Category: Vulnerabilities
Max-Severity SAP Commerce Cloud RCE Exploited Just Days After Patch
A CVSS 10.0 unauthenticated remote code execution flaw in SAP Commerce Cloud's Data Hub Adapter is already being hit in the wild,…
macOS Screen Sharing Auth Bypass Exploited to Plant Monero Miners
Dutch NCSC warns attackers are actively abusing CVE-2026-65400, a macOS Screen Sharing flaw, to gain root access and deploy cryptomining malware on…
New Evooo1Bot Malware Turns Routers Into Proxy Nodes for Attackers
A modular, Mirai-based Linux botnet dubbed Evooo1Bot is compromising gateway devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, converting them…
Trezor Discloses Data Breach at Shipping Partner ShipMonk, 14,000 Customers Affected
A breach at third-party fulfillment provider ShipMonk exposed names, addresses, and contact details of nearly 14,000 Trezor customers, though Trezor says its…
Beacon CRM Breach Traces Back to Leaked AWS Key, Over 1,000 Charities Affected
UK nonprofit CRM provider Beacon says attackers used a compromised AWS access key found in public JavaScript build files to exfiltrate its…
Attackers Exploit Critical VMware vCenter Flaw CVE-2026-59310 Within Days of Patch
An APT actor is exploiting a critical directory traversal and RCE bug in VMware vCenter's Syslog server, hitting over 360 IP addresses…
ShieldBreak Zero-Day Bypasses Microsoft Defender Patch, Grants SYSTEM Access
A new PoC dubbed ShieldBreak sidesteps Microsoft's fix for the RoguePlanet Defender flaw, letting attackers escalate to SYSTEM on fully patched Windows…
Cisco Warns of Actively Exploited ASA/FTD VPN Flaw Causing Device Crashes
A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software is being exploited to remotely crash devices via crafted HTTP requests…
Microsoft Fixes 398 Flaws, Patches Actively Exploited Windows Kernel Driver Zero-Day
August's Patch Tuesday closes 398 vulnerabilities, including a zero-day in a core Windows networking driver that attackers are already using to gain…
Microsoft’s August Patch Tuesday Fixes Nearly 400 Flaws, One Under Active Attack
Microsoft's latest security update addresses 398 vulnerabilities, including an actively exploited Windows privilege escalation bug, as AI-assisted discovery continues to drive record…
Mozilla Rotates Firefox GPG Signing Key After Accidental GitHub Exposure
Mozilla revoked and replaced a GPG signing subkey used for Firefox and Thunderbird Linux artifacts after finding an unencrypted copy in a…
CISA Confirms Active Exploitation of Critical Kemp LoadMaster RCE Flaw
A command injection bug in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is being actively exploited in the wild, prompting CISA to add…