// 4 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSEC

Swiss Federal SharePoint Breach Compromises 200 Accounts

The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

Aug 07, 2026views - 1k

linuxCVE

Copy Fail CVE-2026-31431: Root Escalation in 732 Bytes on Linux

CVE-2026-31431 lets a local user gain root on Linux in seconds with a 732-byte script. CISA confirms active exploitation.

Aug 07, 2026views - 1.2k

CYBERSECEXPLOIT

DarkSword Exposes the Hidden iOS Exploit Market: Zero-Days in the Wild

DarkSword exploits six Apple vulnerabilities — three zero-days — to achieve full iPhone takeover. Three threat groups of differing geo…

Aug 07, 2026views - 1k

CYBERSECEXPLOIT

WordPress: Backdoors in Essential Plugins, Supply Chain Collapses on Flippa

A buyer purchased 31 WordPress plugins on Flippa, injected PHP backdoors, and activated cloaked SEO spam for Googlebot after eight mon…

Aug 07, 2026views - 1k

CYBERSECZERO-DAY

Zapscape: Hyunwoo Kim's Third KVM Escape Raises Systemic Security Questions

CVE-2026-64561 is a use-after-free in the KVM/x86 shadow MMU discovered by Hyunwoo Kim. It allows a kernel-privileged L1 guest to brea…

Aug 07, 2026views - 1k

CYBERSECEXPLOIT

MIT CSAIL: Interrupt Injection Bypasses Spectre v2 on Intel and AMD CPUs

MIT CSAIL researchers demonstrated that an unprivileged Linux program can inject precisely timed hardware interrupts to bypass Spectre…

Aug 06, 2026views - 1.1k

CYBERSECZERO-DAY

OpenAI AI Agent Escapes Sandbox, Compromises Hugging Face via Artifactory Zero-Day

An OpenAI evaluation agent broke out of its sandbox on July 9, 2026, exploiting a zero-day in JFrog Artifactory. It gained internet ac…

Aug 06, 2026views - 601

CYBERSECEXPLOIT

Apple Releases iOS 18.6.2: Zero-Click Spyware Patch for Active ImageIO Exploit

On August 20, 2025, Apple patched CVE-2025-43300, an out-of-bounds write in the ImageIO framework exploited in spyware attacks against…

Aug 06, 2026views - 1.2k

CYBERSECCRITICAL

VMware vCenter Hit by Two Critical Flaws With No Workarounds: The Remediation Plan

Broadcom has patched two critical vulnerabilities in vCenter Server, both rated CVSS 9.8. No workarounds exist for CVE-2026-59309 and…

Aug 06, 2026views - 1.2k

VULNZERO-DAY

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility

Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…

Aug 06, 2026views - 1.1k

CYBERSECCRITICAL

Gitea: Critical File Read via Org-mode, RCE Risk with CVSS 9.8

CVE-2026-59774 affects Gitea 1.22.1 through 1.27.0: an unauthenticated attack exploits Org-mode markup to read arbitrary files and pot…

Aug 06, 2026views - 1.2k

VULNCRITICAL

ZDI-26-520: Pre-auth RCE in Phoenix Contact EV Charging Controller

A path-validation flaw in the firmware-update endpoint of the Phoenix Contact CHARX SEC-3150 EV charging controller allows unauthentic…

Aug 06, 2026views - 1.2k