// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECEXPLOIT

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete

CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

Jul 24, 2026views - 1.3k

CYBERSEC

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365

Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

Jul 24, 2026views - 1.3k

CYBERSECZERO-DAY

Zero-Click Spyware: How Infection Works Without Touching the Phone

Zero-day attacks on smartphones exploit unknown vendor vulnerabilities to install spyware without any user interaction. A Bitdefender…

Jul 24, 2026views - 1.7k

CYBERSEC

SEBI Fines CDSL ₹1 Crore: LockBit Attack Was 'Foreseeable Outcome' of Systemic Failures

India's securities regulator SEBI has fined Central Depository Services Limited (CDSL) ₹1 crore for cybersecurity lapses that enabled…

Jul 24, 2026views - 1.8k

CYBERSECCRITICAL

Langflow: CISA Orders 72-Hour Patch for Pre-Auth RCE as Root

CVE-2026-0770 enables unauthenticated remote code execution as root in Langflow. CISA mandates remediation by July 24, 2026 for federa…

Jul 23, 2026views - 1.3k

CYBERSECZERO-DAY

Three Chained Zero-Days in Siemens ROX II: From File Leak to Root Control

Unit 42 and Siemens disclosed three zero-days in RUGGEDCOM ROX II industrial switches. The chain enables arbitrary file disclosure, pr…

Jul 23, 2026views - 1.3k

CYBERSEC

LastPass Suffers New Breach via Klue: Vaults Safe, Personal Data Exposed

LastPass disclosed an indirect data breach through vendor Klue. Password vaults remain secure, but personal data including names, emai…

Jul 23, 2026views - 1.6k

CYBERSECZERO-DAY

Microsoft Patch Tuesday July 2026: Two Zero-Days, and the CVSS 5.3 Is More Dangerous Than the 7.8

Microsoft's July 2026 Patch Tuesday addressed 570 CVEs, including two actively exploited zero-days: CVE-2026-56164 in SharePoint Serve…

Jul 23, 2026views - 1.6k

CYBERSEC

AsyncAPI: 5 Malicious npm Packages with Valid SLSA Attestations Distributed for Hours

Attackers compromised two AsyncAPI GitHub repositories via a misconfigured pull_request_target workflow, then used legitimate CI/CD pi…

Jul 23, 2026views - 1.3k

CYBERSECCVE

CVE-2026-16232: Check Point SmartConsole Zero-Day Actively Exploited in the Wild

Check Point confirms active exploitation of CVE-2026-16232, an authentication bypass with a CVSS 9.3 score in SmartConsole. CISA has a…

Jul 23, 2026views - 1.3k

CYBERSECCRITICAL

BIN Project Files as Weapons: The Delta Electronics DTM Soft Flaw That Turns Engineering Data into Code Execution

A deserialization vulnerability in Delta Electronics DTM Soft allows remote code execution via malicious BIN project files. With a CVS…

Jul 23, 2026views - 1.3k

CYBERSECCRITICAL

Synology DS925+: Root RCE via Redis MailPlus, Patch Available

ZDI-26-423 reveals a cryptographic flaw in the Synology DS925+ MailPlus Redis component. Network-adjacent attackers achieve unauthenti…

Jul 23, 2026views - 1.2k