// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSEC

Beacon CRM: The Cloud Revealed as a Lock With the Key Left in the Door

Beacon CRM confirmed the total theft of its customer database covering 1,500+ UK charities. The cause: an AWS access key exposed in pu…

Aug 16, 2026views - 1.1k

CYBERSECCVE

CVE-2026-65400: From Patch to Exploit in 4 Hours on macOS Screen Sharing

The Dutch NCSC confirms active exploitation of CVE-2026-65400: a pre-authentication bypass in macOS Screen Sharing granting root acces…

Aug 16, 2026views - 1.1k

CYBERSEC

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Greatness phishing-as-a-service toolkit has integrated device code phishing, abusing the OAuth 2.0 Device Authorization Grant to b…

Aug 16, 2026views - 1.2k

CYBERSECCVE

CVE-2026-17583: Three Decades of DNA Evidence at Risk of Digital Tampering

A vulnerability in Thermo Fisher software allows undetected alteration of forensic DNA files. The patch does not validate 30 years of…

Aug 15, 2026views - 1.2k

CYBERSECCRITICAL

Galaxy S25: A TIFF File Can Trigger Remote Code Execution

CVE-2026-21045 strikes the Galaxy S25's Quram library. Heap overflow in TIFF parsing carries a CVSS 8.4 score, with a three-month gap…

Aug 15, 2026views - 1.1k

CYBERSEC

fTPM 2.0 Compromised: AMD and Intel Forced to Patch the Root of Trust

Two critical vulnerabilities in the shared fTPM 2.0 firmware used by AMD and Intel expose cryptographic secrets and enable key forgery…

Aug 15, 2026views - 1.1k

CYBERSECZERO-DAY

PAX Q80: Unpatchable Zero-Day RCE Exposes Payment POS Terminals

The PAX Technology Q80 payment terminal contains a zero-day RCE vulnerability exploitable via local network. The vendor declared the f…

Aug 14, 2026views - 1.2k

CYBERSEC

TeamPCP Compromises LiteLLM: 434,000 Pipelines Exposed in 40 Minutes

TeamPCP injected malicious LiteLLM packages onto PyPI for 40 minutes. CloudSEK estimates 2,500+ organizations exposed. Stolen credenti…

Aug 14, 2026views - 1.2k

CYBERSEC

Cursor IDE Executes Code from Poisoned Repositories: 7 Months of Silence, No Patch

Mindgard disclosed a vulnerability in the popular Cursor IDE that allows automatic execution of malicious code via a poisoned git.exe…

Aug 14, 2026views - 1.1k

CYBERSECCVE

Norton Utilities Ultimate: Local Privilege Escalation to SYSTEM via Symlink, CVE-2024-13962

The ZDI-26-567 vulnerability in the NortonUtilitiesSvc service enables local privilege escalation to SYSTEM through a symlink attack.…

Aug 13, 2026views - 1.1k

CYBERSEC

Hackers Traverse Private APN, Shut Down Turbine at Polish Thermal Plant

CERT Polska has documented the first observed real-world attack that pivoted across a private cellular network from a wind farm to a t…

Aug 12, 2026views - 1.2k

CYBERSEC

ZDI-26-558: Amazon Smart Plug Certificate Validation Flaw in OTA Firmware Updates

A vulnerability in the Amazon Smart Plug's over-the-air update process allows a network-adjacent attacker to bypass certificate valida…

Aug 12, 2026views - 1.1k