// 1 CRITICAL · 2 ZERO-DAY · 6 CVE · 3 EXPLOIT IN THE LAST 24H
VULNEXPLOIT

Dirty Frag: Linux Kernel Vulnerability Chain Exploited in the Wild for Root Access

Dirty Frag chains two Linux kernel flaws to achieve deterministic local privilege escalation. With a public PoC available and active e…

May 11, 2026views - 143

rceCVE

CVE-2026-3854: Critical RCE Vulnerability in GitHub Triggered via Single ‘git push’

A specifically crafted git push command can execute remote code on GitHub.com and GitHub Enterprise Server. While the cloud environmen…

May 11, 2026views - 461

cveCVE

CVE-2026-31431: CISA Mandates Container Patch — Actively Exploited in the Wild

CISA has confirmed active exploitation of CVE-2026-31431, a critical Linux kernel vulnerability dubbed "Copy Fail." With a 732-byte Po…

May 07, 2026views - 162

malware

BRICKSTORM: CISA and NSA Alert on Evolving Rust Backdoor Targeting vSphere

Cybersecurity agencies have updated their Malware Analysis Report for BRICKSTORM, a sophisticated ELF backdoor targeting VMware vSpher…

May 06, 2026views - 151

CYBERSEC

Multi-Ecosystem Sleeper Packages Target CI Pipelines for Credential Theft and Persistence

At least two distinct campaigns have deployed malicious sleeper packages across RubyGems, npm, and Go modules to harvest developer cre…

May 06, 2026views - 86

linuxEXPLOIT

Linux ‘Copy Fail’ Under Active Attack: CISA Sets May 15 Patch Deadline

CISA has added CVE-2026-31431, known as 'Copy Fail,' to its KEV catalog following reports of active exploitation. The stealthy 732-byt…

May 04, 2026views - 349

cybersec

Ruby and Go Supply Chain Attack: Discover the Sleeper Risk

A new supply chain attack targets Ruby and Go using sleeper packages and fake wrappers. Learn how to protect CI/CD pipelines and corpo…

May 01, 2026views - 67