// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
infostealerEXPLOIT

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector

Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

Jul 27, 2026views - 1.2k

CYBERSECEXPLOIT

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls

The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Jul 27, 2026views - 1.1k

microsoftEXPLOIT

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint

The July 14, 2026 Patch Tuesday sets a record with 570 CVEs patched, two actively exploited zero-days, and a third publicly disclosed.…

Jul 27, 2026views - 1.2k

ransomware

Stadler Rejects $12.3M Ransom: Everest Fails to Leak Data

Swiss rail manufacturer Stadler Rail publicly refused a 10 million Swiss franc ($12.3 million) ransom demand from the Everest ransomwa…

Jul 26, 2026views - 1.2k

VULN

MSI Center's Ghost Driver: Local Escalation to SYSTEM in One Command

ZDI-26-430 discloses an origin validation flaw in the MSI Center kernel driver NTIOLib_X64.sys, tracked as CVE-2026-6102 (CVSS 7.8). A…

Jul 26, 2026views - 1.2k

VULNCRITICAL

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough

CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Jul 26, 2026views - 1k

VULNCRITICAL

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE

Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Jul 25, 2026views - 1.1k

infostealer

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches

On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

Jul 25, 2026views - 1.3k

CYBERSEC

Wind Tre Fined €1.7M: Social Engineering Beats Firewalls

Italy's data protection authority fined Wind Tre €1,715,600 for two breaches caused by phone-based social engineering at retail stores…

Jul 25, 2026views - 1.2k

CYBERSEC

F5 BIG-IP: Source Code Stolen, 45 Patches in One Quarter, CISA on Alert

A nation-state actor stole F5 BIG-IP source code and information on undisclosed vulnerabilities. CISA issued Emergency Directive ED 26…

Jul 24, 2026views - 1.5k

CYBERSEC

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365

Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

Jul 24, 2026views - 1.3k

ransomware

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware

The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Jul 24, 2026views - 1.4k