Ten Hours episode artwork

EPISODE · Jun 1, 2026

Ten Hours

from CyberPulse · host Tushar Vartak

The mean time from CVE publication to working exploit has collapsed to approximately 10 hours in 2026 — down from 56 days in 2024 and 23 days in 2025, across 3,532 CVE-exploit pairs. Google's Threat Intelligence Group confirmed it thwarted a hacker group using AI to discover a zero-day and plan a mass vulnerability exploitation operation — the first confirmed case of AI-powered coordinated mass exploitation planning. Ivanti EPMM CVE-2026-6973 was exploited as a zero-day. Palo Alto PAN-OS CVE-2026-0300 allows unauthenticated root-level RCE on firewalls through the authentication portal — active exploitation, no patch available. Dirty Frag, an unpatched Linux kernel flaw, enables root privilege escalation with public PoC. cPanel CVE-2026-41940 (max severity auth bypass) is under mass exploitation from 2,000+ attacker IPs. 84 TanStack npm package artifacts were compromised in a supply chain attack.

Episode metadata supplied by the publisher feed · Published Jun 1, 2026

Embed this episode

NOW PLAYING

Ten Hours

0:00 0:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this CyberPulse episode published?

This episode was published on June 1, 2026.

Can I download this CyberPulse episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!