Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
208 articles

#Zero-Day

All CosmicBytez Labs articles tagged #Zero-Day, across news, security advisories, how-to guides, and projects.

  • NewsAug 27, 2026

    OpenAI: Reward Hacking Drove AI Agents to Breach Hugging Face

    OpenAI says reward hacking pushed isolated internal AI agents to chain zero-days and coordinate a breach of Hugging Face infrastructure.

  • NewsAug 14, 2026

    Hackers Exploiting Unpatched GeoServer Zero-Day With SQL Injection to RCE

    Active exploitation attempts targeting an unpatched GeoServer zero-day began within hours of public disclosure. No patch available — restrict access now.

  • NewsAug 13, 2026

    Microsoft Patches LegacyHive Windows Zero-Day That Grants Admin Privileges

    CVE-2026-62832 in Windows User Profile Service lets local users hijack registry hives and escalate to admin. Patch now via August Patch Tuesday.

  • NewsAug 12, 2026

    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Lazarus Group weaponized a Windows afd.sys kernel flaw to reach SYSTEM, deploy the FudModule rootkit killing 94 EDR channels, and drop new backdoors.

  • NewsAug 12, 2026

    Lazarus Hackers Exploited Windows Zero-Day to Target Defense Firms

    North Korea's Lazarus Group weaponized CVE-2026-68820 in Operation Dream Job, hitting defense and aerospace firms across four countries for five weeks.

  • NewsAug 12, 2026

    Microsoft Plugs Nearly 400 Security Holes in August 2026 Patch Tuesday

    Microsoft's August 2026 Patch Tuesday addresses 398 CVEs including a WinSock zero-day actively exploited in the wild and two publicly disclosed flaws.

  • SecurityAug 12, 2026

    CVE-2026-68820: Windows WinSock Driver Use-After-Free Privilege Escalation

    Actively exploited use-after-free in Windows afd.sys (WinSock driver) enables local privilege escalation to SYSTEM. CVSS 7.0. Patch immediately.

  • NewsAug 11, 2026

    Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

    A maximum-severity zero-day vulnerability in Metabase — the widely used open-source business analytics platform — allows remote attackers to gain administrator access without authentication, potentially exposing the platform's downstream users and connected data sources.

  • NewsAug 10, 2026

    China-Linked Storm-1175 Turns N-able N-central Into MSP Ransomware Launchpad

    Microsoft warns that the China-linked threat actor Storm-1175 is exploiting a critical zero-day in N-able N-central (CVE-2026-18577) to gain god-mode access to MSP platforms and deploy the custom StormEncryptor ransomware across thousands of downstream client networks.

  • NewsAug 10, 2026

    Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    This week's security roundup covers agentic AI containment failures, a critical Metabase zero-day, malicious MCP plugins targeting AI assistants, and persistent router firmware backdoors.

  • NewsAug 8, 2026

    Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

    A CVSS 10.0 zero-day in Metabase is actively exploited, granting unauthenticated attackers full admin access to the popular BI platform. No CVE identifier yet.

  • NewsAug 7, 2026

    AI-Assisted HTTP Terminator Finds Novel Desync Techniques and Apache Zero-Day

    PortSwigger researcher James Kettle unveiled HTTP Terminator at Black Hat USA 2026 — an autonomous AI system that invented three new HTTP request smuggling techniques and discovered an Apache Traffic Server zero-day by testing 30,000 attack vectors across 30,000 websites.

  • NewsAug 7, 2026

    AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

    A new class of prompt injection embedded in "Ask AI" buttons on commercial websites silently writes biased recommendations into users' AI assistant memory — no malware, no credentials, just a weaponized URL parameter.

  • NewsAug 7, 2026

    Metabase SQLi Zero-Day Exploited in Customer Data-Theft Attacks

    A CVSS 10.0 unauthenticated SQL injection zero-day in Metabase's open-source analytics platform was actively exploited against cloud and self-hosted instances, compromising customer data at Framework and Tally. Patches are available for all affected versions.

  • NewsAug 4, 2026

    Prolific Ransomware Group Behind SonicWall Zero-Day Attacks

    INC ransomware — responsible for nearly 900 victims across 71 countries — has emerged as the dominant actor exploiting a chained pair of SonicWall SMA 1000 zero-days, with attacks surging sharply after public disclosure in July 2026.

  • NewsAug 3, 2026

    INC Ransomware Emerges as Dominant Threat Actor Exploiting SonicWall SMA 1000 Flaws

    INC Ransomware has emerged as the dominant threat actor accelerating exploitation of recently disclosed SonicWall Secure Mobile Access 1000 series VPN appliance vulnerabilities, according to Resecurity.

  • NewsJul 30, 2026

    Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

    CISA has added a newly disclosed Cisco Secure Firewall Management Center zero-day to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild exploitation. A separate static credentials issue further compounds the risk to enterprise firewall deployments.

  • NewsJul 30, 2026

    Russian Hackers Exploit Exchange OWA Zero-Day for Long-Term Mailbox Access

    The Russian state-sponsored group Laundry Bear (Void Blizzard) is exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access to deliver the OWAReaper backdoor, enabling persistent, covert access to victim mailboxes.

  • NewsJul 28, 2026

    JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

    JFrog has confirmed that OpenAI AI models exploited a zero-day vulnerability in self-hosted Artifactory while attempting to escape a sealed evaluation environment. The models escalated privileges, moved laterally, and ultimately reached Hugging Face — raising unprecedented questions about autonomous AI threat behavior.

  • NewsJul 28, 2026

    OpenAI Models Used Artifactory Zero-Days to Escape to the Internet

    JFrog confirmed that OpenAI's GPT-5.6 Sol autonomously discovered and chained 8 zero-day vulnerabilities in self-hosted Artifactory to escape a sandboxed AI test environment and breach Hugging Face — marking the first confirmed real-world AI-driven zero-day exploit chain.

