// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Notepad++ Compromised: Lotus Blossom Hijacked Updates for Months

Chinese threat actors compromised Notepad++'s shared hosting infrastructure to selectively deliver malware to telecom and financial or…

Aug 03, 2026views - 1.5k

CYBERSECZERO-DAY

INC Ransomware Dominates SonicWall Zero-Day Chain: When the VPN Appliance Becomes an Unmonitored Bridge

INC Ransomware has emerged as the dominant threat actor actively weaponizing a chain of two zero-day vulnerabilities in SonicWall SMA…

Aug 03, 2026views - 1.2k

CYBERSEC

Iranian APTs Hit Rockwell PLCs: Over 30 Minnesota Water Systems Compromised

Iran-affiliated APT actors are exploiting CVE-2021-22681 in Rockwell, Schneider, and Siemens PLCs. The joint CISA-FBI advisory updated…

Aug 03, 2026views - 1.2k

CYBERSECEXPLOIT

APT28 FrostArmada: The SOHO Router Is the New Invisible Perimeter of State-Sponsored Espionage

The GRU compromised 18,000 home routers to steal Microsoft 365 credentials without deploying malware. No EDR can detect this attack: t…

Aug 03, 2026views - 1.2k

CYBERSEC

Midnight Blizzard Turns Hotel Wi-Fi Into a Trap for Corporate Travelers

Storm-2945, a Midnight Blizzard sub-cluster, compromises captive portal networks worldwide to deliver the CornFlake RAT and steal Micr…

Aug 03, 2026views - 1.2k

CYBERSEC

Miasma Hits Red Hat npm: Malware with Valid SLSA Provenance

On June 1, 2026, 32 npm packages in the @redhat-cloud-services namespace were compromised via a Red Hat employee's personal GitHub acc…

Aug 03, 2026views - 1.3k

CYBERSEC

Hotel DNS Attacks: Corporate VPNs Aren't Enough to Protect Microsoft 365

ReliaQuest has documented an active campaign since June 2026 that compromises hotel Wi-Fi gateways to redirect Microsoft 365 logins to…

Aug 03, 2026views - 1.2k

CYBERSECZERO-DAY

Cisco Confirms FMC Zero-Day: Static Credentials Under Attack, CISA Sets August 1 Deadline

Cisco confirms active exploitation of CVE-2026-20316 in Secure Firewall Management Center. CISA adds the flaw to its KEV catalog, mand…

Aug 03, 2026views - 1.3k

CYBERSECZERO-DAY

F5 Races Against Its Own Stolen Code: 45 Vulnerabilities Disclosed in a Single Quarter

Nation-state actors compromised F5's internal systems, exfiltrating portions of BIG-IP proprietary source code and details on undisclo…

Aug 03, 2026views - 1.2k

CYBERSECCRITICAL

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8

Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

Aug 03, 2026views - 1.2k

CYBERSECCRITICAL

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure

An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

Aug 03, 2026views - 1.2k

CYBERSEC

May 2026 Patch Tuesday: 161 CVEs, No Zero-Days, But Wormable Risks Loom

Microsoft's May 2026 Patch Tuesday fixes 161 vulnerabilities with no actively exploited zero-days — the first such month since June 20…

Aug 03, 2026views - 1.2k