// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Bank of Baroda Data Breach Traced to Compromised Email Account: The Limits of What We Know

India's Bank of Baroda confirms an employee email account was compromised, but insists core banking systems remain untouched. A threat…

Aug 01, 2026views - 526

CYBERSECEXPLOIT

KNX BCU Key Flaw: How a Security Feature Became a Permanent Denial-of-Service

CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on July 15, 2026, with a federal remediation deadline of July…

Aug 01, 2026views - 672

CYBERSECCVE

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine

F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

Jul 31, 2026views - 630

CYBERSEC

Anthropic: Claude Models Accidentally Accessed Real Systems During Cybersecurity Evaluations

Three Claude models gained unauthorized access to real organizational systems during capture-the-flag exercises due to a network misco…

Jul 31, 2026views - 1.1k

CYBERSECEXPLOIT

Record Patch Tuesday: Microsoft Fixes 622 Bugs, Two Zero-Days Already Exploited

Microsoft's July 2026 Patch Tuesday sets an all-time high with 622 CVEs patched, including two actively exploited zero-days in SharePo…

Jul 31, 2026views - 1.3k

CYBERSECCRITICAL

Splunk Enterprise Critical Zero-Day Enables Pre-Auth RCE: When the SIEM Becomes the Entry Point

CVE-2026-20253 hits Splunk Enterprise with a CVSS 9.8 score. The pre-authentication vulnerability in the PostgreSQL sidecar service ea…

Jul 31, 2026views - 1.4k

CYBERSECEXPLOIT

GitHub Tightens Bug Bounty While Losing Control of Its CI/CD

GitHub has restructured its public bug bounty program, slashing payouts and creating an invite-only VIP tier, while its Actions infras…

Jul 31, 2026views - 1.3k

CYBERSECZERO-DAY

Check Point's Firewall Brain Has a Trust-System Flaw

An authentication bypass in Check Point SmartConsole enables remote administrative access. CISA has mandated patching by July 25 for U…

Jul 31, 2026views - 1.4k

CYBERSECEXPLOIT

AsyncAPI: Five npm Packages Compromised with Valid Provenance

Attackers hijacked the AsyncAPI project's CI/CD pipeline on July 14, 2026, stealing the asyncapi-bot service account token and publish…

Jul 31, 2026views - 950

CYBERSEC

npm/PyPI Supply Chain: When Sigstore Provenance Signs the Malware

Four attacks in seven weeks compromised npm and PyPI. Sigstore and SLSA provenance proved useless: the attacker stole the CI identity,…

Jul 31, 2026views - 1.3k

CYBERSECZERO-DAY

Microsoft Patches RoguePlanet, the Defender Black Hole That Handed SYSTEM to Anyone

CVE-2026-50656: a race condition in the Windows 10 and 11 antivirus engine let a standard user gain SYSTEM privileges. The silent engi…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

Iran: APTs Modify Internet-Exposed PLCs, CISA Alerts Seven Agencies

CISA and six U.S. government agencies have updated a joint advisory on Iranian attacks against programmable logic controllers (PLCs) d…

Jul 30, 2026views - 1.3k