// 2 CRITICAL · 5 ZERO-DAY · 10 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSEC

CSE Discloses Three Offensive Cyber Operations in Rare 2025 Report

Canada's Communications Security Establishment (CSE) revealed in its 2025 annual report that it conducted three authorized offensive c…

Jul 06, 2026views - 1.5k

CYBERSEC

Armored Likho Targets Governments and Power Operators with BusySnake Stealer

The Armored Likho APT group, uncovered by Kaspersky, is conducting cyber-espionage and financially motivated attacks against governmen…

Jul 06, 2026views - 1.3k

ransomware

A U.S. Local Government Paid $1 Million for an Illusion of Control

A U.S. government entity paid roughly $1 million in bitcoin to the Kairos ransomware group on June 13, 2025, to prevent the release of…

Jul 04, 2026views - 1.5k

CYBERSEC

Researcher Documents Real-Time Shared Access Between FortiBleed Operator and INC Ransom, Lynx Panels for First Time

SOCRadar documented that an operator with access to the FortiBleed infrastructure was simultaneously logged into the negotiation panel…

Jul 04, 2026views - 1.3k

CYBERSECZERO-DAY

Bad Epoll: Linux Kernel Bug Roots Android, Escapes Chrome Sandbox

CVE-2026-46242 is a race condition in the Linux kernel's epoll subsystem that allows an unprivileged user to gain root privileges. The…

Jul 03, 2026views - 1.3k

CYBERSEC

Medtronic Begins Breach Notifications: 369,200+ Confirmed Victims vs. 9 Million Claimed by ShinyHunters

Medtronic has started notifying individuals affected by an April 2026 corporate IT breach. State regulator filings confirm over 369,20…

Jul 02, 2026views - 1.5k

CYBERSEC

FortiBleed, the Missing Link: From 430,000 Targeted Firewalls to INC and Lynx Ransomware

SOCRadar ties the FortiBleed credential theft campaign to the INC and Lynx ransomware groups, revealing a single operator managing bot…

Jul 02, 2026views - 1.4k

CYBERSECCRITICAL

ZDI-26-377: XSS in NetVault Backup Enables Auth Bypass and SYSTEM RCE Chain

An XSS flaw in the viewclient page of Quest NetVault Backup lets a remote attacker bypass authentication and, when chained with other…

Jul 01, 2026views - 706

malware

ScreenConnect Abused to Deliver AsyncRAT via 90+ Spoofed Freeware Domains

Kaspersky MDR uncovered a large-scale campaign that weaponizes the legitimate remote-access tool ScreenConnect to deploy AsyncRAT thro…

Jul 01, 2026views - 621

CYBERSEC

Citrix Patches Six NetScaler Flaws: The Trap Is Manual

Citrix released patches on June 30, 2026 for six vulnerabilities in NetScaler ADC and NetScaler Gateway, including a new CitrixBleed i…

Jul 01, 2026views - 1.1k

malware

RustDuck: The IoT Botnet Rewritten in Rust Challenges Researchers

QiAnXin XLab has tracked RustDuck since February 2026: a two-stage malware rewritten in Rust with enterprise-grade encryption and anti…

Jun 30, 2026views - 1.4k

CYBERSECCRITICAL

Langflow RCE Exploited for Miner Worm: 19-Day Campaign

CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

Jun 30, 2026views - 1.4k