// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSEC

FulcrumSec Steals 86 GB of MAG Data: API Keys Were Hardcoded in Client-Side JavaScript

The FulcrumSec data extortion group claimed responsibility for the Manchester Airports Group breach, publishing ~86 GB of data. Access…

Sep 02, 2026views - 1.1k

VULNZERO-DAY

ZDI-26-614: 0-day in PDF Architect Enables Remote Code Execution

The Zero Day Initiative published advisory ZDI-26-614 on August 31, 2026, detailing a 0-day vulnerability in the pdfforge PDF Architec…

Sep 01, 2026views - 1.2k

CYBERSEC

Spring Ring: The Teams Vishing Campaign That Jumps From Chat to Domain in Minutes

From January to April 2026, the Spring Ring campaign impersonated IT help desk staff on Microsoft Teams to trick employees into runnin…

Aug 31, 2026views - 1.1k

CYBERSEC

Russian Hackers of UAC-0099 Weaponize AI Guardrails as Evasion Tactic

On August 31, 2026, ESET disclosed an evasion technique: UAC-0099 hackers, a Russian group affiliated with the GRU, embed nuclear weap…

Aug 31, 2026views - 1.2k

CYBERSEC

Attacker's Own Infostealer Infection Exposes Full Arsenal of Colombian Blind Eagle Campaign

A consumer infostealer accidentally infected a threat actor's workstation, leaking browser history, local folders, credentials, and a…

Aug 31, 2026views - 1.2k

VULNZERO-DAY

PaperCut Issues Back-to-Back Emergency Patches for Actively Exploited Zero-Days

PaperCut released two emergency patches within 24 hours for CVE-2026-81578 and CVE-2026-82078. The first patch was bypassed, leaving t…

Aug 31, 2026views - 1.1k

CYBERSEC

Beacon CRM Breached, Robert Burns Trust Warns Donors: The Risk

A cyberattack on Beacon CRM, a SaaS provider for the non-profit sector, exposed contact data for over 1,000 organizations. The Robert…

Aug 31, 2026views - 1.2k

ransomware

Rhysida Hits Berlin Government: Data Auction Launched, Ransom Refused

The Rhysida ransomware group claimed responsibility for a cyberattack on the Berlin state government on August 28, 2026, auctioning 5.…

Aug 30, 2026views - 1.2k

ransomware

ATF Confirms 'Major Incident' Without Confirming Who Caused It

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed the breach of a standalone system but stopped short of attributing i…

Aug 30, 2026views - 1.1k

CYBERSEC

TA4922 Launches PackClient Campaigns in Asia: Modular RAT Bought on Telegram

Chinese threat group TA4922 deployed the PackClient RAT framework across China and India via tax-themed phishing between May and July…

Aug 30, 2026views - 1.1k

CYBERSEC

'Superior' Campaign: 19 Extensions in Google and Microsoft Stores Turned Into Data-Theft Platforms

Socket identified 19 malicious extensions in the Chrome Web Store and Edge Add-ons Store. The modular framework hit nearly 80,000 user…

Aug 30, 2026views - 1.1k

CYBERSEC

McKesson in ShinyHunters' Crosshairs: 284 Million Records and a $55 Million Ransom

McKesson disclosed a security incident involving unauthorized access to third-party applications. The ShinyHunters group claims to hav…

Aug 30, 2026views - 1.1k