Skip to content
feed: live
>_ 0dayNews
$ news

Vulnerability & Exploit Coverage

479 articles · sorted newest first

~/news --filter

~/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts
ShinyHunters Hits RingCentral: 1.6M Accounts Exposed
● Breaking
threat intel

ShinyHunters Hits RingCentral: 1.6M Accounts Exposed

ShinyHunters breached RingCentral in July, exposing 1.6 million accounts. Names, addresses, emails, and phone numbers are now published by the group.

read →
~/articles/2026-08-14-beacon-crm-breach-charities-aws-key
Beacon CRM Breach Hits 1,000+ Charities via AWS Key
● Breaking
cloud

Beacon CRM Breach Hits 1,000+ Charities via AWS Key

Over 1,000 UK charities had supporter data exposed after attackers used an AWS access key found in Beacon's public JavaScript build artifacts.

read →
~/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript
WordPress 7.0.4 Patches High-Severity RCE Flaw
wordpress

WordPress 7.0.4 Patches High-Severity RCE Flaw

WordPress 7.0.4 fixes a high-severity RCE allowing Author-level accounts to execute code via malicious PostScript files. Update now.

read →
~/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation
GeoServer Zero-Day SQL Injection Exploited in Wild
● Breaking
threat intel

GeoServer Zero-Day SQL Injection Exploited in Wild

Threat actors are actively exploiting an unpatched SQL injection in GeoServer that enables remote code execution. No patch available; restrict exposure immediately.

read →
~/articles/2026-08-14-apple-mercenary-spyware-threat-notifications
Apple Notifies Users of Mercenary Spyware Attacks
● Breaking
apple

Apple Notifies Users of Mercenary Spyware Attacks

Apple issued Threat Notifications to iPhone users warning of active mercenary spyware attacks. If you received one, here is what to do immediately.

read →
~/articles/2026-08-14-belgium-eid-browser-extension-rce
Belgium eID Browser Extension Bugs Enable RCE
● Breaking
browser

Belgium eID Browser Extension Bugs Enable RCE

Severe vulnerabilities in Belgium's eID browser extension fully compromised the country's national identity trust framework, researchers confirmed, opening citizen accounts to remote code execution.

read →
~/articles/2026-08-13-legacyhive-windows-zero-day-patch
Microsoft Patches LegacyHive Windows Zero-Day
microsoft

Microsoft Patches LegacyHive Windows Zero-Day

Microsoft issued a patch for LegacyHive, a named Windows zero-day disclosed in the gap between July and August Patch Tuesday cycles.

read →
~/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft
Akira Disables EDR via Safe Mode Reboot, Steals Data
● Breaking
ransomware

Akira Disables EDR via Safe Mode Reboot, Steals Data

An Akira ransomware affiliate rebooted a compromised host into Safe Mode to kill EDR, exfiltrated data, then failed to encrypt. The exfiltration is the real threat.

read →
~/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence
VMware vCenter Exploit Deploys Reverse SSH Backdoor
● Breaking
vmware

VMware vCenter Exploit Deploys Reverse SSH Backdoor

Threat actors exploiting CVE-2026-59310 are deploying a reverse SSH tool for persistent access on compromised vCenter management planes.

read →
~/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer
New Mirai Variant Adds Encrypted C2 and Credential Sniffer
Analysis
threat intel

New Mirai Variant Adds Encrypted C2 and Credential Sniffer

A new Mirai variant adds encrypted C2 comms and a default-credential sniffer — raising the detection bar for defenders relying on network-layer visibility.

read →
~/articles/2026-08-13-trezor-shipmonk-breach-14k-customers
Trezor Breach: 14,000 Customers Exposed via ShipMonk Hack
● Breaking
supply chain

Trezor Breach: 14,000 Customers Exposed via ShipMonk Hack

Trezor disclosed a breach hitting nearly 14,000 customers after shipping partner ShipMonk was compromised. No device or key exposure. Customer order data is the risk.

read →
~/articles/2026-08-13-white-house-hack-back-private-firms-ncc
White House Opens Hack-Back Program to Private Firms
● Breaking
threat intel

White House Opens Hack-Back Program to Private Firms

Trump memo directs the NCC to license private security firms for offensive cyber ops against foreign criminal organizations. $1M bond required for compliance.

read →
~/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops
Jewelbug APT Merges Espionage and Crypto Fraud
● Breaking
threat intel

