Blog
CVE-2026-42533: NGINX’s Hidden 15-Year Flaw (CVSS 9.2) Threatens Every Web Server — Patch Before the PoC Drops
CVE-2026-42533 is a critical NGINX heap buffer overflow (CVSS 9.2) hiding since 2011. Patch to nginx 1.30.4 or 1.31.3 now — a PoC exploit drops by 5 August.
Read More →GodDamn Ransomware’s Signed PoisonX Driver Is Silently Killing Your EDR — Inside Hyadina’s BYOVD Playbook
Hyadina's GodDamn ransomware uses a Microsoft-signed malicious kernel driver (PoisonX/g11.sys) to disable EDR and AV before encrypting 10+ hosts. Here's the full BYOVD attack chain and how to stop it.
Read More →FEDERAL DEADLINE TODAY: CVE-2026-58644 SharePoint Zero-Day (CVSS 9.8) Exploited in the Wild — CISA Mandates Immediate Patching
CVE-2026-58644 (CVSS 9.8) is a zero-day unauthenticated RCE in SharePoint Server now on CISA's KEV list. Federal deadline is today — here's what to patch and how to check if…
Read More →GoldenEyeDog Breached DigiCert and Armed 27 Stolen EV Code-Signing Certificates — Zero Trust Is Now Your Only Defence
Chinese APT CylindricalCanine breached DigiCert via a support chat screensaver, stealing 27 EV code-signing certificates now used to sign Zhong Stealer malware targeting APAC finance firms.
Read More →wp2shell (CVE-2026-63030, CVSS 9.8): One HTTP Request Can Own Your WordPress Site — Patch Now
Critical pre-auth RCE in WordPress Core (CVE-2026-63030, CVSS 9.8) lets attackers own any WordPress 6.9–7.0 site with a single anonymous request. Patch to 6.9.5 or 7.0.2 immediately.
Read More →CISA Mandate: Patch Fortinet FortiSandbox Now — Three CVSS 9.1 Flaws Under Active Attack (Federal Deadline July 19)
Three CVSS 9.1 Fortinet FortiSandbox vulnerabilities (CVE-2026-25089, CVE-2026-39808, CVE-2026-39813) are actively exploited — CISA KEV added July 16 with a federal patch deadline of July 19. Patch to 4.4.9 or…
Read More →SonicWall SMA1000 Zero-Day Chain (CVE-2026-15409 CVSS 10.0): Attackers Are Stealing VPN Credentials and MFA Seeds — Patch Today
Two actively exploited SonicWall SMA1000 zero-days chain to steal VPN credentials and MFA seeds. CISA deadline is today, July 17. Patch now or re-image if compromised.
Read More →LegacyHive: Unpatched Windows Zero-Day Drops Hours After Patch Tuesday — Every Supported Version at Risk
LegacyHive is an unpatched Windows User Profile Service privilege escalation zero-day released hours after July 2026 Patch Tuesday. Every supported Windows version is affected — here is the technical breakdown…
Read More →Microsoft Patch Tuesday July 2026: 570 Flaws, Two Actively Exploited Zero-Days in AD FS and SharePoint
Microsoft’s July 2026 Patch Tuesday — the largest in company history at ~570 CVEs — includes two actively exploited zero-days: CVE-2026-56155 (AD FS, CVSS 7.8) and CVE-2026-56164 (SharePoint, CVSS 5.3).…
Read More →No Password Needed: CVE-2026-46817 (CVSS 9.8) Gives Attackers Full Access to Oracle EBS Payments Over Plain HTTP — 950+ Instances Exposed
CVE-2026-46817 (CVSS 9.8) in Oracle EBS Payments is under active attack — 950+ instances exposed, no auth needed. Here's what to patch and check now.
Read More →