// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Valve: Steam Hardware Shipping Data Exposed in CEVA Logistics Attack

Valve notified European Steam hardware customers on August 7, 2026 that their shipping data was compromised in a cyberattack on logist…

Aug 10, 2026views - 1.2k

CYBERSECEXPLOIT

Hermes Agent: The AI Offensive That Exposed Itself — When Autonomy Becomes a Liability

Palo Alto Networks Unit 42 has uncovered the first documented campaign of fully autonomous AI-enabled cyberattacks: a Chinese-speaking…

Aug 09, 2026views - 1.4k

CYBERSECEXPLOIT

Adobe ColdFusion: Active Exploit in 2 Hours, Critical Patch for CVE-2026-48282

CVE-2026-48282 in ColdFusion carries a maximum CVSS 10.0 score with in-the-wild exploitation detected within two hours. CCCS confirms…

Aug 09, 2026views - 1.3k

CYBERSECCVE

WinRAR CVE-2025-8088: Russian and Chinese APTs Exploit N-Day Patched Six Months Ago

Google Threat Intelligence Group confirms active exploitation of CVE-2025-8088 by Russian and Chinese state actors and financially mot…

Aug 09, 2026views - 1.2k

CYBERSEC

China Launches Security Review of Palo Alto Networks: Self-Censorship Failed to Work

The Cyberspace Administration of China (CAC) opened a national security review of Palo Alto Networks products on August 6, 2026. The m…

Aug 09, 2026views - 1.3k

CYBERSEC

Backdoored LiteLLM on PyPI: Malware Triggers on Python Startup Alone

On March 24, 2026, two malicious LiteLLM versions exfiltrated credentials from over 50 categories via a .pth mechanism. The compromise…

Aug 09, 2026views - 1.2k

CYBERSECZERO-DAY

Barracuda Zero-Day: Mandiant Attributes CVE-2023-2868 to Chinese Espionage

Mandiant links the zero-day vulnerability in Barracuda Email Security Gateway to threat actor UNC4841 with high confidence, describing…

Aug 09, 2026views - 1.1k

CYBERSECZERO-DAY

Metabase Zero-Day CVSS 10.0 Actively Exploited for Corporate Data Theft

A maximum-severity SQL injection zero-day without a CVE has compromised Metabase cloud and self-hosted instances. Framework, Tally, an…

Aug 09, 2026views - 1.2k

CYBERSEC

Phoenix Contact CHARX: Credentials in Logs Open EV Charging Stations to Attack

The ZDI-26-506 vulnerability in the Phoenix Contact CHARX SEC-3150 industrial charger exposes credentials in log files. A network-adja…

Aug 08, 2026views - 1.2k

CYBERSECEXPLOIT

TrueConf Becomes Strategic Chokepoint: Compromised Servers Infect Clients

At least three distinct attack campaigns — attributed to Ukrainian hacktivists and Chinese threat actors — have compromised on-premise…

Aug 08, 2026views - 1.2k

CYBERSECCVE

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster

CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…

Aug 08, 2026views - 1.1k

CYBERSEC

Guangdong Chanming: The Ghost Vendor Behind PLA Botnets

Chinese firm Guangdong Chanming, which has no website or known commercial clients, sold anonymized relay infrastructure to the PLA and…

Aug 08, 2026views - 1.1k