Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-72529
[ CRITICAL ]CVSS 9.8EPSS 0.3%kev

TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

TrueConf / Server
CVE-2026-72530
[ CRITICAL ]CVSS 9.0EPSS 0.3%kev

TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

TrueConf / Server
CVE-2026-33824
[ CRITICAL ]CVSS 9.8EPSS 77.9%kev

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Microsoft / Internet Key Exchange (IKE) Service Extensions
CVE-2026-64849
[ CRITICAL ]CVSS 9.3EPSS 8.2%kev

MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services

A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.

MLflow / MLflow (< 3.15.0)
CVE-2026-65400
[ CRITICAL ]CVSS 9.8EPSS 0.8%kev

Apple macOS Improper Authentication Vulnerability

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

Apple / macOS
CVE-2025-62593
[ HIGH ]EPSS 1.0%kev

Ray-Project Ray Code Injection Vulnerability

Ray-Project Ray has a code injection flaw enabling RCE, added to CISA KEV on August 18, 2026. Ray installs with browser-reachable interfaces are at risk. Federal patch deadline is August 21.

Ray-Project / Ray
$ latest --more

From the desk

all articles →
~/articles/2026-08-19-china-ai-apac-nation-state-attack
China-Linked AI Framework Hits APAC Government Targets
● Breaking
threat intel

China-Linked AI Framework Hits APAC Government Targets

A Chinese-language operator used a complex AI framework to compromise APAC government agencies in what researchers call the first purported near-autonomous nation-state attack.

read →
~/articles/2026-08-18-medusa-ransomware-500-victims-cisa-fbi
CISA, FBI: Medusa Ransomware Has 500+ Victims
ransomware

CISA, FBI: Medusa Ransomware Has 500+ Victims

CISA and the FBI updated their Medusa ransomware advisory, confirming the group has hit more than 500 organizations in critical infrastructure since 2021.

read →
~/articles/2026-08-18-cosnitch-copilot-personal-data-exfiltration
CoSnitch: Three Copilot Flaws Enable One-Click Data Theft
microsoft

CoSnitch: Three Copilot Flaws Enable One-Click Data Theft

Varonis Threat Labs found three flaws in Microsoft Copilot Personal, named CoSnitch, that let attackers silently pull data from all connected apps in one click.

read →
~/articles/2026-08-18-mlflow-fuxa-cve-exploitation-cloud-scada
MLflow SSRF, FUXA Auth Flaws Actively Exploited
● Breaking
ics ot

MLflow SSRF, FUXA Auth Flaws Actively Exploited

Attackers are exploiting an SSRF in MLflow's AI platform and scanning FUXA SCADA installs—critical flaws in both enabling cloud credential theft and full RCE.

read →
~/articles/2026-08-18-clop-windchill-webshell-credential-theft
Clop's Windchill Implant Decrypts Passwords, Steals Files
ptc

Clop's Windchill Implant Decrypts Passwords, Steals Files

ReliaQuest finds a Clop-linked JSP implant engineered for PTC Windchill that decrypts LDAP credentials and maps file vaults to steal engineering data.

read →
~/articles/2026-08-18-stubmaker-rubygems-typosquat-supply-chain
16 Fake RubyGems Steal Browser Creds, Crypto Wallets
supply chain

16 Fake RubyGems Steal Browser Creds, Crypto Wallets

Sixteen malicious RubyGems packages tracked as StubMaker are stealing browser credentials and crypto wallets via typosquatting—audit your Gemfile now.

read →