// 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSEC

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure

The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

Aug 10, 2026views - 191

CYBERSECEXPLOIT

Cisco FMC Under Attack: Static Credentials Exploited, No Workaround Available

CVE-2026-20316 in Cisco Secure Firewall Management Center involves hard-coded static credentials, confirmed active exploitation, and n…

Aug 10, 2026views - 1.1k

CYBERSECEXPLOIT

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them

In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

Aug 10, 2026views - 1.1k

pythonCRITICAL

aeon: RCE via eval() in Python Dataset Loading, Patch Released

ZDI-26-469 discloses a code injection vulnerability in the Python aeon library. The use of eval() during dataset loading allows arbitr…

Aug 10, 2026views - 1.1k

VULNEXPLOIT

Dirty Frag: Linux Kernel LPE Chain with Public PoC and Patches Available

Dirty Frag is a two-vulnerability chain in the Linux kernel that enables root escalation on nearly all distributions. Mainline patches…

Aug 09, 2026views - 1.2k

aiCVE

CVE-2025-23266: NVIDIA Container Escape in Three Lines of Dockerfile

NVIDIA's GPU orchestration toolkit contains a critical vulnerability enabling container escape and privilege escalation on cloud AI in…

Aug 09, 2026views - 1.1k

CYBERSECEXPLOIT

Hermes Agent: The AI Offensive That Exposed Itself — When Autonomy Becomes a Liability

Palo Alto Networks Unit 42 has uncovered the first documented campaign of fully autonomous AI-enabled cyberattacks: a Chinese-speaking…

Aug 09, 2026views - 1.1k

CYBERSECEXPLOIT

Adobe ColdFusion: Active Exploit in 2 Hours, Critical Patch for CVE-2026-48282

CVE-2026-48282 in ColdFusion carries a maximum CVSS 10.0 score with in-the-wild exploitation detected within two hours. CCCS confirms…

Aug 09, 2026views - 1.2k

CYBERSECCVE

WinRAR CVE-2025-8088: Russian and Chinese APTs Exploit N-Day Patched Six Months Ago

Google Threat Intelligence Group confirms active exploitation of CVE-2025-8088 by Russian and Chinese state actors and financially mot…

Aug 09, 2026views - 1.1k

CYBERSECZERO-DAY

Barracuda Zero-Day: Mandiant Attributes CVE-2023-2868 to Chinese Espionage

Mandiant links the zero-day vulnerability in Barracuda Email Security Gateway to threat actor UNC4841 with high confidence, describing…

Aug 09, 2026views - 1.1k

CYBERSEC

Phoenix Contact CHARX: Credentials in Logs Open EV Charging Stations to Attack

The ZDI-26-506 vulnerability in the Phoenix Contact CHARX SEC-3150 industrial charger exposes credentials in log files. A network-adja…

Aug 08, 2026views - 1.1k

VULNCRITICAL

Heimdall Data: Root RCE in Database Proxy Poses Infrastructure-Wide Risk

ZDI-26-479 reveals a directory traversal flaw in the uploadJar method of Heimdall Data Database Proxy. Authentication is required, but…

Aug 08, 2026views - 1.1k