Critical vulnerabilities, active threats, and security news — curated for professionals.
Critical path traversal vulnerability via organization names allowing arbitrary file write and Git hook overwrites, leading to complete unauthenticated Remote Code Execution (RCE).
SourceCritical prototype pollution flaw in XML and GSuiteAdmin nodes that allows authenticated workflow creators to achieve full remote code execution under the n8n process user.
SourceAuthentication bypass vulnerability in the administrative web interface actively weaponized in recent critical infrastructure attacks by Gunra ransomware operators.
SourceCritical remote code execution and administrative bypass flaw actively exploited in chained attacks against global enterprise edge devices.
SourceMulti-stage ransomware operation actively exploiting perimeter network flaws (including Fortinet FortiOS/FortiProxy) to breach networks, exfiltrate data, and deploy ransomware.
SourceCompromised maintainer account injected malicious typosquatted build scripts into popular Rust crates (arrayref, internment, append-only-vec) to execute remote code during project compilation.
SourceThe Rust Project rapidly purged poisoned releases of popular crates (arrayref, internment, append-only-vec) after compromised accounts injected build-script payloads executing remote code upon compilation.
Read moreU.S. and international intelligence agencies issued an active threat advisory regarding threat actors using AI-generated exploit scripts targeting Siemens S7 and industrial programmable logic controllers.
Read moreCyber espionage groups (UNC6293, UNC7005, UNC5976) are abusing legitimate authentication flows and QR-code device linking to hijack accounts across defense, government, and think tanks.
Read moreCritical directory traversal flaw leading to unauthenticated RCE. Actively exploited in the wild to establish reverse SSH backdoors and deploy Babuk ransomware.
SourceCritical unauthenticated RCE in CI/CD build environments. Listed on CISA KEV with active exploitation observed across enterprise targets.
SourceZero-day privilege escalation vulnerability ('ShieldBreak') bypassing prior RoguePlanet protections. Listed on CISA KEV.
SourceCritical unauthenticated remote code execution (RCE) flaw allowing full appliance compromise across perimeter network appliances.
SourceThreat actors are actively leveraging CVE-2026-59310 to install persistent reverse SSH tunnels, followed by the deployment of Babuk-derived ransomware.
SourceThreat actors are actively weaponizing CVE-2026-59310 to compromise VMware vCenter instances, dropping reverse SSH implants and Babuk-variant ransomware.
Read moreCISA has updated its Known Exploited Vulnerabilities catalog with actively targeted flaws in Microsoft Windows Defender and JetBrains TeamCity.
Read moreCritical unauthenticated RCE. Added to CISA KEV Aug 5, 2026; attackers actively targeting build servers. Patch immediately.
SourceRCE actively exploited to deploy a reverse SSH tool for persistence and remote access.
SourceZero-day; public PoC (ShieldBreak) claims Microsoft failed to fully patch prior RoguePlanet flaw CVE-2026-50656. Added to CISA KEV; federal agencies required to patch by Aug 25, 2026.
SourceActive exploitation of VMware vCenter RCE to deploy reverse-SSH backdoors for persistence and remote access.
Source400 flaws fixed, including 1 actively exploited and 2 publicly disclosed zero-days.
Read morePublic PoC (ShieldBreak) released claiming Microsoft failed to fully patch CVE-2026-50656; tested on Windows 11 25H2 and Server 2025.
Read moreMaximum-severity flaw (insufficient authorization checks/input validation) allowing unauthenticated attackers to abuse a default authentication client and execute crafted requests. Actively exploited in the wild within days of the patch.
SourceDirectory-traversal vulnerability in vCenter Server enabling arbitrary code execution. Patched July 29, 2026 but now exploited by a suspected China-nexus APT to drop Babuk-derived ransomware on exposed instances.
SourceArbitrary code execution in the Whirlpool hash implementation: it loads native .so modules using broad glob patterns and no integrity verification, allowing attackers to plant malicious libraries in site-packages for native code execution.
SourceArbitrary file upload via handle_file_upload; insufficient file-type validation lets unauthenticated attackers bypass the dangerous-extension blocklist and upload malicious PHP leading to RCE. Actively exploited.
