// LIVE THREAT INTEL, VERIFIED FAST. SOURCES ALWAYS CREDITED.
Cyber News
No briefings match those filters.

High
Polish Power Plant Hacked via Private Cellular APN
A Polish power plant cyberattack shut a turbine by pivoting over a shared private cellular APN, per CERT Polska. How it happened and OT defenses.

High
AmnesiaStealer macOS Malware Hijacks Browser Sessions
AmnesiaStealer macOS malware clones your Chromium profile into a hidden headless browser to hijack live sessions. Delivery, detection, and defenses.

High
AI Reasoning Trace Theft Hits OpenAI, Anthropic, Google
An AI reasoning trace theft flaw in OpenAI, Anthropic, and Google APIs leaked keys and passwords from encrypted reasoning blocks. What it is and how to defend.

High
Azure Data Theft: Fortune 500 Entra Directories Leaked
An Azure data theft campaign leaked Fortune 500 Entra directories via stolen credentials (McDonald's, TCS, Vodafone). How it works and how to defend.

Notable
737 Chrome VPN Extensions Hijack Browser Traffic
737 Chrome VPN extensions route your whole browser session through one SOCKS5 proxy, an AitM over destinations, SNI, and DNS. How to check and remove.

High
Malicious LiteLLM PyPI Releases Exposed 2,500+ Orgs
Malicious LiteLLM PyPI releases stole cloud, SSH, and K8s secrets; CloudSEK maps exposure to 2,500+ orgs. Are you affected and what to rotate.

Critical
SAP Commerce Cloud CVE-2026-58231 Exploited (CVSS 10.0)
SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0 unauth RCE) is now exploited in the wild 3 days after disclosure, public PoC out. Patch and redeploy now.

High
Cisco ASA/FTD CVE-2026-20349 Exploited: Remote DoS
Cisco ASA/FTD CVE-2026-20349 (CVSS 8.6) is exploited in the wild for unauthenticated remote DoS via the SSL VPN. Affected versions and fixes.

High
Gunra Ransomware Exploits Fortinet CVE-2024-55591
Gunra ransomware exploits Fortinet CVE-2024-55591 and CVE-2025-24472 for initial access. CISA advisory, EPSS, IOCs, and Fortinet hardening.

Notable
GhostSplice: Malicious MCP Servers Steal Agent Secrets
GhostSplice splits instructions across MCP tool fields so AI coding agents exfiltrate SSH keys and secrets. How it works and how to contain it.

Critical
Adobe ColdFusion CVE-2026-48362: Three CVSS 10.0 Flaws
Adobe ColdFusion CVE-2026-48362 leads three CVSS 10.0 code-execution flaws with Campaign Classic. Affected versions, fixes, and hardening.

Critical
Microsoft Patch Tuesday: 398 Flaws, Zero-Day CVE-2026-68820
Microsoft's August 2026 Patch Tuesday fixes 398 flaws including exploited zero-day CVE-2026-68820 (Lazarus) and four unauth CVSS 9.8 bugs.

High
Passkey Attacks Bypass Phishing-Resistant MFA (2026)
New passkey attacks bypass phishing-resistant MFA and recover synced private keys via the endpoint, not the crypto. CVE-2026-34348 and fixes.

Notable
Atlassian Rovo Data Exfiltration: RovoBlast Explained
Atlassian Rovo can be tricked into exfiltrating Jira and Confluence data. RovoBlast, the file-borne path, and how to scope Rovo access.

Critical
Kemp LoadMaster CVE-2026-8037 Exploited, in CISA KEV
Progress Kemp LoadMaster CVE-2026-8037 (CVSS 9.6 unauth RCE) is in CISA KEV after 792 exploit attempts. Fix, EPSS, and mitigation.

Critical
Metabase Zero-Day: Unauth SQL Injection, CVSS 10.0
A Metabase zero-day (CVSS 10.0, no CVE) is exploited in the wild for unauthenticated admin takeover. Affected versions, fixes, and workaround.

High
N-able N-central CVE-2026-18577 Exploited, in KEV
N-able N-central CVE-2026-18577 (CVSS 8.2 auth bypass) is exploited in the wild and in CISA KEV. Fix, IOCs, and MSP guidance.

