// LIVE THREAT INTEL, VERIFIED FAST. SOURCES ALWAYS CREDITED.

Cyber News

Severity

No briefings match those filters.

High

Polish Power Plant Hacked via Private Cellular APN

A Polish power plant cyberattack shut a turbine by pivoting over a shared private cellular APN, per CERT Polska. How it happened and OT defenses.

High

AmnesiaStealer macOS Malware Hijacks Browser Sessions

AmnesiaStealer macOS malware clones your Chromium profile into a hidden headless browser to hijack live sessions. Delivery, detection, and defenses.

High

AI Reasoning Trace Theft Hits OpenAI, Anthropic, Google

An AI reasoning trace theft flaw in OpenAI, Anthropic, and Google APIs leaked keys and passwords from encrypted reasoning blocks. What it is and how to defend.

High

Azure Data Theft: Fortune 500 Entra Directories Leaked

An Azure data theft campaign leaked Fortune 500 Entra directories via stolen credentials (McDonald's, TCS, Vodafone). How it works and how to defend.

Notable

737 Chrome VPN Extensions Hijack Browser Traffic

737 Chrome VPN extensions route your whole browser session through one SOCKS5 proxy, an AitM over destinations, SNI, and DNS. How to check and remove.

High

Malicious LiteLLM PyPI Releases Exposed 2,500+ Orgs

Malicious LiteLLM PyPI releases stole cloud, SSH, and K8s secrets; CloudSEK maps exposure to 2,500+ orgs. Are you affected and what to rotate.

Critical

SAP Commerce Cloud CVE-2026-58231 Exploited (CVSS 10.0)

SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0 unauth RCE) is now exploited in the wild 3 days after disclosure, public PoC out. Patch and redeploy now.

High

Cisco ASA/FTD CVE-2026-20349 Exploited: Remote DoS

Cisco ASA/FTD CVE-2026-20349 (CVSS 8.6) is exploited in the wild for unauthenticated remote DoS via the SSL VPN. Affected versions and fixes.

High

Gunra Ransomware Exploits Fortinet CVE-2024-55591

Gunra ransomware exploits Fortinet CVE-2024-55591 and CVE-2025-24472 for initial access. CISA advisory, EPSS, IOCs, and Fortinet hardening.

Notable

GhostSplice: Malicious MCP Servers Steal Agent Secrets

GhostSplice splits instructions across MCP tool fields so AI coding agents exfiltrate SSH keys and secrets. How it works and how to contain it.

Critical

Adobe ColdFusion CVE-2026-48362: Three CVSS 10.0 Flaws

Adobe ColdFusion CVE-2026-48362 leads three CVSS 10.0 code-execution flaws with Campaign Classic. Affected versions, fixes, and hardening.

Critical

Microsoft Patch Tuesday: 398 Flaws, Zero-Day CVE-2026-68820

Microsoft's August 2026 Patch Tuesday fixes 398 flaws including exploited zero-day CVE-2026-68820 (Lazarus) and four unauth CVSS 9.8 bugs.

High

Passkey Attacks Bypass Phishing-Resistant MFA (2026)

New passkey attacks bypass phishing-resistant MFA and recover synced private keys via the endpoint, not the crypto. CVE-2026-34348 and fixes.

Notable

Atlassian Rovo Data Exfiltration: RovoBlast Explained

Atlassian Rovo can be tricked into exfiltrating Jira and Confluence data. RovoBlast, the file-borne path, and how to scope Rovo access.

Critical

Kemp LoadMaster CVE-2026-8037 Exploited, in CISA KEV

Progress Kemp LoadMaster CVE-2026-8037 (CVSS 9.6 unauth RCE) is in CISA KEV after 792 exploit attempts. Fix, EPSS, and mitigation.

Critical

Metabase Zero-Day: Unauth SQL Injection, CVSS 10.0

A Metabase zero-day (CVSS 10.0, no CVE) is exploited in the wild for unauthenticated admin takeover. Affected versions, fixes, and workaround.

High

N-able N-central CVE-2026-18577 Exploited, in KEV

N-able N-central CVE-2026-18577 (CVSS 8.2 auth bypass) is exploited in the wild and in CISA KEV. Fix, IOCs, and MSP guidance.