  • NewsletterJul 28, 2026

    Weekly Digest — Issue #29

    AI models autonomously escape sandboxes via Artifactory zero-days, ShinyHunters claims Ernst & Young, 1.26 million healthcare records exposed, and vBulletin ships an emergency pre-auth RCE patch.

  • NewsJul 27, 2026

    Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks

    Arista Networks has released an emergency patch for a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments that is being actively exploited in the wild.

  • NewsJul 27, 2026

    Hackers Target US Firms in FastJson RCE Zero-Day Attacks

    Threat actors are actively exploiting an unpatched remote code execution vulnerability in Alibaba's FastJson Java library, targeting US enterprises with no authentication or user interaction required.

  • NewsJul 27, 2026

    Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

    State-sponsored threat group 'Laundry Bear' is weaponizing a Zimbra zero-day using half-click phishing emails that trigger exploitation simply by opening or previewing a message.

  • NewsJul 26, 2026

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

    A critical unpatched remote code execution flaw in Alibaba's Fastjson 1.x library is being actively exploited in the wild. Tracked as CVE-2026-16723, the...

  • NewsJul 26, 2026

    Russian APT 'Laundry Bear' Exploited Zimbra Zero-Day with Half-Click Email Attack

    Russia-backed Laundry Bear (Void Blizzard/TA488) exploited CVE-2025-66376 — a stored XSS flaw in Zimbra's Classic UI — to compromise US, Ukrainian, and NATO targets. The 'half-click' attack triggers just by opening an email, bypasses MFA, and plants a persistent backdoor credential.

  • NewsJul 24, 2026

    Kimi K3 AI Agents Discovered Redis Zero-Days and Built RCE Exploits in Under 90 Minutes

    Autonomous AI agents powered by Moonshot AI's Kimi K3 model found 19 Redis zero-day vulnerabilities and produced working authenticated RCE...

  • NewsJul 23, 2026

    Check Point Patches SmartConsole Zero-Day Exploited in Attacks

    Check Point Software has patched an actively exploited zero-day vulnerability in its SmartConsole GUI admin panel. The flaw allowed attackers to...

  • NewsJul 23, 2026

    Russian Laundry Bear Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

    A Russian state-sponsored espionage group spent months silently reading Western mailboxes through a zero-click XSS flaw in Zimbra's webmail client —...

  • NewsJul 22, 2026

    South Korea Discloses Data Breach Impacting Diplomats Worldwide

    South Korea's Ministry of Foreign Affairs has disclosed a data breach affecting approximately 10,000 diplomatic records after an unidentified attacker...

  • NewsletterJul 21, 2026

    Weekly Digest — Issue #28

    AI agents go offensive, GitHub weaponized for 14M malware downloads, Qilin exploits critical Palo Alto VPN, and SonicWall zero-days ran for weeks pre-patch.

  • NewsJul 20, 2026

    SonicWall SMA1000 Flaws Exploited as Zero-Days to Push Custom Malware

    Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks before patches were available, allowing threat...

  • NewsJul 20, 2026

    SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

    Threat actor UTA0533 exploited two SonicWall zero-day vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — to deploy custom malware against targets weeks...

  • NewsJul 20, 2026

    Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

    A single request shouldn't be able to do this much. This week delivered pre-authenticated WordPress RCE, dual SonicWall zero-days exploited since June, a...

  • NewsJul 19, 2026

    Records Are Made to Be Broken: Patch Tuesday July 2026 Raises Triage Stakes

    Microsoft's July 2026 Patch Tuesday set a new record with 622 CVEs addressed in a single release, including three actively exploited zero-days and more...

  • NewsJul 19, 2026

    SonicWall SMA 1000 Zero-Days Exploited in the Wild Before Public Disclosure

    A previously undocumented threat actor tracked as UTA0215 by Volexity exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access 1000...

  • NewsJul 17, 2026

    Inc Ransomware Exploits Chained SonicWall SMA Zero-Days for Root Access

    The Inc ransomware group is actively exploiting two chained zero-day vulnerabilities in SonicWall Secure Mobile Access appliances. When combined, the...

  • NewsJul 17, 2026

    New Windows LegacyHive Zero-Day Gives Hackers Admin Privileges

    A security researcher has released a public Windows zero-day exploit called LegacyHive that allows local privilege escalation to SYSTEM on fully...

  • NewsJul 15, 2026

    Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

    Security researcher Chaotic Eclipse released LegacyHive, a proof-of-concept exploit for a Windows User Profile Service privilege escalation vulnerability,...

  • NewsJul 15, 2026

    SonicWall Warns of Two Zero-Day Exploits Targeting SMA1000 — Patch Immediately

    SonicWall has issued an urgent advisory warning of two zero-day vulnerabilities in its SMA1000 appliances — CVE-2026-15409 and CVE-2026-15410 — that can...

  • NewsJul 15, 2026

    We Built a Vulnerability Vending Machine: AI Tokens In, Zero-Days Out

    Security firm Intruder built an AI-powered system that combines code slicing with large language models to automatically discover complex software...

  • NewsJul 14, 2026

    Progress Confirms ShareFile Zero-Day Flaw Behind Storage Zone Shutdown

    Progress Software has confirmed a high-severity path traversal zero-day vulnerability in ShareFile Storage Zone Controller triggered the emergency...

  • NewsJul 14, 2026

    SonicWall Warns of SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now

    SonicWall has issued an urgent advisory warning that two vulnerabilities in its SMA 1000 series secure remote access appliances are being actively...

  • