Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
Last-Mile Vulnerabilities: Analyzing the OnTrac Network Breach
OnTrac has confirmed a network breach occurring between March 20 and 22, 2026. This analysis explores the risks logistics companies face from evolving AI-cybersecurity threats and the necessity of robust IAM security and autonomous defense practices.
Agentic Exploitation: How 'YOLO' Mode Turned the Hermes AI Into a Cyber Threat
An analysis of how an open-source AI agent named Hermes, operating in an unattended 'YOLO' mode, automated post-exploitation tasks in an attempted breach against the Thai Ministry of Finance.
Urgent Security Update: Critical XSS Vulnerability Identified in Zimbra Classic Web Client
Investigation into a critical stored XSS vulnerability identified in the Zimbra Collaboration Suite's Classic Web Client. The flaw requires an urgent update to ZCS v10.1.19 to prevent potential unauthorized access to user session data. Reported by Google's Threat Analysis Group (TAG).
Clop Exploited Oracle Flaw to Steal Estée Lauder’s HR Data — And It’s Been Happening Since August
Estée Lauder’s year-long data breach was enabled by a zero-day in Oracle E-Business Suite, exploited by the Clop ransomware gang since August 2025 — a failure that mirrors systemic neglect across enterprise IT.
LegacyHive Zero-Day: How Nightmare Eclipse's Windows Exploit Exposes AI Cybersecurity Threats in Patch Management
A security researcher known as Nightmare Eclipse has published a proof-of-concept for LegacyHive, a Windows zero-day that escalates privileges through the User Profile Service on patched systems. The exploit, which has no CVE and no available patch, lets standard users load an administrator's registry hive—enabling code execution when the admin next logs in.
BeyondTrust Warned Customers to Patch Two Critical Security Flaws in Its Remote Support (RS) and Privileged Remote Access
BeyondTrust issued emergency patches for two critical authentication bypass flaws in Remote Support and Privileged Remote Access, with two high-severity DoS flaws. Here's why your patch calendar just got crowded—and why ignoring this is a gamble with your incident response plan.
The Exploitarium Dump: A Solo Researcher's Zero-Day Shotgun Blast
An anonymous security researcher known as bikini published working exploit code for 15 zero-day vulnerabilities across libssh2, Gitea, Splunk, and more — without warning a single vendor. Two are already under active attack.
The Tenda Backdoor Nobody Knew Existed — And Why It Matters
A hidden authentication backdoor in Tenda router firmware (CVE-2026-11405) grants admin access to anyone who knows the secret password. No patch exists. Here's what you need to know before attackers find it first.
F5 Just Patched Two NGINX Flaws That Could Let Attackers Take Over Your Servers
Emergency out-of-band updates for NGINX address critical memory corruption flaws—here’s what actually breaks if you don’t patch, and how to survive until you can.
New macOS Privilege Escalation Technique Exploits XPC Service Trust
Researchers at XM Cyber have discovered a macOS vulnerability that allows standard-privileged users to disable security tools and perform privileged operations by exploiting faulty XPC service trust validation.
How ShinyHunters Turned a PeopleSoft Zero-Day Into the Biggest University Heist of 2026
Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters against 300+ university instances.
Patch Tuesday Just Exposed How Broken Windows Security Really Is
Microsoft patched three zero-days on Tuesday—two that hand attackers SYSTEM access, one that opens BitLocker drives. But the real story is what came after: a researcher named Nightmare Eclipse kept leaking exploits because Microsoft wouldn't listen.