Blog
CVE-2026-57092 (CVSS 9.9): Windows VMSwitch Use-After-Free Lets Hyper-V Guest VMs Escape to Own the Host — Patch Now
CVE-2026-57092 is a CVSS 9.9 use-after-free in Windows VMSwitch allowing Hyper-V guest VMs to break out and escalate to full host control. All Windows Server versions affected — patch now.
Read More →CVE-2026-58644 (CVSS 9.8): Microsoft SharePoint Servers Are Being Hit by Active RCE Exploitation Right Now
CVE-2026-58644 is a CVSS 9.8 Microsoft SharePoint deserialization RCE actively exploited in the wild. CISA added it to KEV on 17 July 2026. Learn what SharePoint versions are affected, how…
Read More →CVE-2026-20316: Cisco Firewall Management Center Zero-Day — Hard-Coded Password Actively Exploited, CISA Orders Patch by August 1
CVE-2026-20316 is a zero-day hard-coded credential flaw in Cisco Secure Firewall Management Center. CISA added it to the KEV catalog on July 29, 2026 with a federal deadline of August…
Read More →Sapphire Sleet: North Korea Backdoored npm’s debug & chalk — Affecting 2 Billion Weekly Downloads
Amazon linked North Korea’s Sapphire Sleet to the npm poisoning of debug, chalk, and axios — packages with 2B+ weekly downloads. Timeline, technical breakdown, and defence playbook inside.
Read More →CVE-2026-63077 (CVSS 9.8): Unauthenticated RCE in JetBrains TeamCity — Your CI/CD Pipeline Is One HTTP Request Away from Compromise
CVE-2026-63077 (CVSS 9.8) lets unauthenticated attackers execute OS commands on any JetBrains TeamCity On-Premises server. Patch to 2025.11.7 or 2026.1.3 now.
Read More →CVE-2026-60004 (CVSS 9.8): Any Gitea User Can Hijack Your Server — A Public PoC Just Made Self-Hosted Git a Ticking Clock
CVE-2026-60004 is a CVSS 9.8 RCE in Gitea 1.17–1.27.0 that lets any user with repository write access execute OS commands on your server via Git hook injection. With open registration…
Read More →CVE-2026-60004 (CVSS 9.8): Any Gitea User Can Hijack Your Server — A Public PoC Just Made Self-Hosted Git a Ticking Clock
CVE-2026-60004 is a CVSS 9.8 RCE in Gitea 1.17–1.27.0 that lets any user with repository write access execute OS commands on your server via Git hook injection. With open registration…
Read More →ShinyHunters Claims EY Data Breach — Client Tax Records, SSNs, and a July 31 Extortion Deadline
ShinyHunters claims EY data breach exposing client SSNs and tax data via supply-chain attack. Extortion deadline is July 31, 2026 — here’s what security teams must do now.
Read More →Three Fortinet FortiSandbox CVEs Are Being Chained for Unauthenticated Root Access — CISA Deadline Passed, Exploitation Confirmed
CVE-2026-25089 (CVSS 9.8), CVE-2026-39808, and CVE-2026-39813 in Fortinet FortiSandbox are being chained by attackers for unauthenticated OS command execution. CISA KEV deadline passed — patch to 4.4.9 or 5.0.6 now.
Read More →CVE-2026-16812 (CVSS 10.0): Arista VeloCloud SD-WAN Orchestrator Zero-Day Is Being Actively Exploited — Patch by July 30
CVE-2026-16812 (CVSS 10.0) is an unauthenticated OS command injection in Arista VeloCloud Orchestrator being actively exploited. CISA KEV deadline is July 30. Patch on-prem VCO now.
Read More →