// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

OWAReaper: The Malware That Survives Device Reimaging

Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

Jul 30, 2026views - 1.2k

CYBERSECCRITICAL

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets

Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

Jul 30, 2026views - 1.4k

CYBERSECCVE

Cisco FMC CVE-2026-20316: Actively Exploited Zero-Day, CISA Sets August 1 Deadline

Cisco disclosed CVE-2026-20316, a zero-day static-credential vulnerability in FMC Software. CISA has ordered federal agencies to remed…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

Sony XAV-9500ES: Bluetooth Turns Weapon — From Pwn2Own to the Parking Lot

ZDI advisory ZDI-26-475 details a heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES head unit, enabling remote cod…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

NoMachine getstat Command Injection Opens Door to RCE, CVSS 8.8

ZDI-26-483 details a command injection flaw in NoMachine's getstat function that allows authenticated remote code execution. A patch i…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

WatchGuard FireWare OS Buffer Overflow Turns Firewall Into a Backdoor

A vulnerability in the networkd process of WatchGuard FireWare OS allows an authenticated remote attacker to execute arbitrary code wi…

Jul 30, 2026views - 1.2k

CYBERSECCRITICAL

Rails Active Storage Exposes Arbitrary Files: The 'EOL Window' That Forces the Issue

A critical flaw in Ruby on Rails Active Storage lets unauthenticated attackers read arbitrary server files via crafted image uploads.…

Jul 29, 2026views - 1.3k

CYBERSECCRITICAL

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning

CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Jul 29, 2026views - 1.6k

CYBERSECCRITICAL

Broadcom Patches Five VMware Flaws: Full vCenter Bypass and VM Escape

Three critical vulnerabilities hit vCenter and ESXi. Two allow credential-less access; one enables escape from a virtual machine to th…

Jul 29, 2026views - 1.2k

CYBERSEC

Tengu: The Botnet That Turns Reboot Into a Forensic Trap

Discovered by Nozomi Networks Labs, the Mirai variant Tengu abuses the hardware watchdog timer on embedded Linux devices to force an a…

Jul 29, 2026views - 1.2k

CYBERSECCVE

CVE-2026-10702: One Click Is All It Takes to Compromise Tor Browser

A JIT compiler bug in Firefox propagates to Tor Browser, enabling arbitrary code execution on a single page visit. Mozilla patched it…

Jul 29, 2026views - 1.2k

CYBERSECZERO-DAY

Russian Zero-Clicks Empty Zimbra Webmail Without a Single Click

An XSS bug in Zimbra Classic UI let a Russian espionage group steal 90 days of email and 2FA codes just by viewing a message

Jul 29, 2026views - 1.2k