Blog
SonicWall SMA1000 Zero-Day Chain (CVE-2026-15409 CVSS 10.0): Attackers Are Stealing VPN Credentials and MFA Seeds — Patch Today
Two actively exploited SonicWall SMA1000 zero-days chain to steal VPN credentials and MFA seeds. CISA deadline is today, July 17. Patch now or re-image if compromised.
Read More →LegacyHive: Unpatched Windows Zero-Day Drops Hours After Patch Tuesday — Every Supported Version at Risk
LegacyHive is an unpatched Windows User Profile Service privilege escalation zero-day released hours after July 2026 Patch Tuesday. Every supported Windows version is affected — here is the technical breakdown…
Read More →Microsoft Patch Tuesday July 2026: 570 Flaws, Two Actively Exploited Zero-Days in AD FS and SharePoint
Microsoft’s July 2026 Patch Tuesday — the largest in company history at ~570 CVEs — includes two actively exploited zero-days: CVE-2026-56155 (AD FS, CVSS 7.8) and CVE-2026-56164 (SharePoint, CVSS 5.3).…
Read More →No Password Needed: CVE-2026-46817 (CVSS 9.8) Gives Attackers Full Access to Oracle EBS Payments Over Plain HTTP — 950+ Instances Exposed
CVE-2026-46817 (CVSS 9.8) in Oracle EBS Payments is under active attack — 950+ instances exposed, no auth needed. Here's what to patch and check now.
Read More →One HTTP Header = Admin Access: CVE-2026-20896 Actively Exploited in the Wild — Patch Your Gitea Now
CVE-2026-20896 (CVSS 9.8) allows attackers to impersonate any Gitea admin with a single HTTP header. Active exploitation confirmed. Patch to 1.26.4 now.
Read More →CVE-2026-53359 “Januscape”: 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to the Host — Patch Now
CVE-2026-53359 'Januscape' is a 16-year-old Linux KVM shadow MMU flaw (CVSS 8.8/9.3) enabling guest VMs to escape to the host on Intel and AMD. Here's how to patch and protect…
Read More →JadePuffer: The World’s First AI-Agent Ransomware — No Human Operator Required
Sysdig has captured JadePuffer — the world's first fully AI-agent-driven ransomware. It exploited CVE-2025-3248 in Langflow, adapted in real time, and encrypted 1,342 production records autonomously.
Read More →FBI FLASH: TeamPCP’s Supply Chain Worm Poisons Trusted Dev Tools — Your CI/CD Pipeline May Already Be Breached
FBI FLASH exposes TeamPCP, who poisoned Trivy, KICS & LiteLLM to steal AWS, GCP and Azure credentials from CI/CD pipelines. Rotate secrets now.
Read More →Adobe ColdFusion Under Active Attack: CVE-2026-48282 & 6 More CVSS 10.0 Flaws — Patch Now Before Your Server Is Next
Adobe patched 7 CVSS 10.0 ColdFusion flaws on 1 July 2026. CVE-2026-48282 is exploited in the wild — an Indian IP was the first attacker. Patch to Update 21 or…
Read More →CVE-2026-46242 “Bad Epoll” (CVSS 7.8): Any Linux User Can Become Root — Patch Now Before Attackers Do It For You
CVE-2026-46242 "Bad Epoll" is a use-after-free flaw letting any local Linux user gain root with 99% exploit reliability. Patch to 6.6.144+, 6.12.95+, or 6.18.33+ now.
Read More →