// 1 CRITICAL · 2 ZERO-DAY · 2 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSEC

FulcrumSec Steals 86 GB of MAG Data: API Keys Were Hardcoded in Client-Side JavaScript

The FulcrumSec data extortion group claimed responsibility for the Manchester Airports Group breach, publishing ~86 GB of data. Access…

Sep 02, 2026views - 1k

ransomware

Aurora Ransomware Group Abuses AI Cursor Agent for Post-Compromise Attacks

The Aurora ransomware group used the AI-powered Cursor Agent with Claude Sonnet as an interactive operational assistant during active…

Aug 28, 2026views - 1.2k

nextjsCRITICAL

Next.js: Two Critical RCE Patches Expose the Managed vs. Self-Hosted Protection Gap

Vercel released critical patches for two unauthenticated RCE vulnerabilities in Next.js on August 25, 2026. The disparity in protectio…

Aug 27, 2026views - 1.1k

CYBERSEC

VCS Blind Spot: Wiz CIRT Publishes DFIR Matrix for GitHub and GitLab

The Wiz CIRT DFIR poster maps VCS audit logs to MITRE ATT&CK but exposes critical gaps: 88% of customers use SaaS with 7-day retention…

Aug 27, 2026views - 1.1k

CYBERSEC

Satanic Exposes 1,033 Stripe API Keys: The Vector Isn't an Infostealer

Threat actor Satanic released data from 669 Stripe vendors with live API keys. Analysis rules out infostealer infections and points to…

Aug 27, 2026views - 1.1k

VULN

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered

CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

Aug 25, 2026views - 1k

bluetoothCRITICAL

BlueZ: A2DP Buffer Overflow Enables Root RCE After Pairing

ZDI-26-589 discloses a stack-based buffer overflow in the BlueZ Bluetooth stack's A2DP module, allowing remote code execution as root…

Aug 25, 2026views - 1.1k

CYBERSECCRITICAL

libwebsockets: RCE via HTTP/2 HPACK, Single-Line Patch Available

ZDI-26-590 discloses an unauthenticated remote code execution vulnerability in libwebsockets. A missing bounds check in the HTTP/2 HPA…

Aug 24, 2026views - 994

CYBERSECEXPLOIT

TeamPCP Exploits AI Supply Chain to Steal One Terabyte of Credentials

The TeamPCP campaign compromised GitHub Actions and PyPI packages between March and April 2026. Over 2,500 organizations potentially e…

Aug 24, 2026views - 1.1k

zeroZERO-DAY

Exploitarium: The 'Recruitment by Chaos' That Shatters the CVD Model

Pseudonymous researcher 'bikini' dumped over 30 zero-day PoC exploits on GitHub on June 27, 2026, without any vendor coordination. CVE…

Aug 24, 2026views - 1k

supply

Trivy and LiteLLM Compromised: 2,100+ Organizations Exposed via Security Tools

TeamPCP compromised the CI/CD pipelines of Trivy and LiteLLM between March 19 and March 24, 2026. Six confirmed breaches hit European…

Aug 23, 2026views - 1k

CYBERSEC

Stripe: 1,033 Vendor API Keys Exposed, Satanic Claims ~20,000 Total

Threat actor Satanic published data from 669 Stripe vendors containing over 1,000 live API keys. Hudson Rock found no infostealer infe…

Aug 23, 2026views - 1.1k