Exploit
Curated coverage and analysis in this editorial area.

NSA and CISA Issue First Alert on AI-Driven Attacks Against Critical Siemens PLCs
Five U.S. federal agencies have released joint advisory AA26-231A confirming threat actors are using AI-generated scripts to target in…

Unisoc VoLTE Exploit Chain Opens Android Kernel via Modem — No Patch, No CVE
A two-stage exploit chain in Unisoc VoLTE modems lets an attacker with a rogue 4G network achieve full Android kernel access when the…

Lazarus Exploits Windows AFD.sys Zero-Day for SYSTEM: Third Time in Two Years
The North Korean group used CVE-2026-68820 for local privilege escalation to SYSTEM, deploying the FudModule 3.1 rootkit and Troy back…

French Cyber-Spies Used GitHub Code to Hack EncroChat
A reverse-engineering report reveals French malware targeting EncroChat was copied from GitHub. Thousands of convictions across Europe…

Exploitarium: The 'Recruitment by Chaos' That Shatters the CVD Model
Pseudonymous researcher 'bikini' dumped over 30 zero-day PoC exploits on GitHub on June 27, 2026, without any vendor coordination. CVE…

CISA Orders September Patches: Two Critical TrueConf Flaws Actively Exploited
CISA added two critical TrueConf Server vulnerabilities to the KEV catalog, already exploited by the Head Mare group to deploy Phantom…

wp2shell: 45 Million Exploit Attempts in 7 Days — Vulnerability Management Hits a Breaking Point
The wp2shell campaign generated 45 million exploit attempts in one week. The data proves traditional vulnerability management is no lo…

Windows ShieldBreak Zero-Day: Researcher Publishes Exploit Targeting Defender
Nightmare Eclipse released ShieldBreak, a zero-day exploit that weaponizes Windows Defender for local privilege escalation. The exploi…

GitLab's 'Future Field' Security Feature Turns Weapon: Emergency Patches for CVE-2026-19478
GitLab released critical patches on August 17, 2026 for CVE-2026-19478, a GraphQL code injection vulnerability with a CVSS 9.4 score t…

CVE-2026-59310: vCenter Exploited in 5 Days, 360+ IPs Compromised
A critical VMware vCenter vulnerability went from patch to in-the-wild exploitation in just five days. Over 360 IP addresses across 47…

CISA Adds Apple Zero-Day CVE-2025-43300 to KEV Catalog: CVSS 10, September 11 Deadline
CISA has cataloged CVE-2025-43300, an out-of-bounds write in Apple ImageIO rated CVSS 10.0 CRITICAL. Federal civilian agencies must pa…

Megalodon: 5,561 GitHub Repositories Compromised in 6 Hours
The Megalodon campaign injected malicious workflows into thousands of GitHub repositories, exfiltrating CI/CD tokens. The Tiledesk cas…