// 1 CRITICAL · 3 ZERO-DAY · 3 CVE · 4 EXPLOIT IN THE LAST 24H
phishing

The Microsoft 365 Account Takeover That Leaves No Trace

Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…

Aug 10, 2026views - 1.2k

aiCVE

CVE-2025-23266: NVIDIA Container Escape in Three Lines of Dockerfile

NVIDIA's GPU orchestration toolkit contains a critical vulnerability enabling container escape and privilege escalation on cloud AI in…

Aug 09, 2026views - 1.2k

CYBERSECEXPLOIT

Adobe ColdFusion: Active Exploit in 2 Hours, Critical Patch for CVE-2026-48282

CVE-2026-48282 in ColdFusion carries a maximum CVSS 10.0 score with in-the-wild exploitation detected within two hours. CCCS confirms…

Aug 09, 2026views - 1.3k

CYBERSEC

China Launches Security Review of Palo Alto Networks: Self-Censorship Failed to Work

The Cyberspace Administration of China (CAC) opened a national security review of Palo Alto Networks products on August 6, 2026. The m…

Aug 09, 2026views - 1.3k

VULNCRITICAL

Heimdall Data: Root RCE in Database Proxy Poses Infrastructure-Wide Risk

ZDI-26-479 reveals a directory traversal flaw in the uploadJar method of Heimdall Data Database Proxy. Authentication is required, but…

Aug 08, 2026views - 1.2k

CYBERSECEXPLOIT

TrueConf Becomes Strategic Chokepoint: Compromised Servers Infect Clients

At least three distinct attack campaigns — attributed to Ukrainian hacktivists and Chinese threat actors — have compromised on-premise…

Aug 08, 2026views - 1.2k

malware

VoidLink: The Cloud-Native Malware Turning Linux into an Attack SaaS

Check Point Research discovered VoidLink in December 2025, a cloud-native Linux malware framework written in Zig with 30-plus plugins,…

Aug 08, 2026views - 1.3k

CYBERSEC

Swiss Federal SharePoint Breach Compromises 200 Accounts

The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

Aug 07, 2026views - 1.1k

CYBERSECZERO-DAY

Zapscape: Hyunwoo Kim's Third KVM Escape Raises Systemic Security Questions

CVE-2026-64561 is a use-after-free in the KVM/x86 shadow MMU discovered by Hyunwoo Kim. It allows a kernel-privileged L1 guest to brea…

Aug 07, 2026views - 1.1k

ransomware

Kodak Confirms 'Limited' Breach, but ShinyHunters Claims 2.2 Million Records

Kodak acknowledged unauthorized access to a 'limited amount' of corporate data on June 18, 2026, but did not verify the 2.2 million re…

Aug 06, 2026views - 1.2k

phishing

Greatness PhaaS Bypasses M365 MFA by Abusing Whitelists

The Greatness Phishing-as-a-Service platform has evolved beyond credential theft to advanced adversary-in-the-middle and device-code p…

Aug 06, 2026views - 1.2k

CYBERSECCRITICAL

VMware vCenter Hit by Two Critical Flaws With No Workarounds: The Remediation Plan

Broadcom has patched two critical vulnerabilities in vCenter Server, both rated CVSS 9.8. No workarounds exist for CVE-2026-59309 and…

Aug 06, 2026views - 1.2k