// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Passkey Bypass: Three Studies Shatter FIDO2's 'Anti-Phishing' Promise

On August 3, 2026, researchers from SpecterOps, Palo Alto Networks Unit 42, and independent researcher Dirk-jan Mollema published dist…

Aug 15, 2026views - 1.1k

CYBERSEC

fTPM 2.0 Compromised: AMD and Intel Forced to Patch the Root of Trust

Two critical vulnerabilities in the shared fTPM 2.0 firmware used by AMD and Intel expose cryptographic secrets and enable key forgery…

Aug 15, 2026views - 1.1k

CYBERSECZERO-DAY

PAX Q80: Unpatchable Zero-Day RCE Exposes Payment POS Terminals

The PAX Technology Q80 payment terminal contains a zero-day RCE vulnerability exploitable via local network. The vendor declared the f…

Aug 14, 2026views - 1.2k

CYBERSEC

Wesco Confirms Cloud CRM Incident: ExfilSquad Claims Theft of 2.6 Million Records

Fortune 500 industrial distributor Wesco confirmed on August 11, 2026, that it is investigating a security incident in its cloud CRM e…

Aug 14, 2026views - 1.2k

CYBERSECZERO-DAY

Apple Patches Decade-Old Zero-Day in iOS Core: dyld Exposed for 10+ Years

CVE-2026-20700 affects the dyld dynamic linker, a fundamental component present for over a decade. Apple confirms targeted exploitatio…

Aug 14, 2026views - 1.1k

CYBERSEC

TeamPCP Compromises LiteLLM: 434,000 Pipelines Exposed in 40 Minutes

TeamPCP injected malicious LiteLLM packages onto PyPI for 40 minutes. CloudSEK estimates 2,500+ organizations exposed. Stolen credenti…

Aug 14, 2026views - 1.2k

CYBERSEC

Cursor IDE Executes Code from Poisoned Repositories: 7 Months of Silence, No Patch

Mindgard disclosed a vulnerability in the popular Cursor IDE that allows automatic execution of malicious code via a poisoned git.exe…

Aug 14, 2026views - 1.1k

CYBERSEC

ChainDrop: The npm Worm That Broke Cryptographic Trust in Four Hours

The ChainDrop worm infected 444 npm packages using valid SLSA provenance. The failure of automated trust in modern software.

Aug 14, 2026views - 1.2k

CYBERSECCRITICAL

Cisco ISE Authenticated RCE Escalates to Root: The 9.9 CVSS Behind the Method

A critical vulnerability in Cisco Identity Services Engine enables authenticated remote code execution with privilege escalation to ro…

Aug 13, 2026views - 1.1k

CYBERSECCVE

Norton Utilities Ultimate: Local Privilege Escalation to SYSTEM via Symlink, CVE-2024-13962

The ZDI-26-567 vulnerability in the NortonUtilitiesSvc service enables local privilege escalation to SYSTEM through a symlink attack.…

Aug 13, 2026views - 1.1k

CYBERSECCRITICAL

BlackBerry QNX: RCE in KEV Parser, Patch Available for SDP 7.x-8.0

CVE-2026-40272 strikes the trace file parser in QNX. Analysis of malicious .kev logs can execute arbitrary code. BlackBerry has releas…

Aug 13, 2026views - 1.2k

CYBERSECEXPLOIT

CISA Cracks Down on LoadMaster: 792 Exploit Attempts and Mandatory Patching

Progress Kemp LoadMaster lands in CISA's KEV catalog with CVE-2026-8037 and a 9.6 CVSS. U.S. federal agencies have three days to patch…

Aug 13, 2026views - 1.1k