// 1 CRITICAL · 3 ZERO-DAY · 3 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSECEXPLOIT

French Cyber-Spies Used GitHub Code to Hack EncroChat

A reverse-engineering report reveals French malware targeting EncroChat was copied from GitHub. Thousands of convictions across Europe…

Aug 25, 2026views - 1.2k

VULNCVE

CVE-2026-32475: Elementor Pro ≤4.2.1 Exposed to Unauthenticated RCE

A critical CVSS 9.0 vulnerability in Elementor Pro allows unauthenticated PHP file upload. The fix sat ready for 34 days before releas…

Aug 25, 2026views - 1.2k

malware

DOUBLECUP: The Fake Steganography That Exposes Criminal Payloads to a Simple grep

The DOUBLECUP loader promises advanced steganography but hides PowerShell code in plaintext after the PNG file. Extractable with FINDS…

Aug 25, 2026views - 821

CYBERSEC

Windows: Localized Filename Bug Steals NTLM Credentials with a Single Click

CVE-2026-50508: A flaw in Windows localized filenames enables NTLM hash theft simply by opening a file or visiting a web page. Microso…

Aug 25, 2026views - 1k

VULN

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered

CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

Aug 25, 2026views - 1k

CYBERSECCRITICAL

Foxit PDF Reader: UAF Bug in Annotation Parser Enables Remote Code Execution

ZDI-26-604 (CVE-2026-13126) is a Use-After-Free in Foxit PDF Reader's Annotation object parsing. Opening a malicious PDF allows arbitr…

Aug 25, 2026views - 1k

CYBERSECCRITICAL

Safari UAF in JavaScriptCore: Apple Patches Already Available

CVE-2026-64715 in Safari's JavaScript engine enables remote code execution simply by visiting a malicious page. Patches were released…

Aug 25, 2026views - 1.1k

nvidiaCRITICAL

NVIDIA TensorRT: ONNX Parsing Flaw Enables RCE with CVSS 7.8

CVE-2026-24268 strikes the ONNX parser in NVIDIA TensorRT. A heap-based buffer overflow with CVSS 7.8, minimal user interaction, and a…

Aug 25, 2026views - 935

bluetoothCRITICAL

BlueZ: A2DP Buffer Overflow Enables Root RCE After Pairing

ZDI-26-589 discloses a stack-based buffer overflow in the BlueZ Bluetooth stack's A2DP module, allowing remote code execution as root…

Aug 25, 2026views - 1.1k

CYBERSECCRITICAL

libwebsockets: RCE via HTTP/2 HPACK, Single-Line Patch Available

ZDI-26-590 discloses an unauthenticated remote code execution vulnerability in libwebsockets. A missing bounds check in the HTTP/2 HPA…

Aug 24, 2026views - 993

CYBERSECZERO-DAY

Windows Compatibility Appraiser: LPE Bug Escalates from LOCAL SERVICE to SYSTEM

ZDI-26-606 discloses a local privilege escalation vulnerability in the Microsoft Windows Compatibility Appraiser. Symbolic link manipu…

Aug 24, 2026views - 1k

VULNCRITICAL

Home Assistant Green: Root RCE via Localhost Exploit Disclosed by ZDI

ZDI-26-561 reveals a command injection in the Home Assistant Green go2rtc process. The flaw allows arbitrary code execution as root fo…

Aug 24, 2026views - 1.2k