Exploit
Curated coverage and analysis in this editorial area.

Lazarus Hits Windows Kernel: Zero-Day CVSS 7.0 with APT Impact
North Korea's Lazarus Group actively exploited CVE-2026-68820, a zero-day in the Windows AFD.sys driver, for over five weeks to gain S…

Zimbra SNMP RCE Under Active Exploitation, CVSS 8.9, Over 12,000 Servers at Risk
CVE-2026-73570 enables unauthenticated RCE via Zimbra's optional SNMP component. CERT Polska confirms active exploitation; patch avail…

iVerify Uncovers DarkSword, iOS Exploit Framework That Bypasses Safari Without Persistence
iVerify published a technical analysis of DarkSword, a sophisticated multi-stage iOS exploit framework that leverages JavaScriptCore J…

Digital Garbage Hits the Cloud Core: Indiscriminate Scanning
SANS Dean of Research Johannes Ullrich documented widespread, untargeted scanning against the Cloud Metadata Service address 169.254.1…

SharePoint On-Prem Under Attack: Rapid7 PoC Weaponized Within 24 Hours
Threat actors are actively exploiting CVE-2026-55040 on Microsoft SharePoint on-premises servers using Rapid7's proof-of-concept code.…

Apple Patches Decade-Old iOS Zero-Day: dyld Exposed to Commercial Spyware
Apple has fixed CVE-2026-20700, a vulnerability in dyld present for over a decade and exploited in targeted attacks. The exploit chain…

Unisoc VoLTE Video-Call Exploit Chain Reaches Android Kernel — No Patch, No CVE
SSD Secure Disclosure details a two-stage exploit chain on Unisoc chipsets that starts with a malicious VoLTE video call and ends with…

GhostLock: Public Exploit Grants Root in 5 Seconds on Linux Since 2011
CVE-2026-43499 has existed in the Linux kernel for 15 years. The public proof-of-concept requires only a local user to obtain root in…

Evooo1Bot: The Botnet Turning Routers and Edge Devices into SOCKS5 Proxies
Fortinet discovers Evooo1Bot, a modular Mirai-based Linux botnet active since July 2026 that exploits 10 known CVEs to build a distrib…

DeadLock: The Ransomware Using Polygon to Evade Infrastructure Seizures
DeadLock leverages Polygon smart contracts to rotate proxy servers and host its data leak site, rendering the infrastructure-seizure s…

ShieldBreak: Zero-Day Exploit Targets Windows Defender for SYSTEM Privilege Escalation
Nightmare Eclipse released ShieldBreak, a zero-day exploit achieving SYSTEM privileges on fully patched Windows via Microsoft Defender…

CVE-2026-65400: From Patch to Exploit in 4 Hours on macOS Screen Sharing
The Dutch NCSC confirms active exploitation of CVE-2026-65400: a pre-authentication bypass in macOS Screen Sharing granting root acces…