Resources
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Mitchell Langley
July 30, 2026
CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical FMC auth bypass rated CVSS ...
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
Andrew Doyle
July 30, 2026
The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Andrew Doyle
July 30, 2026
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in agent memory.
OpenAI’s Rogue AI Used JFrog Zero-Days to Breach Hugging Face
Mitchell Langley
July 29, 2026
A new postmortem reveals OpenAI's rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face and four other services.
Check Point SmartConsole Auth Bypass PoC Elevates Active Exploit Risk
Mitchell Langley
July 29, 2026
Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in the wild.
Firefox JIT Flaw CVE-2026-10702 Exposes Tor Browser to Deanonymization
Gabby Lee
July 29, 2026
Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to deanonymization.
Gitea CVE-2026-60004 Gives Repo Writers Shell Access via Git Hooks
Gabby Lee
July 29, 2026
CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch content.
OpenWrt CVE-2026-53921 Lets Attackers Root Routers via DHCPv6 Overflow
Gabby Lee
July 29, 2026
CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt's DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on affected routers.
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Gabby Lee
July 29, 2026
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
Fastjson 1.x Zero-Day CVE-2026-16723 Under Active Exploit, No Patch
Mitchell Langley
July 28, 2026
CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare backends.
Weekly Newsletter
Weekly Cybersecurity Newsletter: 14th to 18th August
Andrew Doyle
July 19, 2025
Explore our latest cybersecurity podcast episodes featuring ransomware attacks, phishing campaigns, corporate breaches, legal showdowns, and deep dives into evolving threats and digital defenses.
This Week In Cybersecurity: 23rd June to 27th June
Andrew Doyle
June 30, 2025
News Stories New ‘FileFix’ Attack Exploits Windows File Explorer to Deliver Stealthy Commands Threat actors use the search-ms URI protocol ...
This Week In Cybersecurity: 26th to 30th May, 2025
Andrew Doyle
May 30, 2025
"Cybersecurity threats escalate as ransomware attacks target major organizations, exposing sensitive data and highlighting vulnerabilities in systems across various industries. Stay informed."
This Week In Cybersecurity: 19th to 23rd May, 2025
Andrew Doyle
May 23, 2025
This week, significant cybersecurity incidents include ransomware attacks, data breaches affecting major organizations, and ongoing threats from state-sponsored groups, highlighting vulnerabilities across various sectors.
This Week In Cybersecurity: 21st – 25th April, 2025
Andrew Doyle
April 25, 2025
Targeted malware, ransomware, phishing, and ad fraud hit SK Telecom, Baltimore schools, Google, and more this week—exposing critical data and abusing trusted systems.
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.