Jewelbug APT Merges Espionage and Crypto Fraud

Symantec links China-tied Jewelbug to dual operations — state espionage and cryptocurrency fraud — run from the same C2 web panel, with a victim database logging over one million implant check-ins.

read →
~/articles/2026-08-13-fortinet-fortiweb-fortimanager-aug-patches
Fortinet Patches Critical FortiWeb Auth Bypass, CVSS 9.8
● Breaking
fortinet

Fortinet Patches Critical FortiWeb Auth Bypass, CVSS 9.8

CVE-2026-26035 in FortiWeb lets unauthenticated attackers log in with any credentials — CVSS 9.8. FortiManager also gets a CVSS 8.1 auth bypass fix this cycle.

read →
~/articles/2026-08-13-sharepoint-cve-2026-55040-active-exploitation-poc
SharePoint CVE-2026-55040 Exploited After PoC Drop
● Breaking
microsoft

SharePoint CVE-2026-55040 Exploited After PoC Drop

Rapid7's 30-day embargo on CVE-2026-55040 has expired. A public PoC is circulating and active exploitation is confirmed. The July 2026 CU patches it. Apply it now.

read →
~/articles/2026-08-13-ics-patch-tuesday-siemens-schneider-phoenix-contact
ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact
ics ot

ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact

Siemens, Schneider Electric, and Phoenix Contact issued security bulletins on August 12. CISA published parallel ICS advisories the same day. OT operators should review now.

read →
~/articles/2026-08-13-android-windrelay-spynote-nfc-relay-fraud
Android Malware Relays NFC Cards, Takes Out Loans
● Breaking
mobile

Android Malware Relays NFC Cards, Takes Out Loans

WindRelay, a new Android NFC relay malware, is deployed alongside SpyNote RAT to steal live card data and take out fraudulent loans in victims' names.

read →
~/articles/2026-08-12-city-forum-salesforce-servicenow-data-theft
City-Forum Campaign Targets Salesforce, ServiceNow
threat intel

City-Forum Campaign Targets Salesforce, ServiceNow

A data-theft operation running since March 2025 harvests records exposed through anonymous-access endpoints in Salesforce Experience Cloud and ServiceNow portals — no CVE required.

read →
~/articles/2026-08-12-colombia-justice-ministry-ransomware
Colombia Justice Ministry Hit With Ransomware
● Breaking
ransomware

Colombia Justice Ministry Hit With Ransomware

Ransomware disrupted Colombia's Ministry of Justice days before the presidential transition, part of a documented pattern of attacks on Latin American government institutions.

read →
~/articles/2026-08-12-adobe-commerce-cve-2026-71362-active-exploit
Attackers Exploiting Critical Adobe Commerce Flaw
● Breaking
adobe

Attackers Exploiting Critical Adobe Commerce Flaw

Active exploitation of CVE-2026-71362 targets Adobe Commerce and Magento storefronts. CVSS 9.1 critical flaw enables account hijacking without user interaction.

read →
~/articles/2026-08-12-chrome-vpn-extensions-proxy-hijack
737 Fake Chrome VPN Extensions Route Traffic via Proxies
browser

737 Fake Chrome VPN Extensions Route Traffic via Proxies

737 Chrome extensions impersonated VPN services while routing users' traffic through a single SOCKS5 proxy. Over 75,000 installs affected across the Store.

read →
~/articles/2026-08-12-lazarus-cve-2026-68820-operation-dream-job-cisa-kev
Lazarus Targeted Defense Firms via Windows Zero-Day
● Breaking
microsoft

Lazarus Targeted Defense Firms via Windows Zero-Day

Lazarus exploited a Windows zero-day in afd.sys targeting defense firms via Operation Dream Job. CISA issued a two-week federal patch mandate.

read →
~/articles/2026-08-12-shieldbreak-defender-cve-2026-50656-patch-bypass
ShieldBreak: Defender Patch Bypass PoC Published
● Breaking
microsoft

ShieldBreak: Defender Patch Bypass PoC Published

ShieldBreak PoC, released hours after Patch Tuesday, claims to bypass the CVE-2026-50656 Defender fix and achieve SYSTEM access on patched systems.

read →
~/articles/2026-08-12-vcenter-cve-2026-59310-exploited-in-wild
vCenter Auth Bypass CVE-2026-59310 Now Exploited
● Breaking
vmware

vCenter Auth Bypass CVE-2026-59310 Now Exploited

CVE-2026-59310 exploitation confirmed in VMware vCenter Server. CVSS 9.8. Patches out since July 29 — unpatched instances need isolation now.

read →