// 1 CRITICAL · 6 ZERO-DAY · 7 CVE · 8 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

Langflow RCE Exploited for Miner Worm: 19-Day Campaign

CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

Jun 30, 2026views - 1.4k

CYBERSECEXPLOIT

CISA Confirms: BlueHammer Now Exploited by Ransomware

CISA has elevated CVE-2026-33825 to a confirmed ransomware vector. Microsoft has not updated its advisory, creating an intelligence ga…

Jun 30, 2026views - 1.3k

cybersecZERO-DAY

Nissan Payroll Breach via Oracle PeopleSoft Zero-Day CVE-2026-35273

Nissan Americas confirmed a breach exposing employee payroll data and Social Security numbers across four countries through CVE-2026-3…

Jun 29, 2026views - 1.3k

VULNCVE

CVE-2026-48558: Djinn Stealer Exploited In-the-Wild on SimpleHelp

Threat actors exploit CVE-2026-48558 to deploy Djinn Stealer and TaskWeaver. The new infostealer targets AI and cloud credentials. Rou…

Jun 29, 2026views - 1k

CYBERSECCVE

CVE-2026-46817: Oracle EBS Under Attack, 450+ Servers Exposed

Defused detects active exploitation of CVE-2026-46817 on Oracle EBS honeypots. CVSS 9.8, patch available since May, over 450 instances…

Jun 29, 2026views - 771

CYBERSEC

Gamaredon 2025: 35 Spear-Phishing Campaigns and 6 PowerShell Tools Target Ukraine

The Gamaredon APT group, attributed by Ukraine's SSU to the FSB's 18th Center for Information Security, launched 35 distinct spear-phi…

Jun 29, 2026views - 973

CYBERSECCVE

Public PoC for CVE-2026-55200: libssh2 at Risk of RCE

A working proof-of-concept for CVE-2026-55200, a critical CVSS 9.2 vulnerability in libssh2, was released on June 23, 2026. The pre-au…

Jun 29, 2026views - 1.2k

CYBERSEC

ATEN Unizon: Authenticated Bug Deletes Files, CVSS 5.5 Understates Risk

Directory traversal in ATEN Unizon's uploadSSL lets an authenticated attacker delete arbitrary files. The CVSS 5.5 rating masks real o…

Jun 28, 2026views - 1.5k

VULNZERO-DAY

ZDI-26-397: Use-After-Free in X.Org Server Opens Door to Local Privilege Escalation

A Use-After-Free flaw in X.Org Server's CreateSaverWindow function (CVE-2026-50263) lets a local low-privilege attacker leak sensitive…

Jun 28, 2026views - 1.6k

aiCVE

CVE-2026-12957: Cloud Credential Theft via Amazon Q Developer

A high-severity vulnerability (CVSS 8.5) in the Amazon Q Developer extension for VS Code allowed automatic execution of malicious MCP…

Jun 27, 2026views - 1.4k

linuxCVE

CVE-2026-46331: Linux 'pedit COW' Exploit Gains Root in 24 Hours

A Linux kernel bug corrupts the page cache of setuid binaries such as /bin/su without touching disk, bypassing all integrity checks.

Jun 26, 2026views - 1.2k

VULNEXPLOIT

DirtyClone: The Fourth Variant in the DirtyFrag Family

CVE-2026-43503, the fourth variant in the DirtyFrag family, exploits cloned packets to corrupt file-backed memory. JFrog published a f…

Jun 26, 2026views - 940