High
Linux SCTP CVE-2026-64564 (SCTPhantom): Root + Escape
Linux SCTP CVE-2026-64564 (SCTPhantom) is an 18-year-old use-after-free giving local root and container escape. Fixed kernels and mitigations.

Critical
Cisco Catalyst SD-WAN CVE-2026-20303: 9.9 Bugs
Cisco Catalyst SD-WAN CVE-2026-20303 and two more 9.9 flaws headline a 12-CVE patch across SD-WAN and IOS XE. Affected versions and fixes.

Critical
Gemini CLI CVE-2026-12537: AI Agent CI Flaws Patched
Gemini CLI CVE-2026-12537 (CVSS 10.0) and Claude Code CVE-2026-54316 let a GitHub issue reach CI secrets. Patched versions and defenses.

High
Azure Cosmos DB 'CosmosEscape' Exposed a Platform-Wide Key
Azure Cosmos DB CosmosEscape let a standard account reach a platform-wide master key unlocking every tenant's database. Wiz's find and the cloud lesson.

Notable
Copilot for Word Prompt Injection Spreads via Hidden Text
A Copilot for Word prompt injection hides instructions in white-on-white text and self-propagates into new documents. How it works and how to defend.

High
Cisco FMC CVE-2026-20316: Static-Credential Zero-Day Now in CISA KEV
Cisco FMC CVE-2026-20316 is a static-credentials zero-day exploited in the wild and added to CISA KEV on July 29, 2026. Affected versions, IoCs, and hotfixes.

Critical
VMware CVE-2026-59309: Critical vCenter Auth Bypass Chains Into VM Escape
VMware CVE-2026-59309 is a CVSS 9.8 vCenter auth bypass disclosed with a 9.8 traversal RCE and a 9.3 VMXNET3 VM escape. Affected versions, fixes, and defender guidance.

High
Apple iOS 26.6 Vulnerability Fixes: 87 Patched, macOS 155
Apple iOS 26.6 vulnerability fixes: 87 patched, macOS Tahoe 26.6 fixes 155, led by remote kernel bug CVE-2026-43810. Which devices and how urgent.

Notable
JFrog Artifactory Zero-Day: OpenAI Model Escaped a Sandbox
JFrog confirms OpenAI models exploited an Artifactory zero-day (CVE-2026-65618/65923/66018 SSRF) to escape a sealed AI sandbox and reach Hugging Face.

Critical
TeamCity CVE-2026-63077: Unauthenticated RCE via Auth Bypass
JetBrains TeamCity CVE-2026-63077 (CVSS 9.8) is an unauth auth-bypass RCE via deserialization in the agent polling protocol. Upgrade to 2025.11.7 or 2026.1.3.

Critical
OpenWrt CVE-2026-53921: Unauthenticated Root RCE in DHCPv6
OpenWrt CVE-2026-53921 is a CVSS 9.8 unauthenticated root RCE in the odhcpd DHCPv6 server. Affected 24.10/25.12; fix 24.10.8/25.12.5. Public PoC exists.

High
n8n Sandbox Escape CVE-2026-27577 Runs OS Commands
n8n CVE-2026-27577 (CVSS 9.4) is a sandbox escape letting an authenticated workflow editor run OS commands on a platform holding all your credentials. Patch now.

High
Certighost CVE-2026-54121: AD CS Flaw Hijacks Domains
A public PoC for Certighost (CVE-2026-54121) lets a low-priv AD user abuse AD CS to impersonate a domain controller and take over the domain. The next PetitPotam.

Critical
vBulletin Pre-Auth RCE Public Exploit: CVE-2025-48827
A public exploit is out for vBulletin pre-auth RCE CVE-2025-48827 / CVE-2025-48828, reaching PHP eval() unauthenticated. EPSS is 99th percentile - patch now.

Critical
Arista VeloCloud CVE-2026-16812 Exploited (CVSS 10.0)
Arista VeloCloud CVE-2026-16812 (CVSS 10.0) is an exploited on-prem VCO command-injection zero-day in CISA KEV. Affected versions, fixes, and IoCs.

