Blog
CVE-2026-59310 (CVSS 9.8): Chinese APT Exploits VMware vCenter in 5 Days — 361 Victims, Babuk Ransomware Encrypts ESXi
CVE-2026-59310 (CVSS 9.8) lets unauthenticated attackers gain root RCE on VMware vCenter via Syslog path traversal. 361 victims in 47 countries; Babuk ransomware deployed on ESXi. Patch VMSA-2026-0006 immediately.
Read More →CVE-2026-58231 (CVSS 10.0): Attackers Exploit SAP Commerce Cloud in 72 Hours — 4,200+ Shops Exposed, Patch Now
CVE-2026-58231 is a CVSS 10.0 RCE in SAP Commerce Cloud exploited just 72 hours after patching. 4,200+ instances exposed — patch via SAP Note 3771065 now.
Read More →CVE-2026-65400 (CVSS 9.8): Attackers Are Silently Rooting Macs via Screen Sharing — 40,000 Hosts Exposed, Monero Miners Deployed
CVE-2026-65400 lets network attackers bypass macOS Screen Sharing auth and gain root without credentials. 40,000 hosts exposed, XMRig Monero miner deployed. CISA CVSS 9.8. Patch now.
Read More →Gunra RaaS: Six Intelligence Agencies Issue Emergency Alert as Conti’s Heir Exploits FortiGate Vulnerabilities — 51 Victims, $10M+ Ransom Demands
CISA, FBI & four partner agencies warn of Gunra ransomware exploiting FortiOS CVE-2024-55591 (CVSS 9.8) to hit healthcare, govt & critical infrastructure globally.
Read More →iAuthFlow v2 & Pass-the-Passkey (CVE-2026-34348): The $10,000 Attack Turning Your Passkeys Against You
A $10,000 underground phishing kit dubbed iAuthFlow v2 enrolls attacker-controlled passkeys in ~6 seconds, persisting through password resets — while CVE-2026-34348 exposed YubiKey signatures stored in cleartext Windows Event Logs.…
Read More →APT29 Ghost Login: Russian Spies Bypass MFA Using Google OAuth and WhatsApp — GTIG Reveals Three Active Espionage Clusters
Google GTIG exposes three Russian APT29-linked clusters (UNC6293, UNC7005, UNC5976) abusing OAuth device-code flows and WhatsApp device-linking to bypass MFA and target defence, diplomacy and academia.
Read More →CVE-2026-55040 + CVE-2026-63520 (CVSS 9.1): Attackers Now Forge SharePoint Admin Credentials — No Password Required
CVE-2026-55040 (CVSS 9.1) lets attackers forge SharePoint JWT tokens with no credentials. Chained with CVE-2026-63520, it enables unauthenticated RCE. CISA KEV-listed Aug 18, 2026.
Read More →The Gentlemen Ransomware: India in the Crosshairs as 500+ Victims Fall and FortiGate Backdoors Enable Global Strikes
The Gentlemen ransomware group has claimed 500+ victims across 66 countries, exploiting FortiGate CVE-2024-55591. Four Indian firms already hit — act now.
Read More →RUSTSEC-2026-0260: North Korean Hackers Poison arrayref Rust Crate With Build-Time Infostealer — 245 Million Downloads at Risk
DPRK-linked attackers poisoned the arrayref Rust crate with build-time malware hitting 245M downloads. Learn how the attack worked and how to secure your CI/CD pipeline.
Read More →CVE-2026-69836 (CVSS 10.0): Microsoft Entra ID’s Maximum-Severity Deserialization RCE Was Exploited Before You Knew It Existed
Microsoft Entra ID carries a CVSS 10.0 deserialization RCE (CVE-2026-69836) already exploited in the wild. Server-side patch applied—here's what your security team must verify now.
Read More →