// 1 CRITICAL · 6 ZERO-DAY · 6 CVE · 8 EXPLOIT IN THE LAST 24H
ransomware

The Gentlemen Climbs RaaS Rankings: 90% Payout and 580 Victims in One Year

The Gentlemen, tracked as Storm-2697, has become the second most active RaaS operation of 2026 with over 6x growth and a 90% affiliate…

Jul 10, 2026views - 1.5k

CYBERSECCRITICAL

Zimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG

Zimbra released ZCS 10.1.19 on July 7, 2026 to fix a stored cross-site scripting vulnerability in the Classic Web Client reported by G…

Jul 10, 2026views - 980

CYBERSECEXPLOIT

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America

Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…

Jul 10, 2026views - 1.3k

CYBERSECEXPLOIT

FortiBleed: 74,000 FortiGates Exposed — Patching Alone Won't Fix It

CISA estimates 74,000 Fortinet devices have compromised credentials. The FortiBleed campaign exploits credential reuse and brute-force…

Jul 08, 2026views - 1.5k

CYBERSEC

Qualys Unveils Risk Operations Center for the 'Day Minus Seven' Era

Qualys published a product-tech blog post on July 8, 2026 introducing the Risk Operations Center (ROC) as an operational response to w…

Jul 08, 2026views - 1.3k

CYBERSECCVE

CISA Orders 3-Day Patch for CVE-2026-55255 in Langflow

An IDOR in Langflow's /api/v1/responses endpoint lets authenticated attackers steal LLM and cloud credentials from other users' flows.…

Jul 08, 2026views - 1.5k

CYBERSECCVE

Ubiquiti Patches CVE-2026-50746, Maximum-Severity Flaw in UniFi OS

Ubiquiti released security updates on July 8, 2026 for seven critical vulnerabilities in UniFi OS. The most severe, CVE-2026-50746, ca…

Jul 08, 2026views - 1.9k

linuxEXPLOIT

GhostLock: 15-Year Linux Kernel Bug Now Publicly Exploitable, Guarantees Root

CVE-2026-43499 enables root escalation and container escape on nearly every Linux distribution since 2011. Nebula Security published t…

Jul 08, 2026views - 1.4k

CYBERSECEXPLOIT

UAT-7810 Expands ORB Network: New LONGLEASH, DOGLEASH, and JARLEASH Backdoors

Cisco Talos reveals the China-nexus APT UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network with new malwar…

Jul 07, 2026views - 1.5k

CYBERSECEXPLOIT

China-Linked Exploit Chain Targets US and Canadian Universities via Roundcube

A suspected Chinese espionage cluster has compromised fewer than ten US and Canadian universities using a two-vulnerability chain in R…

Jul 07, 2026views - 1.6k

CYBERSECZERO-DAY

Nissan Employees in Four Countries Exposed by Oracle PeopleSoft Zero-Day

Nissan Americas confirmed that attackers exploited CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft PeopleTools, to steal…

Jul 07, 2026views - 1.3k

VULN

Januscape: 16-Year-Old KVM Bug Enables Guest-to-Host Escape on Intel and AMD

CVE-2026-53359 strikes the shared shadow MMU code in Linux KVM used by both Intel and AMD. The flaw has existed since 2010 and require…

Jul 06, 2026views - 1.2k