// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECCVE

Microsoft Corrects Course: CVE-2026-69836 Was CVSS 10, But Not Exploited

Microsoft reclassified CVE-2026-69836, a critical Entra ID flaw, retracting its initial claim of active exploitation. The episode rais…

Aug 22, 2026views - 1k

CYBERSECCVE

CVE-2026-59310: vCenter Exploited in 5 Days, 360+ IPs Compromised

A critical VMware vCenter vulnerability went from patch to in-the-wild exploitation in just five days. Over 360 IP addresses across 47…

Aug 22, 2026views - 1.4k

CYBERSECCVE

CVE-2024-9042: SYSTEM-Level RCE on Kubernetes Windows Nodes via a Single curl Request

A vulnerability in Kubernetes' Log Query feature enables remote code execution with SYSTEM privileges on every Windows node in a clust…

Aug 22, 2026views - 1k

CYBERSECEXPLOIT

Megalodon: 5,561 GitHub Repositories Compromised in 6 Hours

The Megalodon campaign injected malicious workflows into thousands of GitHub repositories, exfiltrating CI/CD tokens. The Tiledesk cas…

Aug 21, 2026views - 1.1k

CYBERSEC

Qualcomm BootROM Bug Lets Attackers Bypass Secure Boot in Minutes

Kaspersky ICS CERT disclosed CVE-2026-25262, a Write-What-Where condition in the BootROM of seven Qualcomm chipset series. Physical US…

Aug 21, 2026views - 1.1k

CYBERSEC

North Korea’s Famous Chollima Behind 47% of State-Backed Tech Attacks

The North Korean group Famous Chollima carried out 47% of all state-sponsored attacks against the technology sector in one year, using…

Aug 21, 2026views - 1.2k

CYBERSECZERO-DAY

Lazarus Hits Windows Kernel: Zero-Day CVSS 7.0 with APT Impact

North Korea's Lazarus Group actively exploited CVE-2026-68820, a zero-day in the Windows AFD.sys driver, for over five weeks to gain S…

Aug 20, 2026views - 1k

CYBERSECCRITICAL

Zimbra SNMP RCE Under Active Exploitation, CVSS 8.9, Over 12,000 Servers at Risk

CVE-2026-73570 enables unauthenticated RCE via Zimbra's optional SNMP component. CERT Polska confirms active exploitation; patch avail…

Aug 20, 2026views - 1.1k

CYBERSECCVE

SonicWall SMA 1000 Under Attack: CVE-2026-15409 CVSS 10.0 and TOTP Seed Theft

CVE-2026-15409 and CVE-2026-15410 exposed SonicWall SMA 1000 appliances to unauthenticated root compromise. The theft of MFA seeds ren…

Aug 20, 2026views - 1.2k

CYBERSECEXPLOIT

Cl0p Exploits PTC Windchill Zero-Day to Steal 100+ GB from Shell and Philips

The Cl0p ransomware group claims theft of over 100 GB of industrial data from Shell and Philips by exploiting CVE-2026-12569. The camp…

Aug 20, 2026views - 1.2k

CYBERSECEXPLOIT

iVerify Uncovers DarkSword, iOS Exploit Framework That Bypasses Safari Without Persistence

iVerify published a technical analysis of DarkSword, a sophisticated multi-stage iOS exploit framework that leverages JavaScriptCore J…

Aug 20, 2026views - 1.1k

CYBERSECCRITICAL

NGINX DAV: Pre-Auth RCE Discovered by Calif.io in Collaboration with

CVE-2026-27654 in the NGINX HTTP DAV module: an integer underflow triggered by an alias in a prefix location enables unauthenticated r…

Aug 20, 2026views - 1k