// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

ShieldBreak: New Zero-Day in Defender Exposes Windows Systems

Nightmare Eclipse released ShieldBreak, an exploit that bypasses the patch for CVE-2026-50656 and enables privilege escalation to SYST…

Aug 12, 2026views - 1.3k

CYBERSEC

Hackers Traverse Private APN, Shut Down Turbine at Polish Thermal Plant

CERT Polska has documented the first observed real-world attack that pivoted across a private cellular network from a wind farm to a t…

Aug 12, 2026views - 1.2k

CYBERSEC

ZDI-26-558: Amazon Smart Plug Certificate Validation Flaw in OTA Firmware Updates

A vulnerability in the Amazon Smart Plug's over-the-air update process allows a network-adjacent attacker to bypass certificate valida…

Aug 12, 2026views - 1.1k

CYBERSECCRITICAL

OriginLab Origin Viewer: RCE Patch for OGW Files, ZDI Disclosure

Trend Micro's Zero Day Initiative (ZDI) has disclosed vulnerability ZDI-26-553 in the OriginLab Origin Viewer OGW file parser. The ven…

Aug 12, 2026views - 1.2k

CYBERSECCVE

CVE-2026-54984: RCE in Windows ICC Parser, but the Vector Is Local

Microsoft patched CVE-2026-54984, an RCE vulnerability in the Windows color management component. The CVSS indicates a local attack ve…

Aug 12, 2026views - 1.2k

CYBERSECCRITICAL

Flowise Pre-Auth RCE, CVSS 9.8: Update Immediately to 3.1.3

ZDI-26-546 discloses a critical flaw in the low-code Flowise platform. The Airtable_Agent component executes Python code without valid…

Aug 12, 2026views - 1.2k

CYBERSECCVE

Microsoft Rates Exploitation 'More Likely' for CVE-2026-62893 in Windows

Microsoft patched a use-after-free in the WDSServer service of Windows Deployment Services. The exploitability assessment is 'More Lik…

Aug 12, 2026views - 1.1k

CYBERSECCRITICAL

Sony XAV-9500ES: AVRCP Heap Overflow Enables RCE via Bluetooth

The ZDI-26-475 vulnerability (CVE-2026-18282, CVSS 8.0) in the Sony XAV-9500ES Bluetooth AVRCP parser allows remote code execution aft…

Aug 12, 2026views - 1.1k

CYBERSEC

Red Hat ACM: Subscription Controller Becomes Bridge for Total Privilege Escalation

A vulnerability in Red Hat Advanced Cluster Management allows users with edit permissions on a single namespace to gain full cluster-a…

Aug 12, 2026views - 1.2k

CYBERSEC

TrendAI Vision One: Log Information Disclosure Fixed After 10 Months

The TrendAI Vision One security platform has closed CVE-2025-71386, an information disclosure vulnerability in Service Gateway logs. H…

Aug 11, 2026views - 1.1k

CYBERSECCVE

Lazarus Strikes with CVE-2026-68820: Microsoft Zero-Day in Defense Sector

Check Point discovers the 2026 wave of Operation Dream Job. Lazarus exploits CVE-2026-68820 in AFD.sys to deploy FudModule via fake jo…

Aug 11, 2026views - 1.5k

CYBERSECCRITICAL

Kenwood DNR1007XR: Firmware Update Flaw Enables Root RCE via Symlink Following

A vulnerability in the Kenwood DNR1007XR firmware update process allows a physically present attacker to achieve arbitrary code execut…

Aug 11, 2026views - 1.1k