Listen to a podcast, please open Podcast Republic app. Available on Google Play Store and Apple App Store.
| Episode | Date |
|---|---|
|
2026-08-05: INC ransomware is actively exploiting the SonicWall zero-day pair with rapid deployment times
|
Aug 05, 2026 |
|
2026-08-04: INC Ransomware is actively exploiting patched SonicWall VPN flaws to extract credentials and MFA
|
Aug 04, 2026 |
|
2026-08-03: N-able shipped an incomplete patch for an authentication bypass in N-central RMM that let attackers
|
Aug 03, 2026 |
|
2026-08-02: A critical Ruby on Rails RCE vulnerability (CVE-2026-66066
|
Aug 02, 2026 |
|
2026-08-01: A Chinese hacker used DeepSeek through Telegram to launch autonomous attacks exploiting five CISA
|
Aug 01, 2026 |
|
2026-07-31: Russian state hackers are actively exploiting a maximum-severity Exchange Server flaw to install
|
Jul 31, 2026 |
|
2026-07-30: Cisco patches actively exploited FMC zero-day granting static credential access
|
Jul 30, 2026 |
|
2026-07-29: Microsoft Active Directory Certificate Services faces privilege escalation through a broken trust
|
Jul 29, 2026 |
|
2026-07-28: Arista VeloCloud Orchestrator critical zero-day (CVE-2026-16812) actively exploited with three-day
|
Jul 28, 2026 |
|
2026-07-27: A Fastjson remote code execution bug (CVE-2026-16723) is under active exploitation against banks
|
Jul 27, 2026 |
|
2026-07-26: Cl0p affiliates are actively exploiting a CISA KEV-listed RCE in PTC Windchill/FlexPLM
|
Jul 26, 2026 |
|
2026-07-25: A public exploit for Certighost (CVE-2026-54121) lets any domain user impersonate a Domain
|
Jul 25, 2026 |
|
2026-07-24: Russian state actors exploit a Zimbra zero-day requiring only email preview to steal credentials
|
Jul 24, 2026 |
|
2026-07-23: Check Point patches critical zero-day CVE-2026-16232 exploited for full admin access via
|
Jul 23, 2026 |
|
2026-07-22: OpenAI's frontier models escaped their sandbox, exploited a zero-day
|
Jul 22, 2026 |
|
2026-07-21: Today
|
Jul 21, 2026 |
|
2026-07-20: SonicWall SMA zero-days exploited in the wild with CISA KEV deadlines passed
|
Jul 20, 2026 |
|
2026-07-19: Russians are using fake Signal support accounts for phishing campaigns
|
Jul 19, 2026 |
|
2026-07-18: Inc ransomware exploits two SonicWall zero-days in active attacks with a CISA deadline today
|
Jul 18, 2026 |
|
2026-07-17: Microsoft SharePoint critical RCE zero-day CVE-2026-58644 added to CISA KEV with July 19 patch
|
Jul 17, 2026 |
|
2026-07-16: Microsoft ships a record 622 patches including four CISA-KEV vulnerabilities with same-day
|
Jul 16, 2026 |
|
2026-07-15: Microsoft ships a record 622 patches including two zero-days under active exploitation in
|
Jul 15, 2026 |
|
2026-07-14: CISA adds an 18-year-old Cisco CSRF flaw to KEV with a 3-day deadline
|
Jul 14, 2026 |
|
2026-07-13: CISA added two critical Joomla extension flaws to KEV with a same-day deadline
|
Jul 13, 2026 |
|
2026-07-12: Compromised npm package jscrambler 8.14.0 drops Rust infostealer targeting dev environments and CI
|
Jul 12, 2026 |
|
2026-07-11: Progress Software ordered ShareFile customers to shut down Storage Zone Controllers over an
|
Jul 11, 2026 |
|
2026-07-10: CitrixBleed 2 (CVE-2025-5777) is being weaponized by Initial Access Brokers leading to Dragonforce
|
Jul 10, 2026 |
|
2026-07-09: CISA adds five exploited vulnerabilities to KEV catalog with a July 10 deadline
|
Jul 09, 2026 |
|
2026-07-08: CISA added four actively exploited flaws to the KEV catalog with Adobe ColdFusion attacks starting
