// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

HAMLOCK: Invisible AI Backdoor Spans Chip and Software

Researchers demonstrate HAMLOCK, a supply-chain attack that splits a neural-network backdoor between minimal software weight changes (…

Jun 15, 2026views - 1.1k

CYBERSECZERO-DAY

ZDI-26-356: Apache Reverse Proxy Betrayed by AJP Backend

CVE-2026-34032 in mod_proxy_ajp lets a compromised AJP backend read out of bounds, with potential escalation to RCE via vulnerability…

Jun 15, 2026views - 962

CYBERSECCRITICAL

Adobe Acrobat Reader: UAF in Annotation Parser Enables RCE via Malicious PDF

CVE-2026-27220: use-after-free in Adobe Acrobat Reader DC's Annotation parser, CVSS 7.8. Patch available, no known in-the-wild exploit…

Jun 15, 2026views - 819

CYBERSECZERO-DAY

ShinyHunters Hits 100+ Universities with Oracle Zero-Day

CVE-2026-35273 in PeopleSoft EMHub: unauthenticated RCE, CVSS 9.8, 68% of victims in higher education. CISA mandates patch by June 15.

Jun 14, 2026views - 1.6k

CYBERSECZERO-DAY

X.Org Server: Root LPE via XkbSetCompatMap; Patch Released

CVE-2026-33999 in X.Org Server enables local privilege escalation to root. Discovered by ZDI, the fix follows a coordinated disclosure…

Jun 13, 2026views - 991

CYBERSEC

Maine Disables Breach Notification Portal After Fake Discord and VRChat Disclosures

Maine's government portal automatically published data breach notifications without verification, facilitating the spread of misinform…

Jun 12, 2026views - 769

CYBERSECCRITICAL

LangGraph Vulnerability Chain Grants RCE via AI Agent Persistence

Check Point Research has uncovered a SQL injection and deserialization chain in LangGraph that enables RCE on self-hosted deployments.…

Jun 12, 2026views - 866

CYBERSECCRITICAL

Europol and DOJ Dismantle AudiA6: A Critical Hub for Ransomware Money Laundering Smashed

In a major operation on June 10, 2026, authorities arrested two administrators in Georgia and seized 25 domains and 30+ servers. The A…

Jun 11, 2026views - 1k

CYBERSEC

Algorithmic Exploitation: How TikTok and Instagram Reels Amplify Vidar Malware

ReversingLabs research reveals threat actors are using fake Spotify Premium tutorials to distribute the Vidar infostealer via PowerShe…

Jun 11, 2026views - 1.1k

CYBERSECEXPLOIT

Microsoft Patches Actively Exploited Exchange Zero-Day, Mandates Dual-Layer Defense

Microsoft has released a permanent patch for CVE-2026-42897, an XSS zero-day in Exchange OWA. Despite the update, the EEMS mitigation…

Jun 10, 2026views - 892

CYBERSEC

Windows Narrator Braille: LPE Hidden in the Accessibility Path

CVE-2026-48565: Local escalation to SYSTEM via brlapi, the Windows Braille service frequently overlooked by enterprise patching cycles.

Jun 10, 2026views - 769

CYBERSECCVE

CVE-2026-3886: QEMU virtio-gpu Integer Overflow Enables Guest-to-Host Escape

An integer overflow in QEMU’s virtio-gpu driver allows local privilege escalation from guest to host with a CVSS score of 8.8. The ups…

Jun 10, 2026views - 1.2k