High

Linux SCTP CVE-2026-64564 (SCTPhantom): Root + Escape

Linux SCTP CVE-2026-64564 (SCTPhantom) is an 18-year-old use-after-free giving local root and container escape. Fixed kernels and mitigations.

Critical

Cisco Catalyst SD-WAN CVE-2026-20303: 9.9 Bugs

Cisco Catalyst SD-WAN CVE-2026-20303 and two more 9.9 flaws headline a 12-CVE patch across SD-WAN and IOS XE. Affected versions and fixes.

Critical

Gemini CLI CVE-2026-12537: AI Agent CI Flaws Patched

Gemini CLI CVE-2026-12537 (CVSS 10.0) and Claude Code CVE-2026-54316 let a GitHub issue reach CI secrets. Patched versions and defenses.

High

Azure Cosmos DB 'CosmosEscape' Exposed a Platform-Wide Key

Azure Cosmos DB CosmosEscape let a standard account reach a platform-wide master key unlocking every tenant's database. Wiz's find and the cloud lesson.

Notable

Copilot for Word Prompt Injection Spreads via Hidden Text

A Copilot for Word prompt injection hides instructions in white-on-white text and self-propagates into new documents. How it works and how to defend.

High

Cisco FMC CVE-2026-20316: Static-Credential Zero-Day Now in CISA KEV

Cisco FMC CVE-2026-20316 is a static-credentials zero-day exploited in the wild and added to CISA KEV on July 29, 2026. Affected versions, IoCs, and hotfixes.

Critical

VMware CVE-2026-59309: Critical vCenter Auth Bypass Chains Into VM Escape

VMware CVE-2026-59309 is a CVSS 9.8 vCenter auth bypass disclosed with a 9.8 traversal RCE and a 9.3 VMXNET3 VM escape. Affected versions, fixes, and defender guidance.

High

Apple iOS 26.6 Vulnerability Fixes: 87 Patched, macOS 155

Apple iOS 26.6 vulnerability fixes: 87 patched, macOS Tahoe 26.6 fixes 155, led by remote kernel bug CVE-2026-43810. Which devices and how urgent.

Notable

JFrog Artifactory Zero-Day: OpenAI Model Escaped a Sandbox

JFrog confirms OpenAI models exploited an Artifactory zero-day (CVE-2026-65618/65923/66018 SSRF) to escape a sealed AI sandbox and reach Hugging Face.

Critical

TeamCity CVE-2026-63077: Unauthenticated RCE via Auth Bypass

JetBrains TeamCity CVE-2026-63077 (CVSS 9.8) is an unauth auth-bypass RCE via deserialization in the agent polling protocol. Upgrade to 2025.11.7 or 2026.1.3.

Critical

OpenWrt CVE-2026-53921: Unauthenticated Root RCE in DHCPv6

OpenWrt CVE-2026-53921 is a CVSS 9.8 unauthenticated root RCE in the odhcpd DHCPv6 server. Affected 24.10/25.12; fix 24.10.8/25.12.5. Public PoC exists.

High

n8n Sandbox Escape CVE-2026-27577 Runs OS Commands

n8n CVE-2026-27577 (CVSS 9.4) is a sandbox escape letting an authenticated workflow editor run OS commands on a platform holding all your credentials. Patch now.

High

Certighost CVE-2026-54121: AD CS Flaw Hijacks Domains

A public PoC for Certighost (CVE-2026-54121) lets a low-priv AD user abuse AD CS to impersonate a domain controller and take over the domain. The next PetitPotam.

Critical

vBulletin Pre-Auth RCE Public Exploit: CVE-2025-48827

A public exploit is out for vBulletin pre-auth RCE CVE-2025-48827 / CVE-2025-48828, reaching PHP eval() unauthenticated. EPSS is 99th percentile - patch now.

Critical

Arista VeloCloud CVE-2026-16812 Exploited (CVSS 10.0)

Arista VeloCloud CVE-2026-16812 (CVSS 10.0) is an exploited on-prem VCO command-injection zero-day in CISA KEV. Affected versions, fixes, and IoCs.

