// 2 CRITICAL · 5 ZERO-DAY · 10 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECCRITICAL

ZDI-26-376: RCE in Quest NetVault Backup with Authentication Bypass

Command injection in NVBULogDaemon enables remote code execution as SYSTEM. Patch available but no CVE or CVSS assigned.

Jun 25, 2026views - 779

CYBERSECZERO-DAY

Fuji Electric Tellus: Kernel Driver Bug Enables SYSTEM Privilege Escalation

CVE-2026-8108 in the Fuji Electric Tellus pcid64 driver allows local privilege escalation to SYSTEM via Registry APIs with excessive p…

Jun 24, 2026views - 891

malware

Mistic: KongTuke's In-Memory Backdoor Challenges EDR Defenses

Operational since April 2026, the stealthy Mistic backdoor leverages DLL sideloading and in-memory BOF execution for long-term persist…

Jun 24, 2026views - 1.2k

CYBERSECEXPLOIT

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries

Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

Jun 24, 2026views - 1.1k

cybersecZERO-DAY

Oracle PeopleSoft Zero-Day: ShinyHunters Targets Higher Education

CVE-2026-35273, a CVSS 9.8 unauthenticated RCE, has been exploited by ShinyHunters since May 27. Over 100 universities hit; MeshCentra…

Jun 22, 2026views - 1.6k

ransomware

Prinz Eugen: The Ransomware That Encrypts the Newest Files First

Threatdown researchers have documented Prinz Eugen, a Go-based ransomware that prioritizes recently modified files, leaves no ransom n…

Jun 20, 2026views - 920

cybersec

Microsoft Attributes Mastra Supply-Chain Attack to North Korean Sapphire Sleet

Microsoft assesses with high confidence that the supply-chain compromise of more than 140 @mastra npm packages was carried out by the…

Jun 20, 2026views - 1.4k

CYBERSEC

Attack Surface 2026: 42% of Companies Have Databases Exposed to the Internet

Intruder's report on 3,000 organizations reveals the midmarket paradox: growing companies with enterprise-scale attack surfaces and SM…

Jun 20, 2026views - 1.5k

VULNEXPLOIT

Gravity SMTP: 17M Attacks Exploit Info-Disclosure Bug

CVE-2026-4020 in the WordPress Gravity SMTP plugin is under active exploitation, exposing email credentials and infrastructure bluepri…

Jun 19, 2026views - 739

VULNZERO-DAY

ZDI-26-358: Allegra Patches XSS in downloadAttachment Method

The ZDI-26-358 advisory from Trend Micro's Zero Day Initiative discloses a cross-site scripting vulnerability in Allegra's downloadAtt…

Jun 19, 2026views - 718

CYBERSECEXPLOIT

usbliter8: Unpatchable Exploit Hits Apple A12/A13 SecureROM

Paradigm Shift releases usbliter8, an unpatchable hardware exploit achieving arbitrary EL1 execution in Apple A12/A13 SecureROM via th…

Jun 19, 2026views - 1.1k

CYBERSEC

Crypto-Clipper: The Fake Reputation Economy Becomes a Weapon

Cybercriminals have weaponized stars, downloads, and reviews to distribute a Rust-based clipper across GitHub, YouTube, and even legit…

Jun 19, 2026views - 1.2k