SourceNew Mirai-derived Linux botnet that turns exposed devices into SOCKS5 proxies. Reuses Mirai DDoS engine and adds encrypted C2, SSH brute-force scanner, SOCKS relay, and credential sniffer; exploits known router/VPN flaws.
SourceCommand-and-control framework that blends into legitimate traffic using DNS tunneling and Google Apps Script, evading network detection.
SourceSuspected China-nexus actor exploits CVE-2026-59310 in vCenter to deploy Babuk-derived ransomware on internet-exposed instances.
SourceCVE-2026-58231 (CVSS 10.0) is under active exploitation; unauthenticated attackers abuse a default auth client. Patch immediately.
Read moreWiz disclosed a GhA workflow injection in snowflakedb/snowflake-connector-net where crafted issues could expose internal Jira credentials to executed commands.
Read moreResearch shows how misconfigured Model Context Protocol servers expose internal secrets to AI agents — a growing enterprise supply-chain risk.
Read moreUse-after-free in the Windows AFD for WinSock lets an authenticated local attacker elevate privileges to SYSTEM. Actively exploited in the wild as a zero-day; Lazarus Group deployed the 'Troy' backdoor against defense and aerospace firms using it. Patch immediately.
SourceWeak authentication (CWE-1390) allows an unauthenticated remote attacker to bypass a security feature over the network and potentially gain control of sensitive enterprise data. Reported under active exploitation; apply Patch Tuesday update.
SourceWormable remote code execution flaw in Windows DNS Server with a CVSS score of 9.8. No authentication required to exploit; highest priority patching due to wormable, network-propagation potential.
SourceNew NFC relay malware family. Captures live payment card data via NFC and relays it in real time to attackers, enabling contactless payment fraud combined with social engineering and remote device control via the SpyNote RAT.
SourceNorth Korean APT used the CVE-2026-68820 WinSock zero-day to gain SYSTEM access and deploy the 'Troy' backdoor against defense and aerospace organizations.
SourceActive exfiltration-based double-extortion campaigns; recently hit victims with large data thefts (e.g. 424GB) and used supply-chain/Clop-style mass exploitation, targeting file-transfer platforms.
SourceMassive monthly update addressing the exploited WinSock zero-day CVE-2026-68820, two publicly disclosed zero-days, a wormable DNS Server bug and ~60 critical flaws. Prioritize patching internet-facing servers.
Read moreResearchers linked the CVE-2026-68820 in-the-wild exploitation to Lazarus, which chain-escalates to SYSTEM to install the Troy backdoor on defense and aerospace targets.
Read moreGroup-IB uncovers an NFC relay malware combined with the SpyNote RAT that lets criminals use victims' bank cards in real time for contactless purchases and cash-out.
Read moreUnauthenticated attacker abuses a default authentication client and submits crafted input lacking validation, enabling arbitrary code execution and compromise of internal components. Patch via SAP Note 3771065.
SourceWeak-authentication security-feature bypass (CWE-1390). Unauthenticated attacker can impersonate administrators. Actively exploited in the wild within days of Rapid7 publishing a public PoC.
SourceServer-Side Request Forgery (SSRF). Exploited as a zero-day, often chained with CVE-2026-15410 (code injection) by INC ransomware actors. Patches and IOCs available; urgent patching recommended.
SourceNow the most active group exploiting SonicWall SMA1000 zero-days (CVE-2026-15409/15410), chaining the flaws to steal credentials and TOTP seeds and reach internal networks.
SourceUpdates cover roughly 400 vulnerabilities, including one actively exploited and two publicly disclosed zero-days.
Read moreSAP released 28 security notes, including fixes for CVE-2026-58231 (CVSS 10.0) and other code-injection RCE flaws in Commerce Cloud and NetWeaver.
Read moreChina's Cyberspace Administration said the review is to ensure safe operation of critical information infrastructure and prevent cybersecurity risks.
Read moreUse-after-free elevation-of-privilege flaw in Windows AFD.sys, actively exploited in the wild. A locally authenticated attacker can trigger a race condition for kernel-level access and SYSTEM privileges. Patched in August 2026 Patch Tuesday.
SourceImproper authentication allows an unauthorized attacker to elevate privileges over the network without user interaction, with high impact to confidentiality, integrity and availability. Fully mitigated by Microsoft; no user action required.