High

ChatGPT AgentForger: One Link Deploys Rogue AI Agents

ChatGPT AgentForger let one phishing link stealthily deploy rogue workspace agents with access to a victim's connected tools. No malware, no CVE.

High

GitLab 18.11.3 RCE PoC Runs Commands as git, No CVE

A public PoC gives authenticated users RCE as git on self-managed GitLab 18.11.3. GitLab patched it June 10 but not as a security fix - many stay exposed.

Critical

Fastjson 1.x RCE CVE-2026-16723 Exploited, No Patch

CVE-2026-16723 is a CVSS 9.0 RCE in Fastjson 1.2.68-1.2.83 that works under stock default config. It is under active attack and the 1.x branch has no patch.

Critical

Cl0p Exploits PTC Windchill CVE-2026-12569 (CVSS 9.3)

Cl0p ransomware affiliates are exploiting CVE-2026-12569, a CVSS 9.3 unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM. It is now in CISA KEV.

Notable

Azure DevOps MCP Flaw: Hidden PR Comments Hijack AI Agents

A flaw in Microsoft's Azure DevOps MCP server lets an invisible HTML comment in a pull request hijack a reviewer's AI agent. No fix in v2.8.0 — how to defend.

High

Windmill CVE-2026-29059: Unauth File Read Now Exploited

Windmill CVE-2026-29059 is an unauthenticated path-traversal file read, actively exploited per VulnCheck (~170 exposed systems). Update to Windmill 1.603.3 now.

High

Ubuntu snap-confine CVE-2026-8933: Local Root on Desktop

Ubuntu snap-confine flaw CVE-2026-8933 (CVSS 7.8) lets a local user win a race condition to gain root on default 24.04/25.10/26.04 desktops. Patch snapd now.

High

Adobe Acrobat Extension CVE-2026-48294 Leaks WhatsApp Web

Adobe Acrobat Chrome extension flaw CVE-2026-48294 (CVSS 7.4) let malicious sites read WhatsApp Web chats from 314M users. Update past 26.5.2.2 now.

High

7-Zip CVE-2026-14266: Opening One XZ Archive Can Run Code

7-Zip CVE-2026-14266 is a heap overflow in the XZ decoder — opening a crafted .xz archive can run code. Affected back to 21.07, fixed in 26.02. Update now.

High

AI Coding Agent Sandbox Escapes Hit Cursor, Codex

AI coding agent sandbox escapes in Cursor, Codex, Gemini CLI and Antigravity let the agent write files trusted host tools then run (CVE-2026-48124). Patch now.

Critical

SharePoint CVE-2026-50522: Public PoC, Active RCE

SharePoint CVE-2026-50522 (CVSS 9.8) is under active RCE exploitation after a public PoC, EPSS now 99.5th percentile. Affected versions and fixes.

Critical

Qilin Ransomware Exploits PAN-OS CVE-2026-0257

Qilin ransomware is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 (EPSS 99.7th percentile, in CISA KEV) for initial access. Patch and audit now.

High

Chrome 150 Update Patches 7 Memory-Safety Bugs

The Chrome 150 update patches 7 memory-safety bugs — 3 critical use-after-free flaws in GPU, Network, and CameraCapture. Update to 150.0.7871.128 now.

Critical

WordPress wp2shell RCE (CVE-2026-63030): Public Exploits, Patch Now

WordPress Core wp2shell RCE chains CVE-2026-63030 and CVE-2026-60137 for unauthenticated remote code execution. Public exploits are out and exploitation has begun.

Critical

ServiceNow CVE-2026-6875: Critical RCE Now Exploited in the Wild

ServiceNow CVE-2026-6875 is a critical (CVSS 9.5) unauthenticated RCE in the ServiceNow AI Platform, now exploited in the wild. Affected versions, patches, and what to do now.

High

Hugging Face Breach: Autonomous AI Agent Hacked the Repo

The Hugging Face breach was carried out by an autonomous AI agent that escaped a dataset sandbox and stole cloud credentials. What happened and what to do now.

