Exploit
Curated coverage and analysis in this editorial area.

CVE-2026-46817: Oracle EBS Under Attack, 450+ Servers Exposed
Defused detects active exploitation of CVE-2026-46817 on Oracle EBS honeypots. CVSS 9.8, patch available since May, over 450 instances…

Public PoC for CVE-2026-55200: libssh2 at Risk of RCE
A working proof-of-concept for CVE-2026-55200, a critical CVSS 9.2 vulnerability in libssh2, was released on June 23, 2026. The pre-au…

KDDI Breach Exposes 14.2 Million Credentials Across Six Japanese ISPs
KDDI Corporation disclosed unauthorized access to a shared email platform serving six Japanese telecom operators on June 17, 2026. The…

Miasma: The Malware Turning npm Into a Developer Trap
Miasma compromised 109 npm packages and GitHub Actions using Phantom Gyp and the Bun runtime. It extracts CI/CD secrets from memory an…

CVE-2026-46331: Linux 'pedit COW' Exploit Gains Root in 24 Hours
A Linux kernel bug corrupts the page cache of setuid binaries such as /bin/su without touching disk, bypassing all integrity checks.

DirtyClone: The Fourth Variant in the DirtyFrag Family
CVE-2026-43503, the fourth variant in the DirtyFrag family, exploits cloned packets to corrupt file-backed memory. JFrog published a f…

PTC Windchill: First In-the-Wild Exploitation of a PLM System
CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries
Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

TTP-Chain Validation: Proving Exploitability Without an Exploit
A Picus Security engineer proposes TTP-chain validation to test CVE exploitability without live exploits, as the disclosure-to-exploit…

Oracle PeopleSoft Zero-Day: ShinyHunters Targets Higher Education
CVE-2026-35273, a CVSS 9.8 unauthenticated RCE, has been exploited by ShinyHunters since May 27. Over 100 universities hit; MeshCentra…

Gravity SMTP: 17M Attacks Exploit Info-Disclosure Bug
CVE-2026-4020 in the WordPress Gravity SMTP plugin is under active exploitation, exposing email credentials and infrastructure bluepri…

usbliter8: Unpatchable Exploit Hits Apple A12/A13 SecureROM
Paradigm Shift releases usbliter8, an unpatchable hardware exploit achieving arbitrary EL1 execution in Apple A12/A13 SecureROM via th…