// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Entra ID Vulnerability: Patch for Agent ID Privilege Escalation

Microsoft fixed a vulnerability in Entra ID's Agent ID Administrator role. The bug allowed high-privilege service principal takeover.…

Apr 28, 2026views - 200

CYBERSEC

Chinese Hacker Extradited to the US: The Xu Zewei Case

Xu Zewei, an alleged Hafnium member arrested in Milan, was extradited to the US. Accused of stealing COVID research, the case sparks a…

Apr 27, 2026views - 130

CYBERSEC

GlassWorm v2: 73 Fake VS Code Extensions Discovered on Open VSX

A cluster of 73 malicious extensions linked to GlassWorm v2 discovered on Open VSX. Attackers use sleeper packages to evade security c…

Apr 27, 2026views - 155

CYBERSEC

IRSF Fraud via Fake CAPTCHAs: Analysis of the Campaign Active Since 2020

Over 120 campaigns use Keitaro TDS to distribute IRSF scams via fake CAPTCHAs. 17 countries hit, costs up to $30 per victim. Here are…

Apr 27, 2026views - 154

CYBERSECEXPLOIT

April 2026 CISA KEV: 12 Vulnerabilities in a Week, Ransomware Alert

CISA added 12 exploited vulnerabilities to the KEV catalog from April 20-24, 2026. SimpleHelp, D-Link, and Samsung are among the affec…

Apr 25, 2026views - 202

CYBERSECCRITICAL

Pack2TheRoot: Critical Linux Passwordless Root Vulnerability

Pack2TheRoot (CVE-2026-41651) affects Linux PackageKit for 12 years. CVSS 8.8, local passwordless root access. Patches available: here…

Apr 24, 2026views - 183