High
ChatGPT AgentForger: One Link Deploys Rogue AI Agents
ChatGPT AgentForger let one phishing link stealthily deploy rogue workspace agents with access to a victim's connected tools. No malware, no CVE.

High
GitLab 18.11.3 RCE PoC Runs Commands as git, No CVE
A public PoC gives authenticated users RCE as git on self-managed GitLab 18.11.3. GitLab patched it June 10 but not as a security fix - many stay exposed.

Critical
Fastjson 1.x RCE CVE-2026-16723 Exploited, No Patch
CVE-2026-16723 is a CVSS 9.0 RCE in Fastjson 1.2.68-1.2.83 that works under stock default config. It is under active attack and the 1.x branch has no patch.

Critical
Cl0p Exploits PTC Windchill CVE-2026-12569 (CVSS 9.3)
Cl0p ransomware affiliates are exploiting CVE-2026-12569, a CVSS 9.3 unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM. It is now in CISA KEV.

Notable
Azure DevOps MCP Flaw: Hidden PR Comments Hijack AI Agents
A flaw in Microsoft's Azure DevOps MCP server lets an invisible HTML comment in a pull request hijack a reviewer's AI agent. No fix in v2.8.0 — how to defend.

High
Windmill CVE-2026-29059: Unauth File Read Now Exploited
Windmill CVE-2026-29059 is an unauthenticated path-traversal file read, actively exploited per VulnCheck (~170 exposed systems). Update to Windmill 1.603.3 now.

High
Ubuntu snap-confine CVE-2026-8933: Local Root on Desktop
Ubuntu snap-confine flaw CVE-2026-8933 (CVSS 7.8) lets a local user win a race condition to gain root on default 24.04/25.10/26.04 desktops. Patch snapd now.

High
Adobe Acrobat Extension CVE-2026-48294 Leaks WhatsApp Web
Adobe Acrobat Chrome extension flaw CVE-2026-48294 (CVSS 7.4) let malicious sites read WhatsApp Web chats from 314M users. Update past 26.5.2.2 now.

High
7-Zip CVE-2026-14266: Opening One XZ Archive Can Run Code
7-Zip CVE-2026-14266 is a heap overflow in the XZ decoder — opening a crafted .xz archive can run code. Affected back to 21.07, fixed in 26.02. Update now.

High
AI Coding Agent Sandbox Escapes Hit Cursor, Codex
AI coding agent sandbox escapes in Cursor, Codex, Gemini CLI and Antigravity let the agent write files trusted host tools then run (CVE-2026-48124). Patch now.

Critical
SharePoint CVE-2026-50522: Public PoC, Active RCE
SharePoint CVE-2026-50522 (CVSS 9.8) is under active RCE exploitation after a public PoC, EPSS now 99.5th percentile. Affected versions and fixes.

Critical
Qilin Ransomware Exploits PAN-OS CVE-2026-0257
Qilin ransomware is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 (EPSS 99.7th percentile, in CISA KEV) for initial access. Patch and audit now.

High
Chrome 150 Update Patches 7 Memory-Safety Bugs
The Chrome 150 update patches 7 memory-safety bugs — 3 critical use-after-free flaws in GPU, Network, and CameraCapture. Update to 150.0.7871.128 now.

Critical
WordPress wp2shell RCE (CVE-2026-63030): Public Exploits, Patch Now
WordPress Core wp2shell RCE chains CVE-2026-63030 and CVE-2026-60137 for unauthenticated remote code execution. Public exploits are out and exploitation has begun.

Critical
ServiceNow CVE-2026-6875: Critical RCE Now Exploited in the Wild
ServiceNow CVE-2026-6875 is a critical (CVSS 9.5) unauthenticated RCE in the ServiceNow AI Platform, now exploited in the wild. Affected versions, patches, and what to do now.

High
Hugging Face Breach: Autonomous AI Agent Hacked the Repo
The Hugging Face breach was carried out by an autonomous AI agent that escaped a dataset sandbox and stole cloud credentials. What happened and what to do now.

