Daily cybersecurity intelligence

The latest unpatched intel.

Raw, actionable daily security news for defenders tracking exploited vulnerabilities, ransomware, breaches, malware, cloud risk, supply-chain security, and practical detection guidance.

Latest stories

criticalExploited VulnerabilitiesAug 13, 2026·3 min read

Attackers exploit VMware vCenter Syslog directory traversal flaw for remote code execution

Attackers are actively exploiting a critical directory traversal vulnerability in the VMware vCenter Syslog server to gain remote code execution.

highAPT / Nation-StateAug 13, 2026·2 min read

Hard-coded credentials and unauthenticated flaws expose ANDRITZ HIPASE-250 process data and workstations

Critical vulnerabilities in the ANDRITZ HIPASE-250 system allow unauthenticated attackers to steal passwords, view live process data, and suppress audit logs.

highDefensive GuidanceAug 13, 2026·2 min read

Remote file reading and root privilege escalation vulnerabilities found in Siemens License Server

Critical flaws in the Siemens License Server (SLS) could allow attackers to read arbitrary files remotely or gain full root access via local privilege escalation.

highDefensive GuidanceAug 13, 2026·2 min read

Specially crafted X_T files trigger arbitrary code execution in Siemens Parasolid software

A high-severity out of bounds read vulnerability in Siemens Parasolid could allow an attacker to execute arbitrary code or crash the application.

highExploited VulnerabilitiesAug 12, 2026·2 min read

Ivanti releases critical patches for Endpoint Manager vulnerabilities targeting credentials and S3 buckets

Ivanti has released critical updates to address multiple high-severity vulnerabilities in Endpoint Manager (EPM) that could lead to credential theft and unauthorized S3 bucket control.

highExploited VulnerabilitiesAug 12, 2026·4 min read

Lazarus Group exploits Windows kernel vulnerability to escalate privileges via fake job offers

Lazarus Group is exploiting a Windows kernel vulnerability to escalate privileges and deploy backdoors via fake job offers.

criticalExploited VulnerabilitiesAug 12, 2026·2 min read

Unauthenticated attackers can achieve full system compromise via critical Adobe ColdFusion flaws

🚨 Critical flaw in Adobe ColdFusion 2025 enables full system compromise. Attackers can execute arbitrary commands without any user interaction or authentication.

highExploited VulnerabilitiesAug 12, 2026·3 min read

Unauthenticated attackers exploit SharePoint vulnerability to bypass authentication and hijack administrative accounts

Attackers are actively exploiting a critical authentication bypass in Microsoft SharePoint. This flaw allows unauthenticated remote users to impersonate site users or administrators and modify data.

highExploited VulnerabilitiesAug 11, 2026·3 min read

Attackers can execute remote code via Zoom annotation tool without user interaction

🚨 High severity. A zero-click remote code execution flaw in Zoom's annotator function allows attackers to take over a participant's machine without any user interaction.

highExploited VulnerabilitiesAug 11, 2026·2 min read

Critical Windows kernel flaw exploitation drives massive Microsoft security patch release

Microsoft has released a massive update addressing 398 security flaws, including one critical vulnerability currently being exploited in the wild.

criticalExploited VulnerabilitiesAug 11, 2026·3 min read

Flaws in Mira hormone monitor firmware and cloud systems risk account hijacking

Critical flaws in Mira hormone monitor firmware and cloud infrastructure expose users to sensitive reproductive health data theft and full account hijacking.

highExploited VulnerabilitiesAug 11, 2026·3 min read

Lazarus group exploits zero-day vulnerability for kernel-mode rootkit deployment and system privilege escalation

Microsoft's August 2026 Patch Tuesday addresses 400 vulnerabilities, including one actively exploited zero-day used by the Lazarus group to deploy kernel-mode rootkits.