// 1 CRITICAL · 7 ZERO-DAY · 8 CVE · 8 EXPLOIT IN THE LAST 24H
CYBERSECEXPLOIT

Public Scanner Released for NGINX Map Regex Flaw; Full RCE Exploit Expected Around August 5

Researcher Stan Shaw (cyberstan) has published an open-source static scanner for CVE-2026-42533, a heap buffer overflow in the NGINX s…

Jul 26, 2026views - 942

CYBERSECZERO-DAY

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies

A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Jul 26, 2026views - 971

CYBERSECCRITICAL

Autel Wallbox Exposed to Pre-Auth RCE: The Pwn2Own Bug Hitting Home EV Chargers

Trend Micro's Zero Day Initiative published advisory ZDI-26-437 on July 15, 2026, detailing a pre-authentication remote code execution…

Jul 26, 2026views - 972

CYBERSECCRITICAL

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft

The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

Jul 25, 2026views - 1.3k

CYBERSECEXPLOIT

DarkSword: The iOS Kit That Armed Three Spy Groups With Six Flaws

Google Threat Intelligence Group uncovered DarkSword, a full-chain iOS exploit kit written in JavaScript that has been active since No…

Jul 25, 2026views - 1.3k

CYBERSECEXPLOIT

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete

CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

Jul 24, 2026views - 1.2k

CYBERSECZERO-DAY

Zero-Click Spyware: How Infection Works Without Touching the Phone

Zero-day attacks on smartphones exploit unknown vendor vulnerabilities to install spyware without any user interaction. A Bitdefender…

Jul 24, 2026views - 1.6k

VULNCVE

CVE-2026-6875: Active Attacks on Self-Hosted ServiceNow; Cloud Protected Since April

Threat actors are exploiting CVE-2026-6875 against unpatched self-hosted ServiceNow instances. The sandbox escape enables pre-authenti…

Jul 24, 2026views - 1.3k

CYBERSECCVE

CVE-2026-16232: Check Point SmartConsole Zero-Day Actively Exploited in the Wild

Check Point confirms active exploitation of CVE-2026-16232, an authentication bypass with a CVSS 9.3 score in SmartConsole. CISA has a…

Jul 23, 2026views - 1.2k

VULNEXPLOIT

Windmill Under Attack: Active Path Traversal on 170 Exposed Servers

CVE-2026-29059 hits the Windmill automation platform with an unauthenticated path traversal. A patch has existed since January, yet th…

Jul 23, 2026views - 396

metasploitCRITICAL

Metasploit Drops Two Modules: FlowiseAI RCE and macOS Privilege Escalation

The Metasploit Framework adds exploit modules for CVE-2026-41264 in FlowiseAI and CVE-2024-27822 in macOS PackageKit. Both are product…

Jul 23, 2026views - 1.5k

CYBERSECZERO-DAY

SonicWall SMA 1000: The Unexpected Backdoor — Active Exploitation and a 72-Hour Patch Window

SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, 2026: active exploitation since June 22, public PoC, and a mandatory…

Jul 22, 2026views - 1.2k