// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Estée Lauder's 10-Month Oracle EBS Breach: The Suspected Patch Gap That Let Clop In

Estée Lauder disclosed a 10-month breach of its Oracle E-Business Suite HR system. The Clop ransomware group exploited CVE-2025-61882,…

Aug 02, 2026views - 1.2k

CYBERSECCVE

TrendAI Vision One and the 'Historical' CVE-2025-71387: Patched in December

Trend Micro published bulletin KA-0023937 for CVE-2025-71387, a privilege escalation vulnerability in TrendAI Vision One that was alre…

Aug 02, 2026views - 1.1k

CYBERSECCRITICAL

Heimdall Data Database Proxy: Root RCE via Directory Traversal in uploadJar

ZDI-26-479 reveals a critical flaw in the uploadJar method of Heimdall Data Database Proxy. An authenticated attacker can achieve arbi…

Aug 02, 2026views - 233

CYBERSEC

Kemp LoadMaster: Hard-Coded Key in enablexroot Exposes Appliance to Root

Progress Software has patched CVE-2026-59689, a CVSS 8.0 privilege-escalation vulnerability in Kemp LoadMaster caused by a hard-coded…

Aug 02, 2026views - 1.2k

CYBERSECCRITICAL

WordPress wp2shell: In-the-Wild RCE Within 24 Hours of AI-Assisted Discovery

The wp2shell vulnerability chain in WordPress Core is under active in-the-wild exploitation with pre-authentication RCE. Wiz Research…

Aug 02, 2026views - 1.1k

CYBERSECZERO-DAY

Heap Overflow in Kenwood DNR1007XR: Malicious vCard Grants Root Code Execution

ZDI-26-488 discloses a vulnerability in the Kenwood infotainment system: a physically present attacker achieves a root shell via a hea…

Aug 02, 2026views - 1.1k

CYBERSEC

VoidStealer Bypasses Chrome Encryption by Attacking Memory

VoidStealer circumvents Chrome's App-Bound Encryption by extracting the master key from memory during decryption. The MaaS infostealer…

Aug 02, 2026views - 1.2k

CYBERSEC

The Great Patching Isn't Enough Anymore: When Attackers Weaponize Your Own Tools

Cisco Talos IR's Q2 2026 report marks a turning point: phishing now drives over 50% of engagements, while authentication abuse surged…

Aug 02, 2026views - 1.2k

CYBERSECCRITICAL

Apple Patches ImageIO: Parsing Bug Opens Door to RCE Across Eight Operating Systems

A flaw in Apple's ImageIO framework allows remote code execution via malformed image files. Patches are available for eight operating…

Aug 02, 2026views - 1.2k

CYBERSEC

TransUnion, the SaaS Periphery Paradox: 4.4 Million SSNs Exposed via Third-Party OAuth App

Credit bureau TransUnion disclosed a data breach exposing 4,461,511 unredacted Social Security Numbers. The vector was not a direct in…

Aug 02, 2026views - 1.3k

CYBERSECCRITICAL

Adobe Campaign Classic: Critical CVSS 10.0 Patch for On-Premise Deployments

Adobe has fixed CVE-2026-48449, a maximum-severity vulnerability in Campaign Classic that allows unauthenticated remote code execution…

Aug 01, 2026views - 1.2k

CYBERSECEXPLOIT

DarkSword: The iOS Exploit Kit Putting APT-Grade Attacks Within Reach

Discovered by Lookout and Google GTIG, DarkSword is a full-chain iOS exploit kit leveraging six vulnerabilities — three zero-days — to…

Aug 01, 2026views - 758