// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECEXPLOIT

KDDI Breach Exposes 14.2 Million Credentials Across Six Japanese ISPs

KDDI Corporation disclosed unauthorized access to a shared email platform serving six Japanese telecom operators on June 17, 2026. The…

Jun 28, 2026views - 752

CYBERSEC

ATEN Unizon: Authenticated Bug Deletes Files, CVSS 5.5 Understates Risk

Directory traversal in ATEN Unizon's uploadSSL lets an authenticated attacker delete arbitrary files. The CVSS 5.5 rating masks real o…

Jun 28, 2026views - 1.5k

CYBERSECZERO-DAY

ZDI-26-393: Stack Buffer Overflow in X.Org Server XKB Subsystem Enables Local Root Escalation

The Zero Day Initiative disclosed ZDI-26-393 on June 24, 2026, detailing a local privilege escalation vulnerability in X.Org Server. A…

Jun 28, 2026views - 1.4k

CYBERSEC

SBU and FBI Expose Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts

Ukraine's SBU and the FBI disclosed a long-running Russian operation that uses morning-timed SMS phishing to steal verification codes…

Jun 27, 2026views - 1.4k

CYBERSEC

Klue Supply Chain Compromised, Icarus Hacked, Data in Circulation

The Klue-Salesforce supply chain breach now spans roughly two dozen confirmed victims. The extortion group Icarus, which claimed respo…

Jun 27, 2026views - 1.6k

CYBERSECEXPLOIT

Miasma: The Malware Turning npm Into a Developer Trap

Miasma compromised 109 npm packages and GitHub Actions using Phantom Gyp and the Bun runtime. It extracts CI/CD secrets from memory an…

Jun 26, 2026views - 1.7k

CYBERSEC

SharkLoader: The Malware That Bypasses Loader Lock to Hide Cobalt Strike

Kaspersky has identified SharkLoader, a new loader that exploits Perfect DLL Hijacking to bypass Windows Loader Lock and deploy Cobalt…

Jun 26, 2026views - 1.5k

CYBERSEC

CL-STA-1062: From Taiwanese Web Hosting to Power Plants with TinyRCT Backdoor

Unit 42 reveals CL-STA-1062's escalation: from web hosting to state energy infrastructure in Southeast Asia with a custom .NET backdoo…

Jun 26, 2026views - 1.1k

CYBERSEC

Turla's STOCKSTAY Backdoor Has Targeted Ukraine Since 2022

Google Threat Intelligence Group disclosed STOCKSTAY, a multi-component backdoor from the Turla APT active since December 2022 against…

Jun 26, 2026views - 1.1k

CYBERSEC

Linux Foundation Launches Akrites: A Shared SIRT for Open Source Software

Akrites brings 19 tech giants under one shared SIRT for open source vulnerabilities. A 5% patch rate and Dolan's admission: the road a…

Jun 26, 2026views - 1.3k

CYBERSECCRITICAL

PTC Windchill: First In-the-Wild Exploitation of a PLM System

CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

Jun 26, 2026views - 1.1k

CYBERSEC

Burnyard: Local Malware Analysis Beats Cloud on Speed, But Accuracy Remains Unverified

Ohio State University's Burnyard project challenges VirusTotal and Sophos Intelix with user-space emulation on local hardware, deliver…

Jun 26, 2026views - 873