// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Copilot Autofix Introduces Vulnerability in Snowflake CI/CD, Then an AI Agent Finds It

GitHub Copilot Autofix introduced a script injection flaw into a Snowflake GitHub Actions workflow. Five days later, Wiz's autonomous…

Aug 17, 2026views - 1.2k

CYBERSEC

Trump Authorizes Private Cyber Offensives: The New NSPM of August 12, 2026

On August 12, 2026, Trump signed an NSPM authorizing vetted private companies to conduct offensive cyber operations against transnatio…

Aug 17, 2026views - 1.2k

CYBERSEC

Passkey Bypass: Three Attacks Demolish Phishing-Resistant Authentication

Three independent studies published in August 2026 demonstrate post-compromise attack chains that bypass passkey-based phishing-resist…

Aug 17, 2026views - 1.9k

CYBERSECEXPLOIT

Evooo1Bot: The Botnet Turning Routers and Edge Devices into SOCKS5 Proxies

Fortinet discovers Evooo1Bot, a modular Mirai-based Linux botnet active since July 2026 that exploits 10 known CVEs to build a distrib…

Aug 17, 2026views - 1.2k

CYBERSEC

Rubrik Zero Labs Unveils RPE: From Word Document to Shell on Copilot

Remote Prompt Execution turns prompt injection into full enterprise identity compromise on Microsoft 365 Copilot. The five-stage chain…

Aug 17, 2026views - 925

CYBERSECCRITICAL

Attackers Shut Down Polish Turbine via Private APN: First Real-World OT Case

CERT Polska documented the first real-world attack on critical infrastructure through a misconfigured private cellular APN. A Polish c…

Aug 17, 2026views - 1.2k

CYBERSECZERO-DAY

ShieldBreak: Zero-Day Exploit Targets Windows Defender for SYSTEM Privilege Escalation

Nightmare Eclipse released ShieldBreak, a zero-day exploit achieving SYSTEM privileges on fully patched Windows via Microsoft Defender…

Aug 17, 2026views - 1.2k

CYBERSEC

Generative AI as a Cyber Force Multiplier: Three North Korean Groups, Three Tactics

Famous Chollima (47% of state-backed tech attacks), Kimsuky (HelloDoor malware with AI assistance), and APT45 (recursive prompting): t…

Aug 17, 2026views - 1.2k

CYBERSECZERO-DAY

Clop Claims Theft of Technical Data from 43 Organizations; Shell Investigates

The Clop group stole technical data from 43 organizations by exploiting CVE-2026-12569 in PTC Windchill. Shell is investigating a pote…

Aug 17, 2026views - 1.2k

CYBERSECCVE

CVE-2026-62911: Exchange Authentication Bypass Enables Full Mailbox Takeover

Discovered at Pwn2Own by Orange Tsai, ZDI-26-534 hits on-premises Exchange with a CVSS 8.0 score. Microsoft released the patch after 8…

Aug 17, 2026views - 1.4k

CYBERSECCRITICAL

Cisco ISE: Authenticated RCE in invokeScript With Root Escalation Path

CVE-2026-20147 enables authenticated remote code execution as the iseadminportal user on Cisco Identity Services Engine, with a docume…

Aug 16, 2026views - 1.2k

CYBERSECCRITICAL

WordPress 7.0.3 Fixes Login XSS That Can Lead to RCE via Social Engineering

CVE-2026-64638 is a pre-authentication reflected XSS in the WordPress login screen, discovered by pwn.ai using AI-assisted systems. Ex…

Aug 16, 2026views - 1.1k