// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Ex-Huntress Analyst Accuses Company of Covering Up Insider Who Allegedly Fed FBI Data to DevMan Ransomware Gang

A former SOC analyst claims Huntress concealed an insider who passed U.S. law enforcement communications to the DevMan ransomware grou…

Jun 26, 2026views - 821

CYBERSEC

Beyond IOCs: Talos Unveils Vision for LLMs in Threat Intelligence

Cisco Talos explores how large language models transcend traditional indicators of compromise by indexing strategic reports in natural…

Jun 25, 2026views - 1.2k

CYBERSEC

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack

Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

Jun 25, 2026views - 807

CYBERSEC

ThreatsDay June 2026: Miasma Toolkit Leaked, Claude Code Patched, AI Agent Phishing

The June 2026 ThreatsDay Bulletin, published June 11 by Rescana, is an aggregated cyber threat digest. This analysis relies primarily…

Jun 25, 2026views - 1.1k

CYBERSECCVE

Adobe Reader: Patch Now for CVE-2026-27278, RCE via PDF

Adobe has released APSB26-26 for CVE-2026-27278, a Use-After-Free vulnerability in Acrobat Reader DC that enables remote code executio…

Jun 25, 2026views - 1.2k

CYBERSECCRITICAL

FlowiseAI CSV Agent RCE: Arbitrary Python Code Execution with Authentication Bypass

ZDI-26-365 discloses a remote code execution vulnerability in FlowiseAI's CSV Agent: Python code injection via customReadCSV with auth…

Jun 25, 2026views - 1.3k

CYBERSECCRITICAL

Docker MCP Plugin: RCE via OCI Label, Urgent Patch

ZDI-26-363: The YAML label io.docker.server.metadata in the Docker MCP Gateway enables remote code execution as root. The fix isolates…

Jun 25, 2026views - 1k

CYBERSECCRITICAL

ZDI-26-376: RCE in Quest NetVault Backup with Authentication Bypass

Command injection in NVBULogDaemon enables remote code execution as SYSTEM. Patch available but no CVE or CVSS assigned.

Jun 25, 2026views - 825

CYBERSECZERO-DAY

Fuji Electric Tellus: Kernel Driver Bug Enables SYSTEM Privilege Escalation

CVE-2026-8108 in the Fuji Electric Tellus pcid64 driver allows local privilege escalation to SYSTEM via Registry APIs with excessive p…

Jun 24, 2026views - 929

CYBERSECCRITICAL

Unraid: Command Injection in ToggleState.php Enables RCE

CVE-2026-9773 in the Unraid web server: command injection in ToggleState.php allows authenticated remote code execution. CVSS 8.8, fix…

Jun 24, 2026views - 792

CYBERSECEXPLOIT

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries

Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

Jun 24, 2026views - 1.1k

CYBERSEC

Railway Cybersecurity: The IT/OT Boundary Has Collapsed

Rail systems are abandoning isolated SCADA for IP networks and AI. DNV's Jorge Aldegunde explains why security is now an active interf…

Jun 24, 2026views - 1.2k