// 1 CRITICAL · 6 ZERO-DAY · 6 CVE · 8 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

Zimbra 10.1.20 Patches Critical Command Injection Among Nine Vulnerabilities

Zimbra released version 10.1.20 of the Collaboration Suite on July 20, 2026, fixing nine security flaws. The most severe is a command…

Jul 22, 2026views - 1.2k

CYBERSECZERO-DAY

DarkSword and Coruna: Government-Grade Spyware Turns Mass Crime on iOS

Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click…

Jul 22, 2026views - 1.2k

oracleZERO-DAY

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks

The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

Jul 22, 2026views - 1.3k

VULNCVE

CVE-2026-31431 "Copy Fail": 732 Bytes of Code Breaks the Linux Kernel Since 2017

A vulnerability in the algif_aead module enables root privilege escalation via a 732-byte exploit. CISA has added CVE-2026-31431 to th…

Jul 21, 2026views - 1.6k

CYBERSECEXPLOIT

GhostApproval, 14 UniFi CVEs, and Roundcube Espionage: A Triple Threat Convergence

Three critical attack vectors converged in July 2026: the GhostApproval symlink vulnerability in six AI coding assistants, 14 new crit…

Jul 21, 2026views - 1.3k

CYBERSECCVE

From VPN Bypass to Encrypted Domain: How CVE-2026-0257 Fuels Qilin Ransomware

Arctic Wolf Labs confirms active exploitation of CVE-2026-0257 to deploy Qilin ransomware. Specific TTPs reveal shared infrastructure…

Jul 21, 2026views - 1.2k

CYBERSECZERO-DAY

Apple Patches Zero-Day in dyld: A Flaw Hidden for Over a Decade

CVE-2026-20700 carries a CVSS 7.8 rating and is actively exploited against targeted individuals. Apple released patches on February 11…

Jul 21, 2026views - 1.4k

CYBERSECEXPLOIT

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery

The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

Jul 21, 2026views - 1.4k

CYBERSECCRITICAL

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter

CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Jul 20, 2026views - 1.3k

CYBERSECCVE

CISA Adds CVE-2008-4128 to KEV: An 18-Year-Old Cisco IOS Bug Resurfaces

CISA's Known Exploited Vulnerabilities catalog now includes CVE-2008-4128, an 18-year-old CSRF flaw in Cisco IOS 12.4. Federal agencie…

Jul 20, 2026views - 1.3k

CYBERSECEXPLOIT

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware

On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

Jul 20, 2026views - 1.4k

CYBERSECEXPLOIT

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes

On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

Jul 20, 2026views - 1.3k