An unauthenticated remote code execution vulnerability in Microsoft SharePoint with CVSS 8.1 was demonstrated at Pwn2Own and requires immediate attention for patch management and network segmentation.
CVE-2026-16232 is actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating an immediate threat to affected systems.
Iranian APT group Handala conducting active, disruptive attacks on ICS/PLC devices , updated Federal Advisory (July 2026) includes new detection guidance and indicators of compromise.
UK and international intelligence agencies attribute a new zero-click phishing campaign to Russian state actors, signalling escalated cyber-warfare operations against Western organisations.
Russian state-sponsored APT combines phishing with zero-click exploitation against Zimbra systems,active campaign targeting Western organizations for email theft.
Russian state-sponsored threat group 'Laundry Bear' has been exploiting Zimbra zero-day since July 2025 against Western governments and enterprises using 'half-click' phishing tactics requiring only message preview.
A successful cyberattack against a Swiss train manufacturer with active extortion demonstrates that established industrial companies in the DACH region are targeted by attackers and that extortion tactics are actively being used against critical infrastructure suppliers.
Russian APT group conducts campaign exploiting zero-click vulnerability in Zimbra Collaboration Suite to exfiltrate credentials and email archives from European organizations.
State-backed Russian APT group exploiting zero-click phishing against global webmail infrastructure; international alert underscores cyber-warfare escalation with relevance for Western critical infrastructure and supply-chain security.
CISA warns of active exploitation of another SharePoint security vulnerability (in addition to cases reported in July) and CVE-2026-16232 in Check Point SmartConsole (CVSS 9.1), without disclosing details on attack scope or attacker tactics.
PowerShell vulnerability enables remote code execution with user interaction (visiting malicious page or opening malicious file) , affects Windows Server 2019/2022 deployments.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8 upon user interaction (opening a malicious file or link).
RCE vulnerability in Adobe Acrobat Pro DC allows arbitrary code execution through visiting a malicious webpage or opening a manipulated file; immediate patching planning required.
A use-after-free in the Annots.api component enables remote code execution in Adobe Acrobat Pro DC following user interaction with a malicious file or website.
Local attackers can escalate privileges on Windows Server systems after obtaining low-privilege access, enabling internal threats and lateral movement scenarios.
Local attackers can escalate privileges on systems with Adobe Creative Cloud by exploiting an uncontrolled search path element in the AdobeUpdateService process, provided they first achieve low-privileged code execution.
XSS vulnerability in SharePoint SPFieldMultiLineText allows attackers to execute web requests with user privileges; exploitation requires user interaction (visiting a malicious page or opening a malicious file).
Local privilege escalation in Windows WMI requires prior code execution, but enables post-compromise privilege amplification in environments vulnerable to lateral movement or untrusted code execution.
Network-adjacent attackers can execute arbitrary code on Synology DiskStation DS925+ without authentication; vulnerability stems from weak password encryption in MailPlus Redis.
RCE in OpenSSL OCSP stapling verification requires user interaction (request to malicious server), but CVSS 7.5 and potential real-world exploitation make patching a priority.
A nine-year-old race condition in XFS enables local attackers to overwrite files and gain root access; the delayed disclosure suggests prior coordination with vendors.
The BSI warning regarding multiple GNU libc vulnerabilities requires verification of specific CVE numbers and KEV status for prioritizing patches on Ubuntu systems.
msaRAT leverages Chrome and Edge for C2 obfuscation and is actively deployed by the Chaos ransomware gang, potentially evading endpoint security controls.
Chaos group employs novel Rust-based RAT (msaRAT) that exclusively uses Chrome DevTools Protocol for C2 communication, bypassing traditional network-based detection.
BSI advisory on multiple critical vulnerabilities in Firefox and Thunderbird enabling arbitrary code execution, sandbox escapes, and memory corruption.
BSI security advisory alerts to multiple OpenSSL vulnerabilities without naming specific CVE numbers or version details; further information is required to determine affected versions.
BSI warning on multiple Chrome vulnerabilities with potential code execution , exact CVE numbers and CVSS scores not specified, so unclear whether already patched or still actively exploited.
The vulnerability allows locally authenticated users to gain direct root privileges without further interaction and affects Ubuntu standard installations with snap.
A widely deployed Adobe extension was exploited as an attack vector for data exfiltration , not a traditional patch issue but a design/permissions problem with abuse potential.
Microsoft's passkey implementations remain vulnerable to classical attack methods (e.g. phishing, social engineering) despite being marketed as more secure than passwords.
A vulnerability in the Adobe Acrobat extension enables attackers to spy on WhatsApp Web conversations without malware or stolen credentials,a visit to a malicious website is sufficient.
BSI warns of multiple vulnerabilities in Adobe Creative Cloud with severe impacts (privilege escalation, code execution, information disclosure); some require user interaction to exploit.
BSI warns of multiple Chrome vulnerabilities without specific CVE details, suggesting a general patch advisory; organizations should deploy Chrome updates promptly.
Chaos Ransomware uses msaRAT to route command-and-control traffic via browser APIs (Chrome DevTools Protocol) to obfuscate network indicators and evade traditional network detection.
Revoked UEFI bootloaders remain visible in trust lists for years even after revocation, enabling Secure Boot bypasses , a governance oversight with implications for firmware integrity on Windows and Linux servers.
Identity-based attacks have overtaken exploits as the leading cause of ransomware incidents, while MFA deployment alone is no longer sufficient to prevent compromise.
BSI warns of multiple unspecified vulnerabilities in Firefox enabling code execution and security bypass , user interaction via file or link opening required.
7-Zip users must be warned against opening suspicious archives, as the vulnerability requires user interaction with compromised files for exploitation.
Microsoft's disruption of the Tycoon2FA platform resulted in a 92% reduction in associated phishing volume in Q2 2026, but no single service replaced it at comparable scale , threat actors are fragmenting their infrastructure.