBERSEC

TrendAI Vision One: Log Information Disclosure Fixed After 10 Months

The TrendAI Vision One security platform has closed CVE-2025-71386, an information disclosure vulnerability in Service Gateway logs. H…

Aug 11, 2026views - 1.1k

CYBERSECCRITICAL

WatchGuard FireWare OS: Stack Buffer Overflow Enables Root RCE, Patch Available

A stack-based buffer overflow in the WatchGuard FireWare OS networkd daemon allows remote code execution with root privileges. Tracked…

Aug 11, 2026views - 1.2k

CYBERSEC

Battering RAM: $50 Physical Attack Bypasses SGX and SEV-SNP on DDR4 Systems

A sub-$50 DDR4 interposer compromises confidential computing. Vendors classify physical attacks as out of scope. Article based on a si…

Aug 10, 2026views - 1.2k