// 1 CRITICAL · 7 ZERO-DAY · 9 CVE · 9 EXPLOIT IN THE LAST 24H
CYBERSECCVE

CVE-2026-46817: Oracle EBS Under Attack, 450+ Servers Exposed

Defused detects active exploitation of CVE-2026-46817 on Oracle EBS honeypots. CVSS 9.8, patch available since May, over 450 instances…

Jun 29, 2026views - 771

CYBERSECCVE

Public PoC for CVE-2026-55200: libssh2 at Risk of RCE

A working proof-of-concept for CVE-2026-55200, a critical CVSS 9.2 vulnerability in libssh2, was released on June 23, 2026. The pre-au…

Jun 29, 2026views - 1.2k

CYBERSECEXPLOIT

KDDI Breach Exposes 14.2 Million Credentials Across Six Japanese ISPs

KDDI Corporation disclosed unauthorized access to a shared email platform serving six Japanese telecom operators on June 17, 2026. The…

Jun 28, 2026views - 711

CYBERSECEXPLOIT

Miasma: The Malware Turning npm Into a Developer Trap

Miasma compromised 109 npm packages and GitHub Actions using Phantom Gyp and the Bun runtime. It extracts CI/CD secrets from memory an…

Jun 26, 2026views - 1.7k

linuxCVE

CVE-2026-46331: Linux 'pedit COW' Exploit Gains Root in 24 Hours

A Linux kernel bug corrupts the page cache of setuid binaries such as /bin/su without touching disk, bypassing all integrity checks.

Jun 26, 2026views - 1.2k

VULNEXPLOIT

DirtyClone: The Fourth Variant in the DirtyFrag Family

CVE-2026-43503, the fourth variant in the DirtyFrag family, exploits cloned packets to corrupt file-backed memory. JFrog published a f…

Jun 26, 2026views - 940

CYBERSECCRITICAL

PTC Windchill: First In-the-Wild Exploitation of a PLM System

CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

Jun 26, 2026views - 1.1k

CYBERSECEXPLOIT

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries

Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

Jun 24, 2026views - 1.1k

CYBERSECEXPLOIT

TTP-Chain Validation: Proving Exploitability Without an Exploit

A Picus Security engineer proposes TTP-chain validation to test CVE exploitability without live exploits, as the disclosure-to-exploit…

Jun 23, 2026views - 1.4k

cybersecZERO-DAY

Oracle PeopleSoft Zero-Day: ShinyHunters Targets Higher Education

CVE-2026-35273, a CVSS 9.8 unauthenticated RCE, has been exploited by ShinyHunters since May 27. Over 100 universities hit; MeshCentra…

Jun 22, 2026views - 1.6k

VULNEXPLOIT

Gravity SMTP: 17M Attacks Exploit Info-Disclosure Bug

CVE-2026-4020 in the WordPress Gravity SMTP plugin is under active exploitation, exposing email credentials and infrastructure bluepri…

Jun 19, 2026views - 743

CYBERSECEXPLOIT

usbliter8: Unpatchable Exploit Hits Apple A12/A13 SecureROM

Paradigm Shift releases usbliter8, an unpatchable hardware exploit achieving arbitrary EL1 execution in Apple A12/A13 SecureROM via th…

Jun 19, 2026views - 1.1k