Exploit
Curated coverage and analysis in this editorial area.

DarkSword and Coruna: Government-Grade Spyware Turns Mass Crime on iOS
Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click…

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks
The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

GhostApproval, 14 UniFi CVEs, and Roundcube Espionage: A Triple Threat Convergence
Three critical attack vectors converged in July 2026: the GhostApproval symlink vulnerability in six AI coding assistants, 14 new crit…

From VPN Bypass to Encrypted Domain: How CVE-2026-0257 Fuels Qilin Ransomware
Arctic Wolf Labs confirms active exploitation of CVE-2026-0257 to deploy Qilin ransomware. Specific TTPs reveal shared infrastructure…

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery
The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

DarkSword: JavaScript iOS Exploit Kit Strikes via Compromised Legitimate Sites
DarkSword chains six CVEs to compromise iPhones through compromised legitimate websites. The fileless, in-memory chain self-erases aft…

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware
On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

LegacyHive: Nightmare Eclipse's Ninth Zero-Day Pierces Fully Patched Windows
Nightmare Eclipse has released LegacyHive, a zero-day exploit targeting the Windows User Profile Service to load arbitrary registry hi…

Three Chained Zero-Days in Siemens Switches: From xz Utility to Root Access
Three zero-day vulnerabilities in Siemens RUGGEDCOM ROX II switches enable full privilege escalation and persistent root access. Firmw…

CISA Adds Two Joomla Zero-Days to KEV Catalog: Deadline July 13
On July 10, 2026, CISA added two actively exploited zero-day vulnerabilities in Joomla extensions to its Known Exploited Vulnerabiliti…

Metasploit Arms FlowiseAI and macOS: Two Exploits Land in the Framework
Metasploit has merged exploit modules for CVE-2026-41264, an unauthenticated RCE in FlowiseAI's CSV Agent, and CVE-2024-27822, a local…

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America
Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…