|
Jul 08, 2026 |
|
2026-07-07: Oracle E-Business Suite faces active exploitation via CVE-2026-46817 affecting 950 instances
|
Jul 07, 2026 |
|
2026-07-06: Microsoft SharePoint zero-day under active attack after patches failed to fix the vulnerability
|
Jul 06, 2026 |
|
2026-07-05: A U.S
|
Jul 05, 2026 |
|
2026-07-04: A new Linux kernel privilege escalation bug called Bad Epoll achieves root from unprivileged
|
Jul 04, 2026 |
|
2026-07-03: Anubis ransomware exploits Citrix Bleed 2 with CISA-mandated July 11 deadline
|
Jul 03, 2026 |
|
2026-07-02: SharePoint RCE hits CISA's known exploited list with a Friday deadline
|
Jul 02, 2026 |
|
2026-07-01: Citrix patches a high-severity NetScaler memory disclosure flaw reminiscent of CitrixBleed
|
Jul 01, 2026 |
|
2026-06-30: Oracle E-Business Suite CVE-2026-46817 (CVSS 9.8) moved from patched-but-quiet to actively
|
Jun 30, 2026 |
|
2026-06-20: CISA orders federal agencies to patch Splunk Enterprise by Sunday as active exploitation confirmed
|
Jun 20, 2026 |
|
2026-06-19: CISA adds actively exploited Splunk vulnerability to its KEV catalog days after disclosure
|
Jun 19, 2026 |
|
2026-06-18: FortiBleed exposes 73,000 Fortinet VPN credentials to a Russian-speaking threat group targeting
|
Jun 18, 2026 |
|
2026-06-17: CISA gives federal agencies until tomorrow to patch an actively exploited cPanel plugin
|
Jun 17, 2026 |
|
2026-06-16: Cisco patches its eighth SD-WAN zero-day of the year
|
Jun 16, 2026 |
|
2026-06-15: Palo Alto GlobalProtect VPN suffers active exploitation with CISA KEV deadline passed
|
Jun 15, 2026 |
|
2026-06-14: Anthropic disabled its two most advanced AI models after a US government export control order over
|
Jun 14, 2026 |
|
2026-06-13: ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 for two weeks
|
Jun 13, 2026 |
|
2026-06-12: CISA gives federal agencies until Sunday to patch an Ivanti Sentry vulnerability already exploited
|
Jun 12, 2026 |
|
2026-06-11: A new Windows zero-day exploit bypassing Microsoft Defender was released hours after Patch Tuesday
|
Jun 11, 2026 |
|
2026-06-10: Microsoft patches 206 vulnerabilities in the largest Patch Tuesday on record
|
Jun 10, 2026 |
|
2026-06-09: Check Point VPN users have three days to patch CVE-2026-50751
|
Jun 09, 2026 |
|
2026-06-08: SolarWinds Serv-U exploit is live in the wild with CISA adding CVE-2026-28318 to the KEV catalog
|
Jun 08, 2026 |
|
2026-06-07: WordPress site takeovers are spreading via a critical Everest Forms Pro exploit that creates rogue
|
Jun 07, 2026 |
|
2026-06-06: SolarWinds Serv-U and Cisco SD-WAN vulnerabilities are being exploited in the wild with no patch
|
Jun 06, 2026 |
|
2026-06-05: Cisco discloses seventh SD-WAN zero-day this year, now actively exploited for root escalation with
|
Jun 05, 2026 |
|
Cyber Threat Brief for 2026-06-04
|
Jun 04, 2026 |
|
2026-06-03: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal
|
Jun 03, 2026 |
|
2026-06-02: Critical Alerts
|
Jun 02, 2026 |
|
2026-06-01: Critical WordPress plugin flaw under active exploitation allows unauthenticated admin account
|
Jun 01, 2026 |
|
2026-05-31: Palo Alto GlobalProtect VPN suffers active exploitation of an authentication bypass (CVE-2026-0257
|
May 31, 2026 |
|
2026-05-30: Palo Alto GlobalProtect bypass is now actively exploited with CISA adding CVE-2026-0257 to KEV
|
May 30, 2026 |
|
2026-05-29: Gogs zero-day enables remote code execution on 2,400+ Internet-exposed servers
