Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This vulnerability was actively exploited for weeks before a patch was released on August 1...
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE), tracked as CVE-2026-33824, is being actively exploited. This double-free memory corruption issue affects all supported versions of Windows 10, Windows 11, and Windows Server. Attackers can exploit the vu...
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that could steal GitHub tokens. The updates are crucial for protecting a wide range of Mi...
A serious vulnerability in Apple's Screen Sharing feature was disclosed, affecting macOS versions Tahoe, Sequoia, and Sonoma. The flaw, tracked as CVE-2026-65400, allows attackers on the same network to authenticate without valid credentials, potentially enabling them to view and control the user's...