// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
VULNCRITICAL

Kaltura Unpatched: RCE and File Read in mwEmbed, No Fix for Five Months

CERT/CC disclosed two critical unpatched vulnerabilities in Kaltura's mwEmbed library enabling remote code execution and arbitrary fil…

Aug 27, 2026views - 1.1k

CYBERSEC

Satanic Exposes 1,033 Stripe API Keys: The Vector Isn't an Infostealer

Threat actor Satanic released data from 669 Stripe vendors with live API keys. Analysis rules out infostealer infections and points to…

Aug 27, 2026views - 1.1k

malware

First Car Head Unit Malware Discovered: Vehicles Recruited into Proxy Botnet

Kaspersky has identified the first malware with a dedicated infection chain for Android automotive head units. It exploits the privile…

Aug 25, 2026views - 1.4k

CYBERSECCVE

Citrix NetScaler: CVE-2026-19490, Critical Authentication Bypass with CVSS 9.3

Citrix has released patches for CVE-2026-19490, a critical authentication bypass in NetScaler ADC/Gateway carrying a CVSS 9.3 score. T…

Aug 25, 2026views - 1.2k

CYBERSECCRITICAL

NSA and CISA Issue First Alert on AI-Driven Attacks Against Critical Siemens PLCs

Five U.S. federal agencies have released joint advisory AA26-231A confirming threat actors are using AI-generated scripts to target in…

Aug 25, 2026views - 1.1k

CYBERSECEXPLOIT

Unisoc VoLTE Exploit Chain Opens Android Kernel via Modem — No Patch, No CVE

A two-stage exploit chain in Unisoc VoLTE modems lets an attacker with a rogue 4G network achieve full Android kernel access when the…

Aug 25, 2026views - 1.1k

CYBERSECZERO-DAY

Lazarus Exploits Windows AFD.sys Zero-Day for SYSTEM: Third Time in Two Years

The North Korean group used CVE-2026-68820 for local privilege escalation to SYSTEM, deploying the FudModule 3.1 rootkit and Troy back…

Aug 25, 2026views - 1.2k

CYBERSECEXPLOIT

French Cyber-Spies Used GitHub Code to Hack EncroChat

A reverse-engineering report reveals French malware targeting EncroChat was copied from GitHub. Thousands of convictions across Europe…

Aug 25, 2026views - 1.2k

VULNCVE

CVE-2026-32475: Elementor Pro ≤4.2.1 Exposed to Unauthenticated RCE

A critical CVSS 9.0 vulnerability in Elementor Pro allows unauthenticated PHP file upload. The fix sat ready for 34 days before releas…

Aug 25, 2026views - 1.2k

VULN

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered

CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

Aug 25, 2026views - 1k

bluetoothCRITICAL

BlueZ: A2DP Buffer Overflow Enables Root RCE After Pairing

ZDI-26-589 discloses a stack-based buffer overflow in the BlueZ Bluetooth stack's A2DP module, allowing remote code execution as root…

Aug 25, 2026views - 1.1k

CYBERSECCVE

CVE-2026-65775: Microsoft Patches win32kfull UAF Discovered at Pwn2Own

Microsoft fixed CVE-2026-65775, a Use-After-Free in the Windows win32kfull driver discovered by Kentaro Kawane at Pwn2Own. The flaw en…

Aug 24, 2026views - 1k