// 2 CRITICAL · 3 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSECEXPLOIT

China-Linked Exploit Chain Targets US and Canadian Universities via Roundcube

A suspected Chinese espionage cluster has compromised fewer than ten US and Canadian universities using a two-vulnerability chain in R…

Jul 07, 2026views - 1.6k

CYBERSECZERO-DAY

Nissan Employees in Four Countries Exposed by Oracle PeopleSoft Zero-Day

Nissan Americas confirmed that attackers exploited CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft PeopleTools, to steal…

Jul 07, 2026views - 1.3k

zeroEXPLOIT

Exploitarium: The Speed Paradox — Public Exploits for Already-Patched Flaws

Pseudonymous researcher 'bikini' dumped 30+ zero-day PoCs on GitHub without coordinated disclosure. CVE-2026-55200 in libssh2 had a fi…

Jul 07, 2026views - 1.3k

CYBERSEC

CSE Discloses Three Offensive Cyber Operations in Rare 2025 Report

Canada's Communications Security Establishment (CSE) revealed in its 2025 annual report that it conducted three authorized offensive c…

Jul 06, 2026views - 1.4k

CYBERSEC

Vishing 2.0 Hits Teams: Fake IT Support Calls Deploy EtherRAT

Palo Alto Networks Unit 42 uncovered a campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support and trick…

Jul 06, 2026views - 1.5k

CYBERSEC

Cavern: The .NET Framework That Challenges Analysts With Three Distinct Compilation Formats

Check Point Research has unveiled Cavern, a modular .NET C2 framework used by the Iranian threat actor Cavern Manticore. The framework…

Jul 06, 2026views - 1.1k

VULN

Januscape: 16-Year-Old KVM Bug Enables Guest-to-Host Escape on Intel and AMD

CVE-2026-53359 strikes the shared shadow MMU code in Linux KVM used by both Intel and AMD. The flaw has existed since 2010 and require…

Jul 06, 2026views - 1.2k

aiADVISORY

Elastic Automates CVE Advisory Writing with RAG on MITRE Data

Elastic Security Labs has put into production an AI pipeline that generates complete CVE advisory drafts with CWE, CAPEC, and CVSS, gr…

Jul 06, 2026views - 184

CYBERSEC

Armored Likho Targets Governments and Power Operators with BusySnake Stealer

The Armored Likho APT group, uncovered by Kaspersky, is conducting cyber-espionage and financially motivated attacks against governmen…

Jul 06, 2026views - 1.2k

CYBERSECEXPLOIT

Adobe ColdFusion: July 1 Patch, Active Exploit Within Hours

Adobe released security updates for ColdFusion on July 1, 2026, fixing 11 vulnerabilities, six rated CVSS 10.0. Within hours, the Cana…

Jul 06, 2026views - 1.2k

ai

SkillCloak: 90% of AI Agent Skill Scanners Fail Against Obfuscated Skills

HKUST researchers demonstrate that static scanners on AI skill marketplaces systematically fail against active evasion techniques. The…

Jul 06, 2026views - 1.3k

CYBERSEC

Kaseya: 69% of SaaS Accounts in Small Businesses Are Guest Access, MFA Disabled for 56%

Kaseya's 2026 SaaS Security Report reveals that guest accounts make up 69% of monitored SaaS identities across 50,000+ SMBs, while MFA…

Jul 06, 2026views - 1.4k