// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
VULNZERO-DAY

Windows: win32kfull Driver Bug Allows Escalation to SYSTEM

Microsoft released a fix on August 11, 2026 for CVE-2026-62712, a vulnerability in the win32kfull driver that allows code running with…

Aug 12, 2026views - 1.2k

CYBERSECCVE

CVE-2026-54984: RCE in Windows ICC Parser, but the Vector Is Local

Microsoft patched CVE-2026-54984, an RCE vulnerability in the Windows color management component. The CVSS indicates a local attack ve…

Aug 12, 2026views - 1.2k

CYBERSEC

Red Hat ACM: Subscription Controller Becomes Bridge for Total Privilege Escalation

A vulnerability in Red Hat Advanced Cluster Management allows users with edit permissions on a single namespace to gain full cluster-a…

Aug 12, 2026views - 1.2k

CYBERSECCRITICAL

Kenwood DNR1007XR: Firmware Update Flaw Enables Root RCE via Symlink Following

A vulnerability in the Kenwood DNR1007XR firmware update process allows a physically present attacker to achieve arbitrary code execut…

Aug 11, 2026views - 1.1k

CYBERSEC

Local Malware Bypasses Google Passkeys: The Flaw Is in Chrome, Not FIDO2

Palo Alto Networks Unit 42 research demonstrates that local malware can bypass FIDO2 passkeys in Chrome on Windows using three techniq…

Aug 11, 2026views - 1.2k

cybersec

Aeternum: The Botnet Loader That Uses Polygon as C2

Unit 42 analyzes Aeternum, a C++ botnet loader that moves command-and-control entirely onto the public Polygon blockchain. On August 1…

Aug 11, 2026views - 1.1k

VULN

Trend Cleaner One Pro: Cleanup Service Turned Weapon for Arbitrary File Deletion

ZDI-26-496 reveals a vulnerability in Cleaner One Pro's Junk Files Cleanup service that allows a local attacker to delete arbitrary fi…

Aug 11, 2026views - 1.1k

CYBERSECCVE

Apple Patches CVE-2026-20700: Zero-Day in dyld Survived Two Decades in iOS

Apple has fixed CVE-2026-20700, a zero-day memory corruption vulnerability in the dyld dynamic linker that existed in iOS for over a d…

Aug 11, 2026views - 1.1k

CYBERSEC

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure

The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

Aug 10, 2026views - 251

CYBERSECEXPLOIT

Cisco FMC Under Attack: Static Credentials Exploited, No Workaround Available

CVE-2026-20316 in Cisco Secure Firewall Management Center involves hard-coded static credentials, confirmed active exploitation, and n…

Aug 10, 2026views - 1.2k

CYBERSEC

Battering RAM: $50 Physical Attack Bypasses SGX and SEV-SNP on DDR4 Systems

A sub-$50 DDR4 interposer compromises confidential computing. Vendors classify physical attacks as out of scope. Article based on a si…

Aug 10, 2026views - 1.2k

phishing

The Microsoft 365 Account Takeover That Leaves No Trace

Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…

Aug 10, 2026views - 1.2k