
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild

Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild

Attackers seized CubePilot’s domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.

Anthropic’s Claude Mythos derived a HAWK-256 key-recovery attack and 200–800x speedup for a seven-round AES-128 attack, with no impact on

Flying Eagle Android RAT source code is on Telegram; researchers traced matching panels to 170 servers targeting Chinese users via

Two @joyfill npm beta packages were compromised to deliver DEV#POPPER RAT on import, risking credential theft and persistent access on

Sysdig documented ENCFORGE, a Go ransomware targeting 180 AI file formats including PyTorch, SafeTensors, and GGUF, deployed by the JADEPUFFER

CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare

CISA added Langflow CVE-2026-0770 and WordPress wp2shell CVE-2026-63030 to its KEV catalog, setting a July 24 Langflow deadline and August

Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.

JetBrains patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in TeamCity CI/CD servers exploitable via the agent polling protocol without any
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.