// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Criminals Buy Expired Domains to Inherit Reputation and Traffic

A single threat actor spent nearly $7 million on over 10,000 expired domains, weaponizing their inherited trust signals for illegal st…

Aug 16, 2026views - 1.2k

CYBERSEC

Beacon CRM: The Cloud Revealed as a Lock With the Key Left in the Door

Beacon CRM confirmed the total theft of its customer database covering 1,500+ UK charities. The cause: an AWS access key exposed in pu…

Aug 16, 2026views - 1.1k

CYBERSECCVE

CVE-2026-65400: From Patch to Exploit in 4 Hours on macOS Screen Sharing

The Dutch NCSC confirms active exploitation of CVE-2026-65400: a pre-authentication bypass in macOS Screen Sharing granting root acces…

Aug 16, 2026views - 1.1k

CYBERSECEXPLOIT

Keyv Compromised: Malware Exploits Signed Provenance and AI Agent Config Files

The August 4, 2026 supply chain attack on keyv delivered malware with valid SLSA attestations and OIDC provenance signatures. AI agent…

Aug 16, 2026views - 1.1k

CYBERSEC

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Greatness phishing-as-a-service toolkit has integrated device code phishing, abusing the OAuth 2.0 Device Authorization Grant to b…

Aug 16, 2026views - 1.2k

CYBERSECCVE

CVE-2026-3854: One git push RCE in GitHub, 88% of GHES instances exposed

Wiz Research disclosed a critical RCE in GitHub Enterprise Server exploitable with a single git push command. GitHub patched GitHub.co…

Aug 15, 2026views - 1.2k

CYBERSECCVE

CVE-2026-17583: Three Decades of DNA Evidence at Risk of Digital Tampering

A vulnerability in Thermo Fisher software allows undetected alteration of forensic DNA files. The patch does not validate 30 years of…

Aug 15, 2026views - 1.2k

CYBERSECEXPLOIT

Lazarus Exploits Microsoft Zero-Day: Job Offers Turn Into Kernel Spyware

Check Point Research uncovers a new wave of Operation Dream Job featuring SecurityPDF and Troy. Lazarus leverages CVE-2026-68820 to de…

Aug 15, 2026views - 1.1k

CYBERSECZERO-DAY

Metabase Zero-Day CVE-2026-72898: Active Exploitation, CVSS 10.0, Wide Blast Radius

A maximum-severity CVSS 10.0 zero-day struck Metabase on August 2, 2026. The attack, confirmed against the vendor's cloud infrastructu…

Aug 15, 2026views - 1.7k

CYBERSECZERO-DAY

SonicWall Email Security: Local Privilege Escalation from CLI to Root via Command Injection

CVE-2026-66149 enables local privilege escalation in SonicWall Email Security. A patch is available, but the security perimeter remain…

Aug 15, 2026views - 1.1k

CYBERSECEXPLOIT

ShinyHunters Exploited Oracle PeopleSoft Zero-Day for Two Weeks

CVE-2026-35273 hit over 100 notified organizations, 68% universities, via an SSRF-to-unauthenticated-RCE chain. CISA added it to the K…

Aug 15, 2026views - 1.1k

CYBERSECCRITICAL

Galaxy S25: A TIFF File Can Trigger Remote Code Execution

CVE-2026-21045 strikes the Galaxy S25's Quram library. Heap overflow in TIFF parsing carries a CVSS 8.4 score, with a three-month gap…

Aug 15, 2026views - 1.1k