Exploit
Curated coverage and analysis in this editorial area.

NGINX Rift: Critical CVE-2026-42945 Exploitation Detected In-the-Wild
The NGINX Rift vulnerability (CVE-2026-42945) has seen active exploitation since May 16, leveraging a long-dormant heap buffer overflo…

DirtyDecrypt: Linux Local Privilege Escalation Exploit Surfaces for Unpatched Systems
A proof-of-concept for 'DirtyDecrypt'—a local privilege escalation flaw in the Linux kernel's RXGK module—is now public. Organizations…

Grafana Labs Hit by GitHub Breach: Source Code Stolen, Ransom Demands Rejected
Grafana Labs has confirmed a breach of its GitHub environment via a 'Pwn Request' vulnerability. While attackers exfiltrated proprieta…

Ivanti Confirms Post-Auth RCE in EPMM Under Active Exploitation
Ivanti has warned of targeted attacks exploiting CVE-2026-6973, a post-authentication RCE flaw in on-premise EPMM. The vulnerability,…

Apple Fixes WebKit Zero-Days Exploited in 'Extremely Sophisticated' Attacks
Apple has issued emergency security updates for Safari 26.2 and iOS 18.7.3 to remediate two critical WebKit vulnerabilities (CVE-2025-…

Burst Statistics Under Fire: Over 7,400 Attacks Blocked in 24 Hours
Threat actors are actively exploiting a critical authentication bypass (CVE-2026-8181) in the Burst Statistics WordPress plugin to hij…

Critical PAN-OS Zero-Day CVE-2026-0300: Unauthenticated Root RCE Hits Exposed Firewalls
CVE-2026-0300: An unauthenticated root RCE vulnerability in the PAN-OS Captive Portal has seen active exploitation since April 9. Whil…

CVE-2026-41940: Global Campaign Targets cPanel Authentication Bypass to Deploy Cross-Platform Backdoors
Threat actor Mr_Rot13 is actively exploiting CVE-2026-41940 in cPanel/WHM to deploy the 'Filemanager' backdoor. With over 2,000 IPs in…

BitLocker Zero-Day: Encrypted Drives Unlocked via USB and WinRE — No Credentials Needed
A new proof-of-concept named YellowKey enables BitLocker bypasses on Windows 11 and Server editions by exploiting the Windows Recovery…

Škoda Germany Data Breach: Online Store Offline After Password Hashes Exposed
Škoda has confirmed a cyberattack on its German online store. While customer data and password hashes were exposed, forensic investiga…

Google Uncovers First Confirmed AI-Generated Zero-Day Exploit Bypassing 2FA
Google has confirmed the discovery of the first zero-day exploit developed with AI assistance. The vulnerability, identified on May 11…