// 3 CRITICAL · 2 ZERO-DAY · 3 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECZERO-DAY

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies

A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Jul 26, 2026views - 1.1k

phishing

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365

A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Jul 25, 2026views - 1.1k

phishing

Joint Operation Dismantles Kratos: The AiTM Phishing Kit That Bypasses MFA

German, U.S., and Indonesian authorities have taken down over 200 servers powering the Kratos phishing kit. The code survives among ro…

Jul 25, 2026views - 1.2k

CYBERSEC

Wind Tre Fined €1.7M: Social Engineering Beats Firewalls

Italy's data protection authority fined Wind Tre €1,715,600 for two breaches caused by phone-based social engineering at retail stores…

Jul 25, 2026views - 1.2k

ai

Google Sues 'Outsider Enterprise': Gemini Weaponized as PhaaS Engine

Google has filed a civil lawsuit against a China-based cybercrime network that abused Gemini to generate phishing code at scale. The c…

Jul 25, 2026views - 1.7k

CYBERSEC

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365

Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

Jul 24, 2026views - 1.3k

CYBERSEC

LastPass Suffers New Breach via Klue: Vaults Safe, Personal Data Exposed

LastPass disclosed an indirect data breach through vendor Klue. Password vaults remain secure, but personal data including names, emai…

Jul 23, 2026views - 1.6k

CYBERSEC

German Police Dismantle Kratos, the Kit That Turned AiTM Phishing Into a Franchise

German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting…

Jul 22, 2026views - 1.5k

CYBERSEC

Microsoft Uncovers OAuth Abuse: Vishing and Supply Chain Attacks Target SaaS

Microsoft has documented ShinyHunters-linked campaigns abusing trusted OAuth relationships in Salesforce through vishing and third-par…

Jul 22, 2026views - 1.7k

CYBERSECEXPLOIT

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America

Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…

Jul 10, 2026views - 1.3k

CYBERSEC

AssuranceAmerica: 7 Million Driver's Licenses Exposed, No Credit Monitoring Offered

A single compromised employee account opened access to nearly 7 million driver's license numbers. AssuranceAmerica is not offering cre…

Jul 09, 2026views - 1.4k

CYBERSEC

Verified X Ads Spread Mac Malware and Steal Microsoft 365 Accounts

Active campaigns exploit X's blue verification badge to distribute Mac malware via ClickFix and steal Microsoft 365 OAuth tokens using…

Jul 09, 2026views - 1.9k