August 26, 2026
- A forum actor is circulating target lists for two authentication-bypass flaws. DailyDarkWeb reports roughly 14,000 hosts potentially relevant to SharePoint CVE-2026-55040 and a separate list of roughly 24,000 internet-facing hosts for macOS Screen Sharing CVE-2026-65400. These are exposure claims, not proof of vulnerable versions or compromise.
· Vulnerabilities & Exploits
in Oracle WebLogic Is Under Active Attack
August 20, 2026
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
August 17, 2026
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 11, 2026
- A researcher published two working macOS Screen Sharing exploits for CVE-2026-65400. The write-up details how any network attacker can reach a Mac with Screen Sharing enabled, following last week's PoC release (calif.io, earlier coverage).
· Vulnerabilities & Exploits
in Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework
August 10, 2026
- A pre-auth RCE PoC is circulating for macOS Screen Sharing (CVE-2026-65400). Apple's fix addresses an authentication state-management bug that lets an unauthenticated network attacker reach the service without valid credentials; patched in Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 (NCSC-NL advisory). Huntress urges immediate patching and has shared detection guidance (Huntress).
· Offensive & Exploitation
in ResetNightmare PoC Drops at Black Hat: One Kerberos Flaw, Any Account's Password Reset