Lyrie
Live · 8568 verified advisories · 542 actively exploited

Threat intelligence that never sleeps.

Critical CVEs, active exploitation, breach forensics, and original research — every story cross-validated by 3+ primary sources before publication. Powered by the same autonomous engine that defends Lyrie.ai customers from rogue-AI and machine-speed attackers.

✓ SOC 2 Type II✓ GDPR✓ PCI DSS✓ OWASP Top 10
Lyrie Cyber Guardian
Pipeline
Autonomous · Machine-speed · Anti-rogue-AI
1445
Deep dives
Active Exploitation

CISA KEV analysis: what gets actively exploited and why

We analyzed every CVE added to CISA KEV in the last 30 days. Breakdown: 41% remote management tools 23% network perimeter devices 18% enterprise software with exposed APIs 11% AI/ML serving infrastructure That last number was 0% two years ago.

Lyrie Threat Intelligence·1 min read·1 sources verified
Coverage

Five always-on streams

How it works →
Latest

Fresh advisories

RSS →
Active Exploitation1 sources

Top bug bounty payouts in 2026: * Apple — up to $5,000,000 * Microsoft — up to $250,000 * Google Chrome — up to $250,00

Top bug bounty payouts in 2026: * Apple — up to $5,000,000 * Microsoft — up to $250,000 * Google Chrome — up to $250,000 * Google Mobile VRP — up to $300,000 * Google Cloud VRP — up to $151,515 * Google AI VRP — up to $55,000 * Meta (Facebook) — up to $300,000 * Samsung Mobile — https://t.co/6xlEnN

XHUNT-2080617742252535897·7/24/2026·1 min
Active Exploitation1 sources

Rapid reaction gets you ahead. 2 days before CISA added CVE-2026-9082 a critical SQL Injection vulnerability in Drupal

Rapid reaction gets you ahead. 2 days before CISA added CVE-2026-9082 a critical SQL Injection vulnerability in Drupal Core, to KEV, watchTowr clients were aware of their exposure. Reach out via our website if you need support. https://t.co/9yEKZfcyz2

XHUNT-2080656659144175808·7/24/2026·1 min
Active Exploitation1 sources

🚨 BREAKING NEWS | CRYPTO MARKET UPDATE – JULY 24, 2026 🔻 Crypto market extends its pullback. Total market capitalizat

🚨 BREAKING NEWS | CRYPTO MARKET UPDATE – JULY 24, 2026 🔻 Crypto market extends its pullback. Total market capitalization has fallen to around $2.3 trillion (-1.3%), while Bitcoin trades near $65,030 and Ethereum also declines. Despite the broader weakness, the DeFi sector https://t.co/J7kMduIhUp

XHUNT-2080638140537254187·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-61100 (CVSS 9.8) — oracle webcenter enterprise capture

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-61100·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-61140 (CVSS 9.8) — oracle webcenter sites

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-61140·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-60880 (CVSS 9.8) — multiple products

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-60880·7/24/2026·1 min
Breaches3 sources

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

breach-bleepingcomputer-hackers-hijack-hotel-wi-fi-dns-to-steal-·7/24/2026·1 min
AI Threats1 sources

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink mani

agent-threats-claude-code-sandbox-escape-via-git-worktree-path-mrz6rfdc·7/24/2026·1 min
Lyrie Originals5 sources

Pattern alert: 13 recent advisories converge on 0day

Lyrie Threat Intelligence identifies a thread connecting 13 recent advisories around 0day.

original-0day-mrz6rckl·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-60999 (CVSS 9.8) — multiple products

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-60999·7/24/2026·1 min
Active Exploitation1 sources

🚨 Check Point admins: Patch NOW. A critical authentication bypass, CVE-2026-16232, is being actively exploited and can

🚨 Check Point admins: Patch NOW. A critical authentication bypass, CVE-2026-16232, is being actively exploited and can let an unauthenticated attacker obtain full administrative access to SmartConsole by abusing the login process. If your Security Management or MDSM server is

XHUNT-2080522314551329215·7/24/2026·1 min
CVE Deep DivesCVSS 9.63 sources

CRITICAL: CVE-2026-16419 (CVSS 9.6) — google chrome

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-16419·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-65689 (CVSS 9.8) — multiple products

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.

CVE-2026-65689·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-65688 (CVSS 9.8) — multiple products

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.

CVE-2026-65688·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-65687 (CVSS 9.8) — multiple products

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.

CVE-2026-65687·7/24/2026·1 min
CVE Deep DivesCVSS 9.93 sources

CRITICAL: CVE-2026-61076 (CVSS 9.9) — multiple products

Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager. While the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Talent Acquisition Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVE-2026-61076·7/24/2026·1 min
CVE Deep DivesCVSS 9.93 sources

CRITICAL: CVE-2026-61072 (CVSS 9.9) — multiple products

Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office Brazil. While the vulnerability is in PeopleSoft Enterprise FIN Staffing Front Office Brazil, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVE-2026-61072·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-61065 (CVSS 9.8) — multiple products

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-61065·7/24/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-61059 (CVSS 9.1) — multiple products

Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Order Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVE-2026-61059·7/24/2026·1 min
CVE Deep DivesCVSS 9.93 sources

CRITICAL: CVE-2026-61041 (CVSS 9.9) — multiple products

Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demantra Demand Management. While the vulnerability is in Oracle Demantra Demand Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVE-2026-61041·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-60367 (CVSS 9.8) — oracle platform security for java

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-60367·7/24/2026·1 min
CVE Deep DivesCVSS 9.93 sources

CRITICAL: CVE-2026-60369 (CVSS 9.9) — oracle platform security for java

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVE-2026-60369·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-60372 (CVSS 9.8) — oracle platform security for java

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-60372·7/24/2026·1 min
CVE Deep DivesCVSS 9.63 sources

CRITICAL: CVE-2026-16424 (CVSS 9.6) — google chrome

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-16424·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-61161 (CVSS 9.8) — oracle commerce experience manager

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-61161·7/24/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-61153 (CVSS 9.1) — oracle commerce experience manager

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVE-2026-61153·7/24/2026·1 min
CVE Deep DivesCVSS 9.93 sources

CRITICAL: CVE-2026-61146 (CVSS 9.9) — oracle commerce experience manager

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVE-2026-61146·7/24/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-61145 (CVSS 9.8) — oracle commerce experience manager

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-61145·7/24/2026·1 min
Breaches3 sources

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 40

breach-securityweek-in-other-news-dolphin-x-ai-powered-malwa·7/24/2026·1 min
CVE Deep DivesCVSS 9.33 sources

CRITICAL: CVE-2026-50252 (CVSS 9.3) — nlnetlabs unbound

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (by default), it meets these conditions, making it vulnerable for DNS cache poisoning attacks. Upon startup, Unbound randomly partitions the available UDP source port space into disjoint subsets of (almost) equal size, assigning each subset to a specific worker thread. When an incoming DNS query is received, the kernel’s SO_REUSEPORT load balancing mechanism deterministically assigns the query to a socket associated with a particular thread. All outgoing DNS queries generated during the resolution of that request use source ports selected exclusively from the port subset assigned to the corresponding thread. Since these port subsets are disjoint across threads, the source port observed in a resolver’s outgoing query to an authoritative name server serves as a reliable indicator of the worker thread that processed the original client query. A malicious actor can acquire the mapping between incoming UDP source ports (for a given fixed source IP address) and Unbound worker threads and leverage it to conduct DNS cache poisoning attacks by effectively lowering the random port population per thread.

CVE-2026-50252·7/24/2026·1 min