// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECCVE

CVE-2026-6071: RCE in Rockwell Arena Simulation via Malicious DOE File

Trend Micro's Zero Day Initiative disclosed CVE-2026-6071, an out-of-bounds write in Rockwell Automation Arena Simulation's DOE file p…

Jul 22, 2026views - 1.3k

CYBERSEC

NVIDIAScape: Container Escape in Three Lines of Code in the NVIDIA Toolkit

CVE-2025-23266, rated CVSS 9.0, affects 37% of AI cloud environments. An old-school bug in the NVIDIA Container Toolkit enables privil…

Jul 22, 2026views - 1.3k

CYBERSECZERO-DAY

SonicWall SMA 1000: The Unexpected Backdoor — Active Exploitation and a 72-Hour Patch Window

SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, 2026: active exploitation since June 22, public PoC, and a mandatory…

Jul 22, 2026views - 1.3k

CYBERSEC

CISA Overhauls Vulnerability Management: 72-Hour Deadline for High-Risk KEVs

The new CISA directive abandons the one-size-fits-all model of BOD 22-01 and introduces four risk-based variables for prioritizing kno…

Jul 22, 2026views - 1.3k

CYBERSECCRITICAL

Zimbra 10.1.20 Patches Critical Command Injection Among Nine Vulnerabilities

Zimbra released version 10.1.20 of the Collaboration Suite on July 20, 2026, fixing nine security flaws. The most severe is a command…

Jul 22, 2026views - 1.3k

CYBERSEC

TrapDoor: 34+ Malicious Packages Turn AI Assistants Into Insider Threats

The TrapDoor campaign has distributed over 34 packages across npm, PyPI, and Crates.io with multi-stage payloads and hidden instructio…

Jul 22, 2026views - 2k

CYBERSEC

German Police Dismantle Kratos, the Kit That Turned AiTM Phishing Into a Franchise

German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting…

Jul 22, 2026views - 1.5k

CYBERSEC

Microsoft Uncovers OAuth Abuse: Vishing and Supply Chain Attacks Target SaaS

Microsoft has documented ShinyHunters-linked campaigns abusing trusted OAuth relationships in Salesforce through vishing and third-par…

Jul 22, 2026views - 1.7k

CYBERSECZERO-DAY

DarkSword and Coruna: Government-Grade Spyware Turns Mass Crime on iOS

Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click…

Jul 22, 2026views - 1.3k

CYBERSECZERO-DAY

Landfall: Military-Grade Spyware Targeted Samsung Galaxy Devices for Months

Palo Alto Networks Unit 42 uncovered Landfall, a commercial-grade modular Android spyware that exploited the Samsung zero-day CVE-2025…

Jul 22, 2026views - 1.4k

CYBERSEC

Accenture Confirms 'Isolated Matter' After Threat Actor '888' Lists 35GB of Data for Sale

Threat actor '888' claims to be selling roughly 35GB of Accenture data, including source code, Azure tokens, and SSH keys. Accenture a…

Jul 21, 2026views - 1.4k

CYBERSECEXPLOIT

GhostApproval, 14 UniFi CVEs, and Roundcube Espionage: A Triple Threat Convergence

Three critical attack vectors converged in July 2026: the GhostApproval symlink vulnerability in six AI coding assistants, 14 new crit…

Jul 21, 2026views - 1.4k