LIVE · cybersecurity feed
Live wire
8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2024-39943 · Operation CameraSwarm Compromised 14,000+ Dahua CamerasCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewCVE-2026-65400 · Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapi

zeroday.news ·

The volume of high- and critical-severity vulnerability disclosures has doubled in the past year, with 8,539 recorded in Q2 2026, according to a recent industry report. This surge is intensifying pressure on security teams, who must prioritize which flaws to address immediately, often contending with a rapidly shrinking window between disclosure and exploit weaponization.

The report highlights that the gap between a patch's availability and an exploit's weaponization has collapsed to near zero. This is exacerbated by a 76% increase in newly disclosed vulnerabilities with publicly available proof-of-concept code compared to Q2 2025. This readily available code makes it easier for attackers to test and weaponize new weaknesses.

A significant concern is the prevalence of network-exploitable vulnerabilities that require no authentication or user interaction. These accounted for 62% of newly exploited vulnerabilities tracked during the quarter, representing an increase from the previous year. Such flaws offer attackers a direct route into vulnerable systems without needing credentials or user engagement.

Internet-facing devices, including VPN systems, remote access gateways, web servers, and routers, are particularly susceptible in this environment. When these devices run vulnerable software accessible from the internet, they become prime entry points for attackers. Organizations are advised to maintain accurate inventories of externally accessible systems, identify reachable vulnerabilities, and enforce authentication on exposed endpoints to mitigate this risk.

Beyond technical exploits, social engineering remains a persistent threat. Fake CAPTCHA and ClickFix techniques constituted 31.8% of observed incident response cases in Q2 2026. These tactics trick users into running malicious commands by presenting seemingly benign instructions. Attackers are also leveraging platforms like Microsoft Teams for social engineering, using familiar workplace communication channels to approach employees.

Once initial access is gained, attackers typically focus on escalating privileges and moving deeper into networks. Common techniques include credential harvesting, abusing remote management tools, and exploiting public-facing software. Ransomware continues to be a significant threat, with the United States recording 881 listed victims during the quarter, far exceeding other countries. Business services and healthcare were the most targeted sectors.

State-aligned groups are also conducting sustained campaigns. Russian-linked APT28 activity included exploiting small office and home office routers for DNS hijacking, potentially exposing authentication tokens and passwords. Iranian groups targeted industrial control and operational technology systems in the United States.

Underground markets further complicate the threat landscape, with exploit and access listings observed across 20 sources. Most vulnerabilities traded in these markets already have publicly available proof-of-concept code, and some are listed in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog. A large majority of these are also network-exploitable vulnerabilities requiring no authentication or user interaction.

Internet-facing edge appliances, such as SSL-VPN systems, RDP gateways, and web servers, remain a critical area of concern. Recommended measures include inventorying and patching these systems, rotating credentials, and enforcing multi-factor authentication on all remote-access paths. Security teams are encouraged to cross-reference vulnerability disclosure spikes with their asset inventories, prioritizing based on internet exposure, reachability, and potential network access paths, rather than treating all newly disclosed vulnerabilities with equal urgency.

vulnerabilitypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

AI is making fraud harder to spot and identity harder to prove

Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. Security measures that make consumers feel most secure (Source: Experian) Deception spreads across digital ch

security

Researchers find a loophole that lets expired credit cards make unauthorized payments

A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. The question behind the loophole “This work is motivated by documented patterns of improper expired card handling. Although

ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]