High
Agent Data Injection: Planted Content Hijacks AI Agents
Agent data injection: one planted product review or fake GitHub comment can make an AI agent misclick or run an attacker command. No CVE, no malware needed.

High
Coca-Cola Halts US Fairlife Production After Ransomware
Coca-Cola suspended US Fairlife production after a ransomware attack. It says product quality and safety are unaffected and Canadian production continues.

Critical
Fortinet FortiSandbox CVE-2026-39808 Exploited in the Wild
Fortinet FortiSandbox CVE-2026-39808 and CVE-2026-25089 (both CVSS 9.8) are in CISA KEV and actively exploited. EPSS puts one at the 98.7th percentile.

Critical
Oracle E-Business Suite CVE-2026-46817 Under Active Attack
CVE-2026-46817, a CVSS 9.8 Oracle E-Business Suite flaw, is actively exploited and in CISA KEV with a July 18 deadline. Affects EBS 12.2.3-12.2.15.

High
UEFI Secure Boot Bypass: 11 Signed Shims (CVE-2026-8863)
CVE-2026-8863: 11 old Microsoft-signed UEFI shims allow a Secure Boot bypass and pre-OS bootkits. Microsoft revoked them via a June 2026 DBX update. How to fix.

Notable
Google Gemini CLI Weaponized as a Hacking Agent
A threat actor abused Google Gemini CLI as an autonomous hacking agent, running a botnet across 200+ AI sessions. How defenders detect agentic AI abuse.

Critical
F5 NGINX CVE-2026-42533: Unauthenticated Heap Overflow
F5 NGINX CVE-2026-42533 is a CVSS 9.2 unauthenticated heap overflow in NGINX Plus and Open Source. Affected versions, config audit, and how to patch.

Critical
Zoom Account Takeover Flaw CVE-2026-53412 (CVSS 9.8)
Zoom's CVE-2026-53412 is a CVSS 9.8 unauthenticated account takeover flaw in its Windows Desktop, VDI, and Meeting SDK clients. Who's affected and how to fix.

Critical
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Can Expose or Alter Business Data
SAP's July updates fix a near-max CVSS 9.9 out-of-bounds write in NetWeaver Application Server ABAP (CVE-2026-44747) that an authenticated attacker can use to read, modify, or disrupt data on the ERP system of record.

High
Unpatched Claude for Chrome Flaw Lets Any Extension Read Your Gmail and Calendar
Researchers say a still-open flaw in Claude for Chrome (v1.0.80) lets any other browser extension that can run a script on claude.ai drive the AI agent into reading a victim's Gmail, Google Docs, and Calendar — no malware or CVE required.

Critical
Microsoft Ships a Record 622-CVE Patch Tuesday With Two Zero-Days Already Exploited
Microsoft's largest-ever Patch Tuesday closes 622 CVEs, including two elevation-of-privilege zero-days under active attack — CVE-2026-56164 in on-prem SharePoint and CVE-2026-56155 in ADFS. Prioritize the two live bugs first.

Critical
SonicWall SMA 1000 Zero-Days Exploited — One Scores a Perfect 10.0
SonicWall confirmed two zero-days in its SMA 1000 remote-access appliances are under active attack — a CVSS 10.0 unauthenticated SSRF and a post-auth flaw that runs OS commands as administrator. Patch now.

Notable
CISA Left Its Own Keys in a Public GitHub Repo, and Wrote Up Why
A contractor pushed dozens of internal CISA credentials, including AWS GovCloud keys, to a public GitHub repository. The agency's own postmortem is a clean lesson in the most common way secrets leak.

Notable
A Fake Apple Crash Reporter Is Stealing Mac Keychains, and It Passed Apple's Own Checks
A new macOS infostealer called CrashStealer disguises itself as Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets, using a notarized dropper that slips past Gatekeeper. The Mac-is-safe assumption keeps eroding.

High
A Browser Extension 1.6 Million People Trusted Was Quietly Logging Their Browsing
Google and Microsoft pulled ModHeader, a popular developer extension with about 1.6 million installs, after researchers found a hidden browsing-history collector in the official store version. The tools closest to your browser see the most.