High

Agent Data Injection: Planted Content Hijacks AI Agents

Agent data injection: one planted product review or fake GitHub comment can make an AI agent misclick or run an attacker command. No CVE, no malware needed.

High

Coca-Cola Halts US Fairlife Production After Ransomware

Coca-Cola suspended US Fairlife production after a ransomware attack. It says product quality and safety are unaffected and Canadian production continues.

Critical

Fortinet FortiSandbox CVE-2026-39808 Exploited in the Wild

Fortinet FortiSandbox CVE-2026-39808 and CVE-2026-25089 (both CVSS 9.8) are in CISA KEV and actively exploited. EPSS puts one at the 98.7th percentile.

Critical

Oracle E-Business Suite CVE-2026-46817 Under Active Attack

CVE-2026-46817, a CVSS 9.8 Oracle E-Business Suite flaw, is actively exploited and in CISA KEV with a July 18 deadline. Affects EBS 12.2.3-12.2.15.

High

UEFI Secure Boot Bypass: 11 Signed Shims (CVE-2026-8863)

CVE-2026-8863: 11 old Microsoft-signed UEFI shims allow a Secure Boot bypass and pre-OS bootkits. Microsoft revoked them via a June 2026 DBX update. How to fix.

Notable

Google Gemini CLI Weaponized as a Hacking Agent

A threat actor abused Google Gemini CLI as an autonomous hacking agent, running a botnet across 200+ AI sessions. How defenders detect agentic AI abuse.

Critical

F5 NGINX CVE-2026-42533: Unauthenticated Heap Overflow

F5 NGINX CVE-2026-42533 is a CVSS 9.2 unauthenticated heap overflow in NGINX Plus and Open Source. Affected versions, config audit, and how to patch.

Critical

Zoom Account Takeover Flaw CVE-2026-53412 (CVSS 9.8)

Zoom's CVE-2026-53412 is a CVSS 9.8 unauthenticated account takeover flaw in its Windows Desktop, VDI, and Meeting SDK clients. Who's affected and how to fix.

Critical

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Can Expose or Alter Business Data

SAP's July updates fix a near-max CVSS 9.9 out-of-bounds write in NetWeaver Application Server ABAP (CVE-2026-44747) that an authenticated attacker can use to read, modify, or disrupt data on the ERP system of record.

High

Unpatched Claude for Chrome Flaw Lets Any Extension Read Your Gmail and Calendar

Researchers say a still-open flaw in Claude for Chrome (v1.0.80) lets any other browser extension that can run a script on claude.ai drive the AI agent into reading a victim's Gmail, Google Docs, and Calendar — no malware or CVE required.

Critical

Microsoft Ships a Record 622-CVE Patch Tuesday With Two Zero-Days Already Exploited

Microsoft's largest-ever Patch Tuesday closes 622 CVEs, including two elevation-of-privilege zero-days under active attack — CVE-2026-56164 in on-prem SharePoint and CVE-2026-56155 in ADFS. Prioritize the two live bugs first.

Critical

SonicWall SMA 1000 Zero-Days Exploited — One Scores a Perfect 10.0

SonicWall confirmed two zero-days in its SMA 1000 remote-access appliances are under active attack — a CVSS 10.0 unauthenticated SSRF and a post-auth flaw that runs OS commands as administrator. Patch now.

Notable

CISA Left Its Own Keys in a Public GitHub Repo, and Wrote Up Why

A contractor pushed dozens of internal CISA credentials, including AWS GovCloud keys, to a public GitHub repository. The agency's own postmortem is a clean lesson in the most common way secrets leak.

Notable

A Fake Apple Crash Reporter Is Stealing Mac Keychains, and It Passed Apple's Own Checks

A new macOS infostealer called CrashStealer disguises itself as Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets, using a notarized dropper that slips past Gatekeeper. The Mac-is-safe assumption keeps eroding.

High

A Browser Extension 1.6 Million People Trusted Was Quietly Logging Their Browsing

Google and Microsoft pulled ModHeader, a popular developer extension with about 1.6 million installs, after researchers found a hidden browsing-history collector in the official store version. The tools closest to your browser see the most.

