Skip to content
feed: live
>_ 0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2026-20316
[ MEDIUM ] CVSS 5.3 EPSS 0.8% kev

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-21513
[ HIGH ] CVSS 8.8 EPSS 15.4% kev

Microsoft MSHTML security feature bypass

Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.

Microsoft / MSHTML Framework (Windows)
CVE-2026-16812
[ CRITICAL ] CVSS 10.0 EPSS 0.9% kev

Arista VeloCloud Orchestrator OS Command Injection

CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.

Arista / VeloCloud Orchestrator On-Prem
CVE-2026-16232
[ CRITICAL ] CVSS 9.1 EPSS 71.4% kev

Check Point SmartConsole improper authentication

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

Check Point / SmartConsole
CVE-2026-60137
[ MEDIUM ] CVSS 5.9 EPSS 79.0% kev

WordPress WP_Query author__not_in SQL injection (wp2shell companion)

A medium-severity SQL injection in WordPress WP_Query's author__not_in parameter (CVE-2026-60137). Tracked as the wp2shell companion. Patched in 6.8.6, 6.9.5, and 7.0.2.

WordPress / WordPress Core (6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1)
CVE-2026-63030
[ CRITICAL ] CVSS 9.8 EPSS 98.4% kev

WordPress Core unauthenticated RCE (wp2shell)

A critical unauthenticated remote code execution flaw in WordPress Core (CVE-2026-63030). GitHub Security Advisory issued July 17, 2026; public PoC circulating.

WordPress / WordPress Core (6.9 and 7.0 branches per The Hacker News)
$ latest --more

From the desk

all articles →
~/articles/2026-08-01-captivecrunch-storm-2945-hotel-wifi-cornflake-rat
Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT
● Breaking
threat intel

Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT

Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.

read →
~/articles/2026-08-01-hollowframe-matryoshka-backdoor-law-firm
HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm
● Breaking
threat intel

HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm

Blackpoint Cyber documents HollowFrame, a Go-based loader, and Matryoshka, a Rust backdoor, deployed against a law firm via spear-phishing and an encrypted LNK archive.

read →
~/articles/2026-08-01-chinese-apt-octlurk-silklurk-central-asia
Chinese APT Deploys OctLurk and SilkLurk in Central Asia
Analysis
threat intel

Chinese APT Deploys OctLurk and SilkLurk in Central Asia

Kaspersky details OctLurk and SilkLurk, new backdoors in a suspected Chinese espionage campaign targeting Central Asian governments since January 2025.

read →
~/articles/2026-07-31-amgen-cloud-breach-patient-health-data
Amgen Says Breach Exposed Patient Health Data
● Breaking
threat intel

Amgen Says Breach Exposed Patient Health Data

Amgen confirmed threat actors stole patient health information and proprietary corporate data from third-party cloud systems operated by outside service providers.

read →
~/articles/2026-07-31-arch-linux-aur-malware-lockdown
Arch Linux Locks Down AUR After Malware Takeover Surge
● Breaking
supply chain

Arch Linux Locks Down AUR After Malware Takeover Surge

Arch Linux disabled AUR package adoption after a surge of malicious takeovers by threat actors who exploited the mechanism to push backdoored updates to users.

read →
~/articles/2026-07-31-adform-ad-script-supply-chain-crypto-clipboard
Adform Ad Script Hijacked in Supply-Chain Crypto Attack
supply chain

Adform Ad Script Hijacked in Supply-Chain Crypto Attack

Adform's ad script was backdoored to swap crypto wallet addresses in visitor clipboards, silently stealing funds on sites running the compromised tag.

read →