// 1 CRITICAL · 5 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSEC

Accenture Confirms Data Breach: 35 GB of Data Up for Sale by Threat Actor '888'

Accenture has confirmed a security breach after threat actor '888' listed 35 GB of allegedly stolen data for sale on a cybercrime foru…

Jul 07, 2026views - 1.9k

malware

CAI Worm Kills Rival Cloud Malware, Steals Credentials

The CAI cloud-native worm eliminates TeamPCP and PCPJack processes to monopolize compromised hosts, marking an escalation in criminal…

Jul 07, 2026views - 1.5k

VULN

Januscape: 16-Year-Old KVM Bug Enables Guest-to-Host Escape on Intel and AMD

CVE-2026-53359 strikes the shared shadow MMU code in Linux KVM used by both Intel and AMD. The flaw has existed since 2010 and require…

Jul 06, 2026views - 1.3k

CYBERSEC

Mustang Panda Turns Zoho WorkDrive Into Covert C2 Channel Against Indian Government

The Mustang Panda APT group ran two espionage campaigns in June 2026 targeting the Indian government and hydroelectric infrastructure,…

Jun 29, 2026views - 1.4k

cloud

Unit 42 Uncovers Universal Bucket Hijacking Across Multiple Clouds

Unit 42/Palo Alto Networks research: globally unique bucket names in Google Cloud, AWS, and Azure allow data-flow hijacking without co…

Jun 27, 2026views - 1.3k

CYBERSEC

Klue Supply Chain Compromised, Icarus Hacked, Data in Circulation

The Klue-Salesforce supply chain breach now spans roughly two dozen confirmed victims. The extortion group Icarus, which claimed respo…

Jun 27, 2026views - 1.6k

cloud

Unit 42: Cloud Buckets Hijackable via Delete-and-Recreate

Unit 42 research shows how globally unique bucket names enable silent redirection of logs and messages across cloud accounts. Cross-CS…

Jun 22, 2026views - 833

linux

systemd 261: Software TPM and Native Installer Rewrite the Rules

systemd 261 expands the project's scope well beyond its traditional init system role, introducing a software TPM based on IBM swtpm, a…

Jun 22, 2026views - 827

CYBERSEC

Attack Surface 2026: 42% of Companies Have Databases Exposed to the Internet

Intruder's report on 3,000 organizations reveals the midmarket paradox: growing companies with enterprise-scale attack surfaces and SM…

Jun 20, 2026views - 1.5k

CYBERSEC

Klue Breach: Dormant OAuth Credential Opens Multi-Victim Door to Salesforce

The Icarus extortion group exfiltrated CRM data from Klue customers by abusing stolen OAuth tokens. Cybersecurity vendor Huntress conf…

Jun 18, 2026views - 1.1k

CYBERSECCRITICAL

Splunk Enterprise PostgreSQL Sidecar Bug (CVSS 9.8) Enables Unauthenticated RCE

CVE-2026-20253 allows unauthenticated remote code execution on Splunk Enterprise. The web proxy on port 8000 exposes an internal Postg…

Jun 18, 2026views - 974

VULNCRITICAL

Vertex AI SDK: Cross-Tenant Bucket Squatting Enabled RCE

Google Cloud Vertex AI SDK versions 1.139.0 through 1.140.0 were vulnerable to cross-tenant bucket squatting leading to remote code ex…

Jun 16, 2026views - 926