// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

SleeperGem: The Day RubyGems Became an npm-Style Target

Three malicious RubyGems packages compromised developer workstations through require-time execution and CI evasion. The campaign marks…

Jul 26, 2026views - 1.2k

CYBERSEC

dYdX Hit by Third Supply-Chain Attack: Compromised npm and PyPI Packages Deliver Wallet Stealer and RAT

DeFi protocol with $1.5T cumulative volume compromised on npm and PyPI. Wallet stealer and remote access trojan distributed via mainta…

Jul 26, 2026views - 1.2k

CYBERSECCVE

CVE-2026-3888: LPE to Root in snapd Hits Ubuntu LTS Since 2016

Qualys discovered a local privilege escalation vulnerability in snapd that lets a local attacker gain root on Ubuntu 16.04 through 24.…

Jul 26, 2026views - 1.2k

CYBERSECCRITICAL

Public Scanner Released for NGINX Map Regex Flaw; Full RCE Exploit Expected Around August 5

Researcher Stan Shaw (cyberstan) has published an open-source static scanner for CVE-2026-42533, a heap buffer overflow in the NGINX s…

Jul 26, 2026views - 1.1k

CYBERSECEXPLOIT

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies

A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Jul 26, 2026views - 1.1k

CYBERSECCRITICAL

Autel Wallbox Exposed to Pre-Auth RCE: The Pwn2Own Bug Hitting Home EV Chargers

Trend Micro's Zero Day Initiative published advisory ZDI-26-437 on July 15, 2026, detailing a pre-authentication remote code execution…

Jul 26, 2026views - 1.1k

CYBERSECZERO-DAY

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft

The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

Jul 25, 2026views - 1.5k

CYBERSECEXPLOIT

DarkSword: The iOS Kit That Armed Three Spy Groups With Six Flaws

Google Threat Intelligence Group uncovered DarkSword, a full-chain iOS exploit kit written in JavaScript that has been active since No…

Jul 25, 2026views - 1.4k

CYBERSEC

Wind Tre Fined €1.7M: Social Engineering Beats Firewalls

Italy's data protection authority fined Wind Tre €1,715,600 for two breaches caused by phone-based social engineering at retail stores…

Jul 25, 2026views - 1.2k

CYBERSEC

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents

The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

Jul 25, 2026views - 1.5k

CYBERSEC

F5 BIG-IP: Source Code Stolen, 45 Patches in One Quarter, CISA on Alert

A nation-state actor stole F5 BIG-IP source code and information on undisclosed vulnerabilities. CISA issued Emergency Directive ED 26…

Jul 24, 2026views - 1.5k

CYBERSECZERO-DAY

Paragon's Graphite Spyware Confirmed on iOS: Italian Government Admits to Surveillance

Citizen Lab has documented the first forensic confirmation of Paragon's mercenary iOS spyware Graphite, revealing targeting of journal…

Jul 24, 2026views - 1.3k