Infosec Trending Feed

Daily-updated intelligence feed tracking CVEs, zero-days, exploit releases, bug bounty writeups, breach reports, red-team research, hacking tools, and real-time infosec trends from leading sources worldwide.

Updated on: 7:52 PM IST, 29 Apr 2026 (3 hour(s) ago)

Zero Day Initiative

HackerOne Hacktivity

Medium.com

GitHub: arkadiyt/bounty-targets-data

Intigriti 'BugBytes' & YesWeHack Blog

Pentest-Report.com & getdisclosed.com Aggregators

Twitter/X

  • GitHub RCE CVE-2026-3854 - Researchers identified a vulnerability where millions of GitHub repositories could be accessed via malicious git push options.
  • Chrome Zero-Day CVE-2025-3124 - Google released an emergency update for a critical zero-day vulnerability being actively exploited.
  • Microsoft Defender 0-day - Tracking a newly released, unpatched Microsoft Defender zero-day vulnerability alongside active exploitation of older Excel flaws.
  • Checkmarx Breach Exposure - Automation-driven compromise of over 766 systems in 24 hours, stealing cloud credentials and API keys.

Reddit r/netsec

Lobste.rs

  • Carrot Disclosure: Forgejo - Security disclosure regarding vulnerabilities in the Forgejo self-hosted software forge.
  • Bypassing DPI with eBPF - Technique for bypassing Deep Packet Inspection using eBPF without requiring a VPN or proxy.
  • GitHub Actions Security Risks - Analysis of why GitHub Actions is often the weakest link in a company's security posture.
  • GTFOBins Updates - New entries and updates to the curated list of Unix binaries that can be used to bypass local security restrictions.

The Hacker News

BleepingComputer

Risky Business

Dark Reading

CIO ET

NIST NVD & CVE Mitre

  • CVE-2026-7363 - Critical Use-after-free in Canvas in Google Chrome on Linux/ChromeOS allowing remote code execution.
  • CVE-2026-7361 - Critical Use-after-free in iOS in Google Chrome allowing remote exploitation of heap corruption.
  • CVE-2026-7344 - Critical Use-after-free in Accessibility in Google Chrome on Windows allowing sandbox escape.
  • CVE-2026-7343 - Critical Use-after-free in Views in Google Chrome on Windows allowing sandbox escape.
  • CVE-2026-41635 - Critical CVSS 9.8 arbitrary code execution vulnerability in Apache MINA.
  • CVE-2026-33694 - Arbitrary code execution vulnerability in Tenable Nessus and Nessus Agent on Windows.

PoC-in-GitHub & GitHub Advisories

GitHub Search (CVE-2026/2025 Created Today)

Exploit-DB & Packet Storm Security

GhostTroops/TOP (Trending Offensive Projects)

p