threat-intel WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine A vulnerability in WinRAR, first identified in July 2025, is being exploited by Russia-aligned cyber groups to deploy malware targeting Ukrainian organizations. The attackers, including Earth Dahu and SHADOW-EARTH-066, a… The Hacker News · Jun 9, 2026 High CVE-2025-8088RUUAwinrarexploitukraine
vulnerability Google patches new Chrome zero-day flaw exploited in the wild Google has released a security update to address a newly discovered and actively exploited zero-day vulnerability (CVE-2026-11645) within the Chrome browser. This flaw, originating in the V8 JavaScript engine, allows att… BleepingComputer · Jun 9, 2026 High CVE-2026-11645CVE-2024-0519CVE-2026-2441zero-daychromev8
vulnerability One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public A critical vulnerability, CVE-2026-23111, has been discovered in the Linux kernel’s nf_tables packet-filtering code, allowing unprivileged users to escalate to root access and break out of containers. The flaw, initially… The Hacker News · Jun 8, 2026 Critical CVE-2026-23111linuxkerneluse-after-free
threat-intel From cause to cash: a cross-border look at hacktivist activity This Securelist article details a cross-border hacktivist campaign led by groups including 4BID, with a broadened geographic scope impacting organizations in Kazakhstan, the UAE, Syria, and Egypt. The campaign utilized t… Securelist · Jun 8, 2026 High CVE-2023-44976KZAESYproxyshellransomwarehacktivism
malware C0XMO botnet spreads via DD-WRT router flaw, kills rival malware A new botnet, C0XMO, leveraging a DD-WRT router vulnerability (CVE-2021-27137) is spreading across various device architectures, including routers, DVRs, and Android devices. This botnet, developed by the Gafgyt group, i… BleepingComputer · Jun 7, 2026 High CVE-2021-27137DEJPddosbotnetexploit
threat-intel Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook This article details a trend of underground forums sharing a tutorial designed to guide novice hackers through the process of identifying, exploiting, and monetizing vulnerabilities. The ‘Hercules’ thread, popular across… BleepingComputer · Jun 4, 2026 High USvulnerabilityexploitmonetization
vulnerability Cisco warns of critical Unified CM flaw with PoC exploit code Cisco has issued a critical security update addressing a vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM) software. This flaw allows attackers to gain root privileges through SSRF attacks… BleepingComputer · Jun 4, 2026 Critical CVE-2026-20230CVE-2026-20045CVE-2024-20253ssrfprivilege escalationroot access
vulnerability VS Code zero-day lets hackers steal GitHub tokens in one click A researcher, Ammar Askar, has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. The vulne… BleepingComputer · Jun 3, 2026 High zero-daygithubvscode
vulnerability CISA flags two-year-old Oracle flaw as actively exploited in attacks CISA has identified a two-year-old Oracle WebLogic Server vulnerability (CVE-2024-21182) as actively being exploited in attacks, prompting a directive for federal agencies to immediately patch their systems. The vulnerab… BleepingComputer · Jun 2, 2026 High CVE-2024-21182CVE-2025-61884CVE-2026-21992oracleweblogicvulnerability
vulnerability Microsoft Threatening Security Researcher A security researcher known as "Nightmare Eclipse" has been publicly disclosing a series of critical vulnerabilities within Microsoft Windows, including a breach of BitLocker encryption. In response, Microsoft has issued… Schneier on Security · Jun 2, 2026 High securityexploitbitlocker
vulnerability Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit A vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, tracked as CVE-2026-0257, is currently being actively exploited. Attackers are leveraging a configuration flaw to bypass authentication and gain… Dark Reading · Jun 1, 2026 Critical CVE-2026-0257CVE-2025-0108USvpnauthenticationcookie
vulnerability WP Maps Pro bug exploited to create admin accounts on WordPress sites A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been exploited by threat actors to create administrator accounts on affected websites. The flaw stems from an insecure AJAX endpoint that a… BleepingComputer · May 31, 2026 Critical CVE-2026-8732wordpresswp maps provulnerability
vulnerability Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks Palo Alto Networks is warning of an actively exploited vulnerability (CVE-2026-0257) in its GlobalProtect VPN software, allowing attackers to bypass authentication and establish unauthorized VPN connections. The flaw, in… BleepingComputer · May 30, 2026 High CVE-2026-0257USvpnauthenticationcookie
vulnerability Exploit Code Published for Critical Flowise RCE Vulnerability A critical remote code execution (RCE) vulnerability, CVE-2026-40933, has been discovered in Flowise, a popular open-source AI agent platform. The flaw, stemming from a command injection issue within the Anthropic MCP pr… SecurityWeek · May 30, 2026 Critical CVE-2026-40933rcecommand injectionai
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
threat-intel AI-Assisted Exploit Development Outpaces Scanner Detection Research from Cogent indicates that AI-assisted exploit development is dramatically accelerating, reducing exploit creation time from 125 days to just 0.5 days using large language models. This creates significant ‘visib… Dark Reading · May 27, 2026 Critical USaiexploitvulnerability
vulnerability Microsoft shares mitigation for YellowKey Windows zero-day Microsoft has released mitigation steps for a newly disclosed Windows zero-day vulnerability, dubbed YellowKey, which allows unauthorized access to BitLocker-protected drives. The vulnerability was initially revealed by… BleepingComputer · May 20, 2026 High CVE-2026-33825CVE-2026-45585zero-daybitlockerwinre
threat-intel Windows Zero-Day Barrage Continues After Patch Tuesday A security researcher known as "Nightmare Eclipse" has disclosed six Windows zero-day vulnerabilities over the past six weeks, some of which are actively being exploited. These vulnerabilities, including YellowKey, Green… Dark Reading · May 19, 2026 High CVE-2020-17103CVE-2026-33825USzero-daybitlockerprivilege escalation
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker
threat-intel CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos identified an intrusion campaign initiated in January 2026 involving the deployment of the CloudZ remote access tool (RAT) alongside a new plugin called ‘Pheno.’ This campaign leveraged the Microsoft Phone Li… Cisco Talos · May 5, 2026 High USotpphone linkcredential theft