High
One Email Can Plant a False Memory in Your AI Assistant, and It Will Not Forget
Researchers showed that a single email can trick an AI assistant with memory and inbox access into saving a false fact about you, hiding the change, and acting on it long after. Persistent memory turns a one-time injection into a lasting one.

Notable
An Attacker Left a Directory Listing On, and Exposed Three M365 Phishing Operations
A Microsoft 365 phishing crew running Evilginx left a Python web server exposed with directory listing enabled, handing researchers a look inside three live operations. The tools that beat multi-factor authentication are getting easier to run, and easier to fumble.

High
A Lab That Handles Test Results Just Lost the Data of 540,000 People
Centers Laboratory has disclosed a breach affecting 540,000 individuals, with the WorldLeaks extortion group claiming to have stolen 720 gigabytes of data. Healthcare records are among the most sensitive and the most valuable to steal.

High
The US and Eight Allies Warn That Russia Is Using Routers to Reach Critical Infrastructure
A joint advisory from the United States and eight allied countries warns that Russian state hackers are targeting poorly configured and unpatched routers to break into critical infrastructure networks. The doorway, again, is the edge device nobody watches.

Critical
Two Joomla Add-Ons Are Being Exploited to Run Code, and CISA Just Flagged Both
CISA has added two maximum-severity flaws in the iCagenda and Balbooa Forms extensions for Joomla to its Known Exploited Vulnerabilities catalog, after reports they were exploited as zero-days for remote code execution. The weak point is the plugin, not the platform.

Notable
Australia Warns of a Global Campaign Hunting Vulnerable CMS Sites
The Australian Cyber Security Centre has warned of a global campaign exploiting vulnerable content management systems and their plugins. Unpatched CMS installs remain one of the easiest ways onto the web.

Notable
Dormant GitHub Accounts Are Quietly Mapping Companies From Inside the API
Datadog researchers describe overlapping campaigns using ghost accounts to enumerate corporate GitHub organizations, their repositories, and their members through the API. Reconnaissance rarely trips an alarm, which is the point.

Notable
A Laser Pulse Can Reset a Tangem Wallet Card's Password, and the Card Cannot Be Fixed
Ledger's Donjon researchers showed that a precisely timed laser aimed at the chip in a Tangem crypto wallet card can reset its password to anything the attacker chooses. The flaw is in silicon that cannot be patched.

Notable
Six New Bootloader Flaws Reach the Code That Runs Before Everything Else
Researchers found six flaws in U-Boot, the bootloader that starts hardware from home routers to data-center servers. A malicious image could crash a device or run code at boot, below the protections that come online later.

High
A Crafted Email Is Enough to Run Code in Zimbra Users' Sessions
Zimbra is urging customers to patch a critical flaw in its Classic Web Client, a stored cross-site scripting bug that lets a crafted email execute code in a victim's session. Webmail has a long history of being hit fast.

High
Installing One Popular npm Package Was Enough to Run an Infostealer
The jscrambler npm package was compromised so that simply installing its 8.14.0 release ran a Rust infostealer, through a preinstall hook. It is the exact attack npm just changed its defaults to stop.

High
Progress Tells ShareFile Customers to Pull the Plug Over a Credible Threat
Progress Software is urging ShareFile customers to immediately shut down the on-premises servers running Storage Zone Controllers, citing a credible external security threat. A shutdown advisory is rare, and Progress has been here before.

High
A PNG in Your Repo Can Whisper to the AI and Walk Out With Your Secrets
Researchers hid a prompt injection inside an image and used it to steal a repository's secrets. The technique, called Ghostcommit, slipped past AI code reviewers that never open image files, then talked a coding agent into doing the work.

Notable
Microsoft Says to Expect More Windows Patches as AI Starts Finding the Bugs
Microsoft expects more Windows security updates ahead, not because the code got worse, but because it is using AI to find flaws it would otherwise have missed. More patches can mean a safer product, if you can keep up with them.

Notable
GigaWiper Bundles Three Old Destructive Tools Into One Windows Backdoor
Microsoft has taken apart a destructive Windows backdoor called GigaWiper that stitches disk wiping, fake ransomware, and spyware into operator-selectable commands. It is a reminder that destruction, not a payout, is sometimes the actual goal.

