Breaking CVE-2026-42945 “NGINX Rift” — 18-year heap overflow, CVSS 9.2, public PoC on GitHub • CVE-2026-45185 “Dead.Letter” — Exim CVSS 9.8 unauthenticated RCE • CVE-2026-0300 — Palo Alto PAN-OS CVSS 9.3 RCE, actively exploited • Google confirms first AI-generated zero-day used in the wild • CVE-2026-31431 “Copy Fail” — Linux kernel LPE, CISA KEV • DAEMON Tools supply chain attack — signed backdoor, 27 days undetected
Latest

Threats & Attacks

Web Server
NGINX Rift (CVE-2026-42945): An 18-Year-Old Heap Overflow With a Public Exploit

A two-pass state mismatch in NGINX’s rewrite module has gone undetected since 2008. CVSS 9.2. Public PoC on GitHub. ~34% of the internet is exposed.

May 14, 2026
Critical RCE
Dead.Letter (CVE-2026-45185): Exim CVSS 9.8 — No Login, No Config Workaround

One malformed SMTP sequence corrupts the heap and opens a shell. An autonomous AI built the full exploit in 7 days. Patch to Exim 4.99.3 immediately.

May 13, 2026
Linux Kernel
Copy Fail (CVE-2026-31431): The 9-Year Linux LPE That Gives Anyone Root in Seconds

732 bytes of Python. Root on every major Linux distro since 2017. No race condition. No disk trace. Container escape primitive. CISA KEV listed.

May 7, 2026
Supply Chain
BufferZoneCorp Sleeper Attack: Poisoned Ruby Gems & Go Modules Draining CI/CD Pipelines

A stealthy campaign used fake developer packages to steal SSH keys, AWS credentials, and GitHub tokens the moment they were installed.

May 2, 2026
Supply Chain
PyTorch Lightning Supply Chain Attack — Credential-Stealing Malware on PyPI

Threat actors compromised PyTorch Lightning on PyPI, deploying credential-stealing malware that executes automatically on import.

May 2, 2026
M&A Risk
Post-Merger Integration Security: How M&A Deals Inherit Vulnerable Systems & Shadow IT

When enterprises merge they combine attack surfaces, unpatched legacy systems, and entrenched security gaps most integration plans never address.

Apr 27, 2026
Deep Dive

Analysis & Intelligence

More

Further Coverage

The DataWater Intelligence Brief

Weekly cybersecurity analysis and CISO-level insights — no noise, no vendor pitches. Just signal.