// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
cybersec

DecryptAds Exposes the Invisible: The Ad Supply Chain Under the Microscope

DecryptAds parses ads.txt and sellers.json files, revealing hidden links between mainstream sites, data brokers, and geopolitical acto…

Aug 19, 2026views - 1.1k

CYBERSEC

Interrupt Injection: MIT Attack Bypasses Spectre v2 Defenses on Intel and AMD

MIT CSAIL researchers Daniël Trujillo and Mengjia Yan presented the Interrupt Injection technique at Black Hat USA 2026, demonstrating…

Aug 18, 2026views - 1.2k

CYBERSECEXPLOIT

Unisoc VoLTE Video-Call Exploit Chain Reaches Android Kernel — No Patch, No CVE

SSD Secure Disclosure details a two-stage exploit chain on Unisoc chipsets that starts with a malicious VoLTE video call and ends with…

Aug 18, 2026views - 1.1k

cybersec

DGFiP Data Breach Exposes 678,000 French Taxpayers; CNIL Weighs Enforcement

The French Finance Ministry confirmed on August 17, 2026, that the DGFiP suffered a breach exposing sensitive tax data for 678,000 ind…

Aug 18, 2026views - 1.2k

malware

Lumma Stealer Hides in Pirated 'The Odyssey' Downloads: The Hidden Extension Trick

Cybercriminals are distributing Lumma Stealer via Windows executables disguised as pirated copies of The Odyssey (2026) on torrent tra…

Aug 18, 2026views - 1.1k

CYBERSEC

RingCentral Breach Exposes 1.6 Million Records via Vishing Call

ShinyHunters compromised RingCentral with a single phone call, exposing 1.6 million records and leaking 280 GB of data. The real-time…

Aug 18, 2026views - 1.1k

CYBERSEC

Copilot Autofix Introduces Vulnerability in Snowflake CI/CD, Then an AI Agent Finds It

GitHub Copilot Autofix introduced a script injection flaw into a Snowflake GitHub Actions workflow. Five days later, Wiz's autonomous…

Aug 17, 2026views - 1.2k

CYBERSECEXPLOIT

Evooo1Bot: The Botnet Turning Routers and Edge Devices into SOCKS5 Proxies

Fortinet discovers Evooo1Bot, a modular Mirai-based Linux botnet active since July 2026 that exploits 10 known CVEs to build a distrib…

Aug 17, 2026views - 1.1k

malware

Mustang Panda Arms CoolClient with Signed Rootkit: EDR in the Kernel Crosshairs

HoneyMyte deploys msagent.sys, a kernel-mode rootkit driver signed with an expired 2013 certificate. It hides processes, files, and C2…

Aug 17, 2026views - 1.1k

CYBERSECEXPLOIT

ShieldBreak: Zero-Day Exploit Targets Windows Defender for SYSTEM Privilege Escalation

Nightmare Eclipse released ShieldBreak, a zero-day exploit achieving SYSTEM privileges on fully patched Windows via Microsoft Defender…

Aug 17, 2026views - 1.2k

CYBERSECCRITICAL

WordPress 7.0.3 Fixes Login XSS That Can Lead to RCE via Social Engineering

CVE-2026-64638 is a pre-authentication reflected XSS in the WordPress login screen, discovered by pwn.ai using AI-assisted systems. Ex…

Aug 16, 2026views - 1.1k

VULNZERO-DAY

dnsmasq: DNSSEC Bug Enables Unauthenticated Remote DoS

A vulnerability in dnsmasq's NSEC/NSEC3 DNSSEC record parsing allows remote denial-of-service attacks without authentication. The flaw…

Aug 16, 2026views - 1.2k