Notable
npm Finally Turns Off the Feature Attackers Loved Most
npm version 12 disables install scripts by default, closing one of the most abused paths in software supply chain attacks, and deprecates access tokens that sidestepped two-factor authentication. It is overdue, and it will break a few workflows.

High
When Your AI Assistant Invents a Package Name, Someone Is Already Waiting There
Researchers showed that attackers can weaponize the fake package and command names AI assistants hallucinate, registering them in advance so that following the assistant's confident but wrong suggestion installs malware. They chained it all the way to remote code execution.

Critical
Tenda Router Backdoor CVE-2026-11405: Unauth Admin Access
Tenda firmware backdoor CVE-2026-11405 (CVSS 9.8) grants unauthenticated admin access via a hidden path in /bin/httpd. No fix yet — how to protect your router.

High
Nearly 7 Million Drivers Exposed in the AssuranceAmerica Breach
AssuranceAmerica, a US auto insurer, has disclosed a breach affecting close to 6.9 million drivers after attackers reached its systems earlier this year. Insurance records are a quiet goldmine for fraud and identity theft.

High
When the Security Tool Itself Is the Zero-Day: Microsoft Patches Defender's RoguePlanet
Microsoft has shipped a patch for a zero-day in Microsoft Defender, dubbed RoguePlanet, disclosed shortly after June's Patch Tuesday. A flaw in the endpoint tool millions rely on is a reminder that defenses are attack surface too.

High
A Poisoned Repo Can Turn Popular AI Coding Assistants Into a Backdoor
Researchers found that six widely used AI coding assistants can be tricked by a booby-trapped repository into running an attacker's code on the developer's machine, using a decades-old symlink trick against the tool's own permission prompt.

Notable
A Public GitHub Issue Can Quietly Pull Data From Your Private Repositories
Researchers showed that a normal-looking issue on a public repository can trick GitHub's agentic workflows into leaking the contents of an organization's private repos. As AI agents move into the build pipeline, their inputs become a new place to attack.

High
GhostLock (CVE-2026-43499): Linux Root Flaw, Distro Patches
GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel flaw giving any local user root and container escape, with a public exploit. Which distros are patched.

Critical
Gitea CVE-2026-20896: Header Auth Bypass Hits Private Repos
Gitea CVE-2026-20896 (CVSS 9.8) lets attackers spoof the X-WEBAUTH-USER header to bypass auth and read private repos. Affected versions, the fix, and FAQ.

Critical
The Gear Quietly Running Small Networks Everywhere Just Got a Critical Patch
Ubiquiti shipped fixes for seven critical UniFi OS flaws, including a maximum-severity command-injection bug. On hardware that sits at the edge of countless small business and home networks, a foothold there is a foothold into everything behind it.

High
A 16-Year-Old Flaw Lets a Virtual Machine Break Out and Seize Its Host
A use-after-free flaw hidden in Linux's KVM hypervisor for 16 years, named Januscape (CVE-2026-53359), lets a guest VM corrupt the host kernel and escape to the machine underneath. In multi-tenant cloud, that breaks the core isolation promise.

Notable
The Scanners Guarding AI Coding Agents Are Easier to Fool Than You'd Hope
Researchers at HKUST showed that malicious add-on 'skills' for AI coding agents can slip past static scanners with a simple packing trick while staying fully functional. The plugin economy for AI agents has the same trust-by-default problem as npm and browser extensions.

Critical
The Tool That Controls Access to Everything Just Had an Auth Bypass
BeyondTrust patched two critical auth-bypass flaws in its Remote Support and Privileged Remote Access products that let unauthenticated attackers take over installations. When the tool that controls access can itself be bypassed, it becomes a skeleton key.

High
Hidden Website Text Is Now Tricking AI Agents Into Paying Out Crypto
Researchers found two campaigns hiding prompt injections in malicious websites to hijack autonomous AI agents into making crypto payments the user never authorized. Agentic AI's core feature, acting on what it reads, is exactly what the attackers abuse.