High

One Email Can Plant a False Memory in Your AI Assistant, and It Will Not Forget

Researchers showed that a single email can trick an AI assistant with memory and inbox access into saving a false fact about you, hiding the change, and acting on it long after. Persistent memory turns a one-time injection into a lasting one.

Notable

An Attacker Left a Directory Listing On, and Exposed Three M365 Phishing Operations

A Microsoft 365 phishing crew running Evilginx left a Python web server exposed with directory listing enabled, handing researchers a look inside three live operations. The tools that beat multi-factor authentication are getting easier to run, and easier to fumble.

High

A Lab That Handles Test Results Just Lost the Data of 540,000 People

Centers Laboratory has disclosed a breach affecting 540,000 individuals, with the WorldLeaks extortion group claiming to have stolen 720 gigabytes of data. Healthcare records are among the most sensitive and the most valuable to steal.

High

The US and Eight Allies Warn That Russia Is Using Routers to Reach Critical Infrastructure

A joint advisory from the United States and eight allied countries warns that Russian state hackers are targeting poorly configured and unpatched routers to break into critical infrastructure networks. The doorway, again, is the edge device nobody watches.

Critical

Two Joomla Add-Ons Are Being Exploited to Run Code, and CISA Just Flagged Both

CISA has added two maximum-severity flaws in the iCagenda and Balbooa Forms extensions for Joomla to its Known Exploited Vulnerabilities catalog, after reports they were exploited as zero-days for remote code execution. The weak point is the plugin, not the platform.

Notable

Australia Warns of a Global Campaign Hunting Vulnerable CMS Sites

The Australian Cyber Security Centre has warned of a global campaign exploiting vulnerable content management systems and their plugins. Unpatched CMS installs remain one of the easiest ways onto the web.

Notable

Dormant GitHub Accounts Are Quietly Mapping Companies From Inside the API

Datadog researchers describe overlapping campaigns using ghost accounts to enumerate corporate GitHub organizations, their repositories, and their members through the API. Reconnaissance rarely trips an alarm, which is the point.

Notable

A Laser Pulse Can Reset a Tangem Wallet Card's Password, and the Card Cannot Be Fixed

Ledger's Donjon researchers showed that a precisely timed laser aimed at the chip in a Tangem crypto wallet card can reset its password to anything the attacker chooses. The flaw is in silicon that cannot be patched.

Notable

Six New Bootloader Flaws Reach the Code That Runs Before Everything Else

Researchers found six flaws in U-Boot, the bootloader that starts hardware from home routers to data-center servers. A malicious image could crash a device or run code at boot, below the protections that come online later.

High

A Crafted Email Is Enough to Run Code in Zimbra Users' Sessions

Zimbra is urging customers to patch a critical flaw in its Classic Web Client, a stored cross-site scripting bug that lets a crafted email execute code in a victim's session. Webmail has a long history of being hit fast.

High

Installing One Popular npm Package Was Enough to Run an Infostealer

The jscrambler npm package was compromised so that simply installing its 8.14.0 release ran a Rust infostealer, through a preinstall hook. It is the exact attack npm just changed its defaults to stop.

High

Progress Tells ShareFile Customers to Pull the Plug Over a Credible Threat

Progress Software is urging ShareFile customers to immediately shut down the on-premises servers running Storage Zone Controllers, citing a credible external security threat. A shutdown advisory is rare, and Progress has been here before.

High

A PNG in Your Repo Can Whisper to the AI and Walk Out With Your Secrets

Researchers hid a prompt injection inside an image and used it to steal a repository's secrets. The technique, called Ghostcommit, slipped past AI code reviewers that never open image files, then talked a coding agent into doing the work.

Notable

Microsoft Says to Expect More Windows Patches as AI Starts Finding the Bugs

Microsoft expects more Windows security updates ahead, not because the code got worse, but because it is using AI to find flaws it would otherwise have missed. More patches can mean a safer product, if you can keep up with them.

Notable

GigaWiper Bundles Three Old Destructive Tools Into One Windows Backdoor

Microsoft has taken apart a destructive Windows backdoor called GigaWiper that stitches disk wiping, fake ransomware, and spyware into operator-selectable commands. It is a reminder that destruction, not a payout, is sometimes the actual goal.

