// 3 CRITICAL · 2 ZERO-DAY · 4 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
VULNEXPLOIT

Dirty Frag: Linux Kernel LPE Chain with Public PoC and Patches Available

Dirty Frag is a two-vulnerability chain in the Linux kernel that enables root escalation on nearly all distributions. Mainline patches…

Aug 09, 2026views - 1.2k

CYBERSECEXPLOIT

Hermes Agent: The AI Offensive That Exposed Itself — When Autonomy Becomes a Liability

Palo Alto Networks Unit 42 has uncovered the first documented campaign of fully autonomous AI-enabled cyberattacks: a Chinese-speaking…

Aug 09, 2026views - 1.4k

CYBERSECEXPLOIT

Adobe ColdFusion: Active Exploit in 2 Hours, Critical Patch for CVE-2026-48282

CVE-2026-48282 in ColdFusion carries a maximum CVSS 10.0 score with in-the-wild exploitation detected within two hours. CCCS confirms…

Aug 09, 2026views - 1.3k

CYBERSECCVE

WinRAR CVE-2025-8088: Russian and Chinese APTs Exploit N-Day Patched Six Months Ago

Google Threat Intelligence Group confirms active exploitation of CVE-2025-8088 by Russian and Chinese state actors and financially mot…

Aug 09, 2026views - 1.2k

CYBERSECZERO-DAY

Metabase Zero-Day CVSS 10.0 Actively Exploited for Corporate Data Theft

A maximum-severity SQL injection zero-day without a CVE has compromised Metabase cloud and self-hosted instances. Framework, Tally, an…

Aug 09, 2026views - 1.2k

CYBERSECEXPLOIT

TrueConf Becomes Strategic Chokepoint: Compromised Servers Infect Clients

At least three distinct attack campaigns — attributed to Ukrainian hacktivists and Chinese threat actors — have compromised on-premise…

Aug 08, 2026views - 1.2k

cveZERO-DAY

7-Zip 26.00: Any .zip File Can Trigger the Most Severe Heap Overflow Yet

CVE-2026-48095 is a heap overflow in 7-Zip's NTFS parser caused by undefined behavior in a 32-bit shift. An apparently harmless archiv…

Aug 08, 2026views - 1.3k

CYBERSECCVE

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster

CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…

Aug 08, 2026views - 1.1k

CYBERSECCVE

Iranian APTs Target U.S. PLCs: Unpatchable CVE-2021-22681 Exploited

Seven U.S. federal agencies confirmed an active Iranian APT campaign against Rockwell, Schneider, and Siemens PLCs. The critical CVE-2…

Aug 07, 2026views - 1.1k

CYBERSECEXPLOIT

Cisco Confirms Active Exploitation of Hard-Coded Credentials in Secure Firewall Management Center

Cisco has confirmed active in-the-wild exploitation of CVE-2026-20316, a static credential vulnerability in Secure Firewall Management…

Aug 07, 2026views - 1.2k

linuxCVE

Copy Fail CVE-2026-31431: Root Escalation in 732 Bytes on Linux

CVE-2026-31431 lets a local user gain root on Linux in seconds with a 732-byte script. CISA confirms active exploitation.

Aug 07, 2026views - 1.3k

CYBERSECEXPLOIT

DarkSword Exposes the Hidden iOS Exploit Market: Zero-Days in the Wild

DarkSword exploits six Apple vulnerabilities — three zero-days — to achieve full iPhone takeover. Three threat groups of differing geo…

Aug 07, 2026views - 1.1k