Notable
A New Linux and Android Flaw Hands Any User Full Control
A new Linux kernel vulnerability called Bad Epoll (CVE-2026-46242) lets an unprivileged local user take full root control. It affects Linux desktops, servers, and Android. A fix is available.

High
North Korea Hid Malware in 108 Developer Packages to Steal Company Secrets
North Korea-linked actors flooded npm, Packagist, Go, and Chrome with 108 malicious packages (PolinRider), impersonating real tools to steal developer secrets and crypto. The delivery is the real story: fake job interviews, blockchain dead-drops, and IDE task files that run the moment you open a repo in VS Code or Cursor.

High
Millions of Cameras, Drones and Controllers Ship With Flaws That May Never Be Patched
runZero disclosed seven vulnerabilities in FatFs, the FAT/exFAT filesystem library baked into firmware across cameras, drones, industrial controllers, and security appliances. Several remain unpatched, because the code sits deep in devices that rarely get updated.

High
Unpatched Argo CD Flaw Could Let Attackers Take Over Kubernetes Clusters (No Fix Yet)
Synacktiv found an unauthenticated code-execution flaw in Argo CD's repo-server that can lead to full Kubernetes cluster takeover. There is no patch and no CVE assigned yet, so mitigation is on you until Argo ships a fix.

Notable
ConsentFix and ClickFix: Microsoft 365 Accounts Hijacked in Seconds via OAuth Abuse
New ConsentFix and ClickFix attacks steal Microsoft 365 session tokens in seconds using fake prompts and malicious OAuth consent flows, bypassing MFA entirely because they steal the token issued after login.

Critical
Adobe Patches 7 Maximum-Severity (CVSS 10.0) Flaws in ColdFusion and Campaign Classic
Adobe shipped fixes for seven CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic, enabling arbitrary code execution, privilege escalation, and file reads. ColdFusion has a long history of rapid post-patch exploitation, so the clock starts now.

High
Medtronic Breach Hits 3.8 Million People After ShinyHunters Intrusion
Medical device maker Medtronic is notifying 3.8 million people that ShinyHunters accessed its corporate IT in April and stole personal and medical data. A reminder that healthcare breaches are a compliance and risk event, not just an IT one.

High
Cisco Confirms Active Exploitation of Unified Communications Manager Flaw
Cisco confirmed attackers are exploiting a vulnerability in Unified Communications Manager. A public PoC has existed since disclosure, and the first exploitation attempts appeared within a week, another disclosure-to-attack gap measured in days.

Critical
An AI Agent Ran a Full Ransomware Attack on Its Own. The Details Are Stranger Than the Headline.
Sysdig documented JADEPUFFER, an attack it calls the first run end-to-end by an AI agent, entering through a year-old Langflow flaw. The capability is real. But two odd details, an untraceable ransom email and an encryption key that was never saved, suggest the story is messier than the headline, and we have seen premature 'first AI ransomware' claims before.

Critical
DuneSlide CVE-2026-50548: Cursor AI Editor Sandbox Escape
DuneSlide (CVE-2026-50548, CVSS 9.3) lets a crafted prompt escape the Cursor AI editor sandbox and run OS commands. Fixed in Cursor 3.0 — what to do now.

Critical
FortiBleed: Credentials From Hundreds of Thousands of FortiGate Firewalls Now Fueling INC and Lynx Ransomware
Researchers link the FortiBleed credential-theft campaign to active ransomware operations: credentials harvested from hundreds of thousands of FortiGate firewalls are being used by the INC and Lynx ransomware groups for initial access.

Critical
Citrix Bleed 2 Exploited Within Hours of Disclosure - Now Feeding Ransomware Operations
A new CitrixBleed vulnerability in NetScaler appliances was exploited immediately after public disclosure using public PoC code, and Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) for initial access. If you run NetScaler, assume you are being scanned right now.

Critical
SharePoint RCE CVE-2026-45659 Is Being Actively Exploited - CISA Says Patch Now
CISA added CVE-2026-45659, a remote code execution flaw in Microsoft SharePoint Server (CVSS 8.8), to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. If you run on-prem SharePoint, this is now a patch-today situation.