// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Weaponized OAuth: Government and Public Sector Targeted in Malicious Redirection Campaign

Microsoft researchers have identified active campaigns abusing OAuth redirection to steer government and public sector entities toward…

May 10, 2026views - 300

CYBERSECCRITICAL

Critical Apache HTTP/2 Double-Free Flaw Enables RCE and Unauthenticated DoS

CVE-2026-23918 in Apache 2.4.66 allows for unauthenticated Denial-of-Service via a single TCP connection and potential RCE on Debian a…

May 09, 2026views - 674

CYBERSECCRITICAL

Weaver E-cology 10.0 N-Day RCE: Unauthenticated Exploitation via Debug API (CVE-2026-22679)

CVE-2026-22679 enables unauthenticated RCE in Weaver E-cology 10.0 via the Dubbo debug endpoint. In-the-wild attacks began March 17, 2…

May 09, 2026views - 188

CYBERSEC

One Million AI Services Exposed Online: Massive Risks from Misconfigurations and Hardcoded Credentials

A security scan of over 2 million hosts has uncovered 1 million exposed AI services, many of which lack basic authentication or featur…

May 09, 2026views - 316

CYBERSEC

NVIDIA Confirms GeForce NOW Data Breach via Armenian Partner

NVIDIA has confirmed that a regional partner in the GeForce NOW Alliance suffered a breach exposing user personal data. While central…

May 09, 2026views - 184

CYBERSECCRITICAL

cPanel Issues Critical Patches as Zero-Day Exploitation Targets WHM with Mirai and Ransomware

cPanel has released security updates for three new WHM vulnerabilities while confirming that a critical authentication bypass (CVE-202…

May 09, 2026views - 218

CYBERSEC

Trellix Confirms Source Code Breach as RansomHouse Claims Attack on Internal Infrastructure

Cybersecurity giant Trellix has confirmed unauthorized access to its source code repository following an extortion claim by RansomHous…

May 09, 2026views - 278

CYBERSEC

Zara Data Breach: 197,000 Emails Exposed via Compromised Anodot Tokens

Threat actor ShinyHunters has published a 140 GB Zara dataset allegedly obtained via compromised Anodot authentication tokens. Have I…

May 08, 2026views - 208

CYBERSEC

TCLBanker Weaponizes WhatsApp and Outlook to Target 59 Financial Platforms

TCLBanker targets 59 financial institutions—spanning banks, fintech, and crypto—using autonomous worm modules to propagate through Wha…

May 08, 2026views - 168

CYBERSEC

ShinyHunters Defaces Canvas LMS, Threatening Leak of 275 Million Records

The ShinyHunters group hijacked the Canvas login page on May 7, 2026, threatening to leak data from 275 million users and causing wide…

May 08, 2026views - 182

CYBERSECZERO-DAY

Ivanti EPMM Zero-Days Under Attack: CISA Mandates Unprecedented 3-Day Patch Deadline

Two unauthenticated RCE zero-days in Ivanti Endpoint Manager Mobile (EPMM) have prompted CISA to issue a rare 72-hour remediation mand…

May 07, 2026views - 203

CYBERSECCRITICAL

Critical Palo Alto Zero-Day Grants Root RCE; Patches Delayed Until May 13

CVE-2026-0300 enables unauthenticated root RCE on Palo Alto firewalls. While CISA has ordered federal agencies to apply mitigations wi…

May 06, 2026views - 208