Attention signal

What's hot right now

The vulnerabilities security press is actually writing about — grouped by story, ranked by how many outlets are covering them and how fresh that coverage is. This measures attention, not age or severity: a critical bug nobody has written about won't appear here.

1627CVEs in the news
38Actively exploited
24Distinct stories
todayLast refreshed
The brieftoday

This week's vulnerability landscape is dominated by CISA adding five critical flaws to its Known Exploited Vulnerabilities catalog, spanning VMware vCenter, macOS, Ray, and Progress LoadMaster. Enterprise software remains the primary target, with a suspected China-nexus threat actor deploying Babuk ransomware via the vCenter flaw, while Microsoft's August Patch Tuesday addressed over 400 vulnerabilities including an actively exploited SharePoint zero-day.

1

VMware vCenter RCE exploited with ransomware

VMware Vcenter Server KEV — exploited CRITICAL 9.8

Admins must patch CVE-2026-59310 immediately — suspected China-nexus actors are deploying Babuk-derived ransomware via this flaw.

The Hacker News Dark Reading BleepingComputer Infosecurity
2

macOS Screen Sharing bug under active attack

Apple macOS KEV — exploited CRITICAL 9.8
▲ +1

Organisations with internet-exposed Macs should patch CVE-2026-65400 now — attackers are actively exploiting this for full device control.

SecurityWeek Help Net Security The Hacker News Ars Technica Security Affairs
first 4d ago · latest 2d ago
4

Progress LoadMaster flaw added to KEV

Progress Connection Manager For Objectscale KEV — exploited CRITICAL 9.8

LoadMaster customers should patch CVE-2026-8037 urgently — CISA has confirmed active exploitation in the wild.

SecurityWeek BleepingComputer The Hacker News Security Affairs
first 1mo ago · latest 1w ago
5

GitLab vulnerability allows project tampering

CRITICAL 9.4

GitLab administrators should priorit CVE-2026-19478 — while not yet exploited, the unauthenticated flaw enables public project modification or deletion.

Help Net Security The Hacker News Cybersecurity Dive Dark Reading SecurityWeek
6

Windows SharePoint zero-day exploited

Microsoft Windows 10 1607 KEV — exploited HIGH 7.0
▲ +1

SharePoint administrators must patch the authentication bypass — attackers are actively exploiting it after a public PoC release.

The Hacker News Help Net Security The Record Security Affairs SecurityWeek BleepingComputer The Register +1
first 1mo ago · latest 2d ago

Ranked by how many distinct security-news outlets are covering each vulnerability and how recent that coverage is, weighted by exploitation status (CISA KEV / EPSS) and severity. Related CVEs from a single event are grouped into one story. A CVE with no current press does not appear, however severe.