|
May 29, 2026 |
|
2026-05-28: CISA added a critical LiteSpeed cPanel plugin flaw to the KEV catalog with a Friday midnight
|
May 28, 2026 |
|
2026-05-27: CISA adds exploited LiteSpeed cPanel plugin zero-day to KEV catalog with May 29 patch deadline
|
May 27, 2026 |
|
2026-05-26: Critical Alerts
|
May 26, 2026 |
|
2026-05-25: Supply chain attacks hit developer ecosystems with 34 malicious packages stealing credentials
|
May 25, 2026 |
|
2026-05-24: Multiple PHP package supply chain attacks hit Laravel and Composer ecosystems with cross-platform
|
May 24, 2026 |
|
2026-05-23: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal
|
May 23, 2026 |
|
2026-05-22: Microsoft patched two actively exploited Defender zero-days with CISA deadline June 3
|
May 22, 2026 |
|
2026-05-21: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3
|
May 21, 2026 |
|
2026-05-20: Microsoft faces a sixth zero-day disclosure in six weeks as researcher "Nightmare Eclipse" releases
|
May 20, 2026 |
|
2026-05-19: Microsoft Exchange zero-day CVE-2026-42897 is under active attack with no patch available
|
May 19, 2026 |
|
2026-05-18: Windows zero-day MiniPlasma grants SYSTEM privileges on fully patched systems with PoC released
|
May 18, 2026 |
|
2026-05-17: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin
|
May 17, 2026 |
|
2026-05-16: Cisco drops its seventh SD-WAN zero-day in three months as attackers exploit a CVSS 10
|
May 16, 2026 |
|
2026-05-15: Cisco SD-WAN faces its sixth exploited zero-day of 2026 with CVE-2026-20182 granting attackers
|
May 15, 2026 |
|
2026-05-14: Microsoft patched 138 vulnerabilities including critical RCE flaws in DNS and Netlogon
|
May 14, 2026 |
|
2026-05-13: Microsoft ships 137 patches with no zero-days for the first time in two years
|
May 13, 2026 |
|
2026-05-12: Linux systems face a second privilege escalation exploit in two weeks with Dirty Frag working
|
May 12, 2026 |
|
2026-05-11: Google catches the first confirmed AI-developed zero-day before mass exploitation
|
May 11, 2026 |
|
2026-05-09: Palo Alto Networks is patching CVE-2026-0300, a critical zero-day in PAN-OS being actively
|
May 09, 2026 |
|
2026-05-08: Ivanti ships its third EPMM zero-day patch of 2026 (CVE-2026-6973, active exploitation confirmed)
|
May 08, 2026 |
|
2026-05-07: Iranian state-sponsored actors are masquerading ransomware attacks to hide espionage operations
|
May 07, 2026 |
|
2026-05-06: Palo Alto Networks firewalls face active zero-day exploitation targeting exposed authentication
|
May 06, 2026 |
|
2026-05-05: cPanel exploitation reaches thousands of servers with Mirai and ransomware payloads
|
May 05, 2026 |
|
2026-05-04: cPanel zero-day exploitation hits over 40,000 servers with CISA KEV deadline this week
|
May 04, 2026 |
|
2026-05-02: Linux kernel privilege escalation vulnerability CVE-2026-31431 hits CISA's KEV catalog with a May
|
May 02, 2026 |
|
2026-05-01: cPanel's CVE-2026-41940 authentication bypass is being actively exploited after months as a
|
May 01, 2026 |
|
2026-04-30: Microsoft's February patch for a Russian zero-day fell short
|
Apr 30, 2026 |
|
2026-04-29: CISA adds exploited ConnectWise and Windows flaws to KEV catalog
|
Apr 29, 2026 |
|
2026-04-28: Supply chain attacks accelerate with a 26-day pause ending in coordinated compromises across npm
|
Apr 28, 2026 |
|
2026-04-27: Firefox and Tor Browser patched a tracking vulnerability that defeats anonymity features
|
Apr 27, 2026 |