// 1 ZERO-DAY · 3 CVE · 3 EXPLOIT IN THE LAST 24H
ransomware

VantaCore: Pro-Ukraine Group Relaunches with Custom Ransomware Targeting Russia

VantaCore, a rebrand of the pro-Ukraine Thor group, is hitting Russian organizations with a proprietary arsenal of ransomware and remo…

Sep 02, 2026views - 1.2k

CYBERSEC

Dark Web: 153 Million Driver's Licenses for Sale, FBI Investigates IDScan.net

The Nexus dark web platform claims 153 million U.S. and Canadian driver's licenses. KrebsOnSecurity empirically verified records and t…

Sep 02, 2026views - 1.6k

CYBERSECEXPLOIT

Public Exploit for CVE-2026-84115 Puts Cleo Harmony at Immediate Risk

A public exploit for the authentication-bypass vulnerability CVE-2026-84115 in Cleo Harmony has been released. Versions 5.8.1.0 throug…

Sep 02, 2026views - 984

CYBERSECCRITICAL

OpenAI's Astra Crosses the Critical Threshold: AI That Finds Zero-Days Without Guidance

OpenAI has designated Astra as the first model to reach the Critical threshold of its Preparedness Framework. The system discovers zer…

Sep 02, 2026views - 982

CYBERSEC

FulcrumSec Steals 86 GB of MAG Data: API Keys Were Hardcoded in Client-Side JavaScript

The FulcrumSec data extortion group claimed responsibility for the Manchester Airports Group breach, publishing ~86 GB of data. Access…

Sep 02, 2026views - 1.1k

CYBERSEC

Russian Extradited from Cyprus: Charged in Malware Campaign Targeting 80,000 Freelancers

Searzhudin Aktulaev was extradited to the U.S. for a 2016–2017 campaign that used malicious Excel files to infect freelancers. The mac…

Sep 02, 2026views - 1k

CYBERSEC

Sality Disrupted: The Takedown That Turned Its P2P Network Into a Trap

On August 31, 2026, international authorities disrupted the Sality botnet by weaponizing its own peer-to-peer protocol. The malware re…

Sep 02, 2026views - 1.1k

malware

Guildma's Brazilian Geofencing: Malware That Only Shows Up for Real Targets

A SANS researcher documented Guildma (Astaroth), a Latin American banking trojan active since 2017, delivering its payload exclusively…

Sep 02, 2026views - 1.1k

CYBERSECZERO-DAY

SonicWall SMA1000: Active Zero-Days Enable Lateral Movement Without VPN

Two zero-day vulnerabilities in SonicWall SMA1000 allow unauthenticated RCE and lateral movement to Active Directory without VPN tunne…

Sep 02, 2026views - 1k

VULNZERO-DAY

ZDI-26-614: 0-day in PDF Architect Enables Remote Code Execution

The Zero Day Initiative published advisory ZDI-26-614 on August 31, 2026, detailing a 0-day vulnerability in the pdfforge PDF Architec…

Sep 01, 2026views - 1.1k

CYBERSECCVE

CVE-2026-0768: Active Exploitation of Langflow, 360+ Attacks in Hours

The Langflow AI platform is under massive exploitation: over 360 attempts detected in hours leveraging critical vulnerability CVE-2026…

Sep 01, 2026views - 1.1k

VULNCRITICAL

Honeypot Confirms Active Exploitation of Sangoma Switchvox RCE

CVE-2026-9586 affects roughly 4,000 internet-exposed Switchvox systems. Defused Cyber honeypots recorded in-the-wild exploitation with…

Sep 01, 2026views - 1.2k