LIVE · cybersecurity feed
Live wire
Brevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

exploit

4 stories
linuxhigh

Public Exploits Released for Linux Kernel Root Privilege Flaws

Working exploit code has been released for four vulnerabilities in the Linux kernel that allow local users to gain administrative root access. While kernel maintainers have already issued fixes for these issues, systems running older, unpatched versions remain vulnerable. Users are advised to update their systems promptly to mitigate the risk.

cosmoscritical

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

A critical vulnerability in the Cosmos EVM module allowed attackers to drain funds from six blockchains between August 20-25, 2026. The flaw, related to balance handling in vesting accounts, was known to Cosmos Labs but initially underestimated. Despite patches being released on August 19, the exploit was successful due to a delayed and improperly handled disclosure and patching process, leading to an estimated loss of nearly $5.7 million.

CVE-2008-4128high

July 2026 CVE Landscape

In July 2026, a significant increase in high-impact vulnerabilities was observed, with 85 critical flaws identified, 36 of which had a Very Critical Recorded Future Risk Score. A notable portion of these vulnerabilities were either already listed in CISA's Known Exploited Vulnerabilities catalog or were reported by vendors. The vulnerabilities affected a wide range of products from 61 vendors, with Microsoft products being the most frequently impacted.

metasploithigh

Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more

Metasploit has released its weekly update, introducing several new modules and enhancements. Notably, a new module allows for the upgrade of SMB sessions to Meterpreter using PsExec. Additionally, the update includes an exploit for an unauthenticated remote code execution vulnerability in Peyara Remote Mouse 1.0.1 and a new command payload for LoongArch64 Linux systems. Several bug fixes and authentication support improvements for the MCP server's HTTP transport are also part of this release.