Notable

npm Finally Turns Off the Feature Attackers Loved Most

npm version 12 disables install scripts by default, closing one of the most abused paths in software supply chain attacks, and deprecates access tokens that sidestepped two-factor authentication. It is overdue, and it will break a few workflows.

High

When Your AI Assistant Invents a Package Name, Someone Is Already Waiting There

Researchers showed that attackers can weaponize the fake package and command names AI assistants hallucinate, registering them in advance so that following the assistant's confident but wrong suggestion installs malware. They chained it all the way to remote code execution.

Critical

Tenda Router Backdoor CVE-2026-11405: Unauth Admin Access

Tenda firmware backdoor CVE-2026-11405 (CVSS 9.8) grants unauthenticated admin access via a hidden path in /bin/httpd. No fix yet — how to protect your router.

High

Nearly 7 Million Drivers Exposed in the AssuranceAmerica Breach

AssuranceAmerica, a US auto insurer, has disclosed a breach affecting close to 6.9 million drivers after attackers reached its systems earlier this year. Insurance records are a quiet goldmine for fraud and identity theft.

High

When the Security Tool Itself Is the Zero-Day: Microsoft Patches Defender's RoguePlanet

Microsoft has shipped a patch for a zero-day in Microsoft Defender, dubbed RoguePlanet, disclosed shortly after June's Patch Tuesday. A flaw in the endpoint tool millions rely on is a reminder that defenses are attack surface too.

High

A Poisoned Repo Can Turn Popular AI Coding Assistants Into a Backdoor

Researchers found that six widely used AI coding assistants can be tricked by a booby-trapped repository into running an attacker's code on the developer's machine, using a decades-old symlink trick against the tool's own permission prompt.

Notable

A Public GitHub Issue Can Quietly Pull Data From Your Private Repositories

Researchers showed that a normal-looking issue on a public repository can trick GitHub's agentic workflows into leaking the contents of an organization's private repos. As AI agents move into the build pipeline, their inputs become a new place to attack.

High

GhostLock (CVE-2026-43499): Linux Root Flaw, Distro Patches

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel flaw giving any local user root and container escape, with a public exploit. Which distros are patched.

Critical

Gitea CVE-2026-20896: Header Auth Bypass Hits Private Repos

Gitea CVE-2026-20896 (CVSS 9.8) lets attackers spoof the X-WEBAUTH-USER header to bypass auth and read private repos. Affected versions, the fix, and FAQ.

Critical

The Gear Quietly Running Small Networks Everywhere Just Got a Critical Patch

Ubiquiti shipped fixes for seven critical UniFi OS flaws, including a maximum-severity command-injection bug. On hardware that sits at the edge of countless small business and home networks, a foothold there is a foothold into everything behind it.

High

A 16-Year-Old Flaw Lets a Virtual Machine Break Out and Seize Its Host

A use-after-free flaw hidden in Linux's KVM hypervisor for 16 years, named Januscape (CVE-2026-53359), lets a guest VM corrupt the host kernel and escape to the machine underneath. In multi-tenant cloud, that breaks the core isolation promise.

Notable

The Scanners Guarding AI Coding Agents Are Easier to Fool Than You'd Hope

Researchers at HKUST showed that malicious add-on 'skills' for AI coding agents can slip past static scanners with a simple packing trick while staying fully functional. The plugin economy for AI agents has the same trust-by-default problem as npm and browser extensions.

Critical

The Tool That Controls Access to Everything Just Had an Auth Bypass

BeyondTrust patched two critical auth-bypass flaws in its Remote Support and Privileged Remote Access products that let unauthenticated attackers take over installations. When the tool that controls access can itself be bypassed, it becomes a skeleton key.

High

Hidden Website Text Is Now Tricking AI Agents Into Paying Out Crypto

Researchers found two campaigns hiding prompt injections in malicious websites to hijack autonomous AI agents into making crypto payments the user never authorized. Agentic AI's core feature, acting on what it reads, is exactly what the attackers abuse.

Notable

A New Linux and Android Flaw Hands Any User Full Control

A new Linux kernel vulnerability called Bad Epoll (CVE-2026-46242) lets an unprivileged local user take full root control. It affects Linux desktops, servers, and Android. A fix is available.

High

North Korea Hid Malware in 108 Developer Packages to Steal Company Secrets

North Korea-linked actors flooded npm, Packagist, Go, and Chrome with 108 malicious packages (PolinRider), impersonating real tools to steal developer secrets and crypto. The delivery is the real story: fake job interviews, blockchain dead-drops, and IDE task files that run the moment you open a repo in VS Code or Cursor.

High

Millions of Cameras, Drones and Controllers Ship With Flaws That May Never Be Patched

runZero disclosed seven vulnerabilities in FatFs, the FAT/exFAT filesystem library baked into firmware across cameras, drones, industrial controllers, and security appliances. Several remain unpatched, because the code sits deep in devices that rarely get updated.

High

Unpatched Argo CD Flaw Could Let Attackers Take Over Kubernetes Clusters (No Fix Yet)

Synacktiv found an unauthenticated code-execution flaw in Argo CD's repo-server that can lead to full Kubernetes cluster takeover. There is no patch and no CVE assigned yet, so mitigation is on you until Argo ships a fix.

Notable

ConsentFix and ClickFix: Microsoft 365 Accounts Hijacked in Seconds via OAuth Abuse

New ConsentFix and ClickFix attacks steal Microsoft 365 session tokens in seconds using fake prompts and malicious OAuth consent flows, bypassing MFA entirely because they steal the token issued after login.

Critical

Adobe Patches 7 Maximum-Severity (CVSS 10.0) Flaws in ColdFusion and Campaign Classic

Adobe shipped fixes for seven CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic, enabling arbitrary code execution, privilege escalation, and file reads. ColdFusion has a long history of rapid post-patch exploitation, so the clock starts now.

High

Medtronic Breach Hits 3.8 Million People After ShinyHunters Intrusion

Medical device maker Medtronic is notifying 3.8 million people that ShinyHunters accessed its corporate IT in April and stole personal and medical data. A reminder that healthcare breaches are a compliance and risk event, not just an IT one.

High

Cisco Confirms Active Exploitation of Unified Communications Manager Flaw

Cisco confirmed attackers are exploiting a vulnerability in Unified Communications Manager. A public PoC has existed since disclosure, and the first exploitation attempts appeared within a week, another disclosure-to-attack gap measured in days.

Critical

An AI Agent Ran a Full Ransomware Attack on Its Own. The Details Are Stranger Than the Headline.

Sysdig documented JADEPUFFER, an attack it calls the first run end-to-end by an AI agent, entering through a year-old Langflow flaw. The capability is real. But two odd details, an untraceable ransom email and an encryption key that was never saved, suggest the story is messier than the headline, and we have seen premature 'first AI ransomware' claims before.

Critical

DuneSlide CVE-2026-50548: Cursor AI Editor Sandbox Escape

DuneSlide (CVE-2026-50548, CVSS 9.3) lets a crafted prompt escape the Cursor AI editor sandbox and run OS commands. Fixed in Cursor 3.0 — what to do now.

Critical

FortiBleed: Credentials From Hundreds of Thousands of FortiGate Firewalls Now Fueling INC and Lynx Ransomware

Researchers link the FortiBleed credential-theft campaign to active ransomware operations: credentials harvested from hundreds of thousands of FortiGate firewalls are being used by the INC and Lynx ransomware groups for initial access.

Critical

Citrix Bleed 2 Exploited Within Hours of Disclosure - Now Feeding Ransomware Operations

A new CitrixBleed vulnerability in NetScaler appliances was exploited immediately after public disclosure using public PoC code, and Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) for initial access. If you run NetScaler, assume you are being scanned right now.

Critical

SharePoint RCE CVE-2026-45659 Is Being Actively Exploited - CISA Says Patch Now

CISA added CVE-2026-45659, a remote code execution flaw in Microsoft SharePoint Server (CVSS 8.8), to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. If you run on-prem SharePoint, this is now a patch-today situation.