Exploit
Curated coverage and analysis in this editorial area.

WinRAR CVE-2025-8088: Russian and Chinese APTs Exploit N-Day Patched Six Months Ago
Google Threat Intelligence Group confirms active exploitation of CVE-2025-8088 by Russian and Chinese state actors and financially mot…

Metabase Zero-Day CVSS 10.0 Actively Exploited for Corporate Data Theft
A maximum-severity SQL injection zero-day without a CVE has compromised Metabase cloud and self-hosted instances. Framework, Tally, an…

TrueConf Becomes Strategic Chokepoint: Compromised Servers Infect Clients
At least three distinct attack campaigns — attributed to Ukrainian hacktivists and Chinese threat actors — have compromised on-premise…

7-Zip 26.00: Any .zip File Can Trigger the Most Severe Heap Overflow Yet
CVE-2026-48095 is a heap overflow in 7-Zip's NTFS parser caused by undefined behavior in a 32-bit shift. An apparently harmless archiv…

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…

Iranian APTs Target U.S. PLCs: Unpatchable CVE-2021-22681 Exploited
Seven U.S. federal agencies confirmed an active Iranian APT campaign against Rockwell, Schneider, and Siemens PLCs. The critical CVE-2…

Cisco Confirms Active Exploitation of Hard-Coded Credentials in Secure Firewall Management Center
Cisco has confirmed active in-the-wild exploitation of CVE-2026-20316, a static credential vulnerability in Secure Firewall Management…

Copy Fail CVE-2026-31431: Root Escalation in 732 Bytes on Linux
CVE-2026-31431 lets a local user gain root on Linux in seconds with a 732-byte script. CISA confirms active exploitation.

DarkSword Exposes the Hidden iOS Exploit Market: Zero-Days in the Wild
DarkSword exploits six Apple vulnerabilities — three zero-days — to achieve full iPhone takeover. Three threat groups of differing geo…

WordPress: Backdoors in Essential Plugins, Supply Chain Collapses on Flippa
A buyer purchased 31 WordPress plugins on Flippa, injected PHP backdoors, and activated cloaked SEO spam for Googlebot after eight mon…

Lazarus Shares Zero-Day and C2 With Gunra: South Korea Raises Alarm
Four South Korean agencies confirm the Lazarus Group shared tools, infrastructure, and a zero-day vulnerability with the Gunra ransomw…

MIT CSAIL: Interrupt Injection Bypasses Spectre v2 on Intel and AMD CPUs
MIT CSAIL researchers demonstrated that an unprivileged Linux program can inject precisely timed hardware interrupts to bypass Spectre…