SourceCritical flaw in Cisco Catalyst SD-WAN and IOS XE discovered during internal security hardening review; allows security-control bypass and unauthorized access. One of five CVEs rated Critical 9.9. Patch immediately.
SourceNew C++ ransomware (appends .encrypted) deployed by China-linked actor Storm-1175, a former Medusa affiliate, since Aug 2 2026. Likely gained access via N-able N-central auth-bypass CVE-2026-18577.
SourceNow the most active group exploiting SonicWall SMA1000 zero-days, breaching victims across multiple regions.
Source62 of 421 vulnerabilities are marked critical. CVE-2026-68820 (Windows AFD.sys LPE) is confirmed exploited in the wild; two zero-days were publicly disclosed.
Read moreCritical vulnerabilities found via internal review can bypass security controls and enable unauthorized access; immediate patching advised.
Read moreMicrosoft Threat Intelligence tracks first activity since April 2026, marking a shift from Medusa to the new C++ ransomware family.
Read moreUse-after-free in the Windows kernel networking driver. Actively exploited zero-day (per Microsoft and Check Point, tied to Lazarus Operation Dream Job). Lets an attacker with code execution escalate to SYSTEM via a race condition.
SourceStack-based buffer overflow reachable remotely with no authentication and no user interaction. ZDI characterizes it as wormable; unauthenticated RCE on exposed DNS servers.
SourceUnauthenticated remote code execution in Microsoft's implementation of the QUIC transport protocol; no user interaction required.
SourceCode-execution half of a SharePoint exploit chain that, combined with the CVE-2026-55040 auth bypass (9.1, patched July), reaches unauthenticated RCE. Both fixes required.
SourceConti-derived RaaS. Gained initial access via Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS/FortiProxy (CVE-2025-24472). Double extortion; 51 victims since April 2025. Warnings from CISA and South Korean agencies.
SourceUses Polygon blockchain smart contracts, Session messaging and decentralized infra (per Microsoft Threat Intelligence) to harden extortion and data-leak operations against disruption.
SourceAndroid/IoT DDoS botnet now disguises HTTP/2 DDoS traffic as legitimate browsing. Discovered by Palo Alto Unit 42.
SourceCVE-2026-68820 (Windows afd.sys, CVSS 7.0) is the only flaw flagged as actively exploited (linked to Lazarus Operation Dream Job). Four unauthenticated 9.8 RCEs hit Windows DNS, Deployment Services, QUIC and HPC Pack. SharePoint chain closed with CVE-2026-63520.
Read moreAttackers shut a turbine after gaining access to a Polish power plant's OT controls through a private cellular network, underscoring ICS/cellular attack surface risks.
Read moreNew cyber-specialized model ships with fewer safeguards, raising questions around AI-assisted malware and exploit generation.
Read moreSigning key was inadvertently exposed in a private repository; certificates revoked as a precaution.
Read moreMaximum-severity server-side request forgery (SSRF) in SMA1000 VPN appliances. Exploitation traced back to June 22, 2026, three weeks before a patch existed. Pre-auth access opens unauthenticated WebSocket tunnels, escalating to root. Actively exploited by INC ransomware.
SourcePost-authentication code injection in the SMA1000 Appliance Management Console (AMC). Chained with CVE-2026-15409 to reach root-level OS access; exploited in the wild by ransomware operators.
SourceIncorrect authorization flaw (CVSS 10.0) allowing arbitrary code execution as the current user with no user interaction required and changed scope. Enterprise marketing automation platform. Patch ASAP.
SourceEmerged as the dominant actor exploiting SonicWall SMA1000 flaws, chaining CVE-2026-15409/CVE-2026-15410 (claimed 885 victims). Accelerating since early August 2026, posting multiple victims on its leak site.
SourceTenet Security researchers showed how attackers poison logs and alerts inside trusted platforms so organizations' own AI coding agents execute attacker instructions using already-granted privileges.
Read moreOpenAI said it is pausing some internal activities around its upcoming AI model Astra after an internal evaluation flagged concerning behavior.
Read moreIncludes CVE-2026-65667, a missing-authorization flaw in Microsoft Teams allowing unauthenticated privilege escalation over the network. Large CVE volume trend continues as AI finds more flaws.
Read more