// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

CISA Adds Microsoft Defender DoS Flaw to KEV Catalog with June 3 Deadline

CISA has added CVE-2026-45498, a Denial of Service vulnerability in Microsoft Defender, to its Known Exploited Vulnerabilities catalog…

May 24, 2026views - 304

CYBERSECCVE

CVE-2026-41091: Microsoft Defender Engine Exploited for SYSTEM Privilege Escalation

A link-following vulnerability in the Microsoft Malware Protection Engine enables local privilege escalation to SYSTEM. An analysis of…

May 24, 2026views - 438

CYBERSECCRITICAL

May 2026 Patch Tuesday: 137 Flaws and the Domain Controller Threat

Microsoft's May 2026 security update addresses 137 vulnerabilities, including 31 critical flaws. While no zero-days were reported, una…

May 23, 2026views - 268

CYBERSECCVE

CVE-2026-48172: Critical Root Escalation in LiteSpeed cPanel Plugin Under Active Attack

A critical vulnerability in LiteSpeed’s cPanel plugin allows for privilege escalation to root. We break down the mechanism and provide…

May 23, 2026views - 208

CYBERSECCRITICAL

Apple Patches macOS RCE Vulnerability in USD Library (ZDI-26-314)

A critical out-of-bounds write in the macOS USD library could allow remote code execution through malicious 3D files. Apple released a…

May 23, 2026views - 221

CYBERSEC

Verizon DBIR 2026: Vishing Success Rates Surpass Email by 40%

The 2026 Verizon Data Breach Investigations Report (DBIR) reveals a 2% median click rate for phone-based phishing, significantly highe…

May 22, 2026views - 257

CYBERSEC

GitLab 19.0 Debuts Native Secrets Management and Air-Gapped AI

GitLab 19.0 integrates native secrets management, agentic merge request workflows, and self-hosted AI models, reinforcing its 'single…

May 22, 2026views - 219

CYBERSECEXPLOIT

Cloud Atlas Upgrades Arsenal: Novel Backdoors and Stealth RDP Patching for Cyber-Espionage

Between 2025 and 2026, the Cloud Atlas APT deployed previously undocumented backdoors, VBCloud and PowerShower, alongside modified sys…

May 22, 2026views - 416

CYBERSECEXPLOIT

TrendAI Fixes Actively Exploited Apex One Zero-Day; CISA Sets June 4 Patch Deadline

TrendAI has issued critical patches for CVE-2026-34926, a directory traversal vulnerability in Apex One on-premises installations curr…

May 22, 2026views - 228

CYBERSEC

30-Minute Lateral Breakouts: Why the SOC is Losing the Race Against AI-Driven Threats

Average breakout times have accelerated by 29%, with the fastest recorded exfiltration dropping from over four hours to just six minut…

May 22, 2026views - 226

CYBERSECEXPLOIT

Unit 42: Frontier AI Models Exploiting Open-Source Transparency to Automate Supply Chain Attacks

Frontier AI models are demonstrating the autonomous reasoning required to identify vulnerabilities in open-source code and orchestrate…

May 22, 2026views - 236

CYBERSEC

Talos Unveils AI Honeypots to Trap Malicious Agents: The Rise of Cognitive Warfare

Cisco Talos demonstrates how generative honeypots can deceive automated AI threats by weaponizing their lack of contextual awareness a…

May 22, 2026views - 238