// 1 ZERO-DAY · 3 CVE · 3 EXPLOIT IN THE LAST 24H
openaiZERO-DAY

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face

OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

Jul 29, 2026views - 1.2k

CYBERSECCVE

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action

Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Jul 28, 2026views - 1.2k

ransomware

Spirals: New Rust Ransomware Deployed Across Enterprise Network in Under 24 Hours

The Symantec Threat Hunter Team has documented Spirals, a Rust-based ransomware using ECDH+AES hybrid encryption. An attack in South A…

Jul 28, 2026views - 1.2k

oracle

Oracle Smashes the Thousand-Patch Ceiling: Enterprise Vulnerability Management Under Strain

Oracle released a record 1,449 security patches in July 2026, nearly tripling the previous high. The volume exposes the unsustainabili…

Jul 28, 2026views - 1.2k

infostealerEXPLOIT

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector

Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

Jul 27, 2026views - 1.2k

CYBERSECEXPLOIT

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls

The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Jul 27, 2026views - 1.1k

microsoftZERO-DAY

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint

The July 14, 2026 Patch Tuesday sets a record with 570 CVEs patched, two actively exploited zero-days, and a third publicly disclosed.…

Jul 27, 2026views - 1.2k

ransomware

Stadler Rejects $12.3M Ransom: Everest Fails to Leak Data

Swiss rail manufacturer Stadler Rail publicly refused a 10 million Swiss franc ($12.3 million) ransom demand from the Everest ransomwa…

Jul 26, 2026views - 1.2k

VULN

MSI Center's Ghost Driver: Local Escalation to SYSTEM in One Command

ZDI-26-430 discloses an origin validation flaw in the MSI Center kernel driver NTIOLib_X64.sys, tracked as CVE-2026-6102 (CVSS 7.8). A…

Jul 26, 2026views - 1.2k

VULNCRITICAL

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough

CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Jul 26, 2026views - 1k

VULNCRITICAL

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE

Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Jul 25, 2026views - 1.1k

infostealer

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches

On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

Jul 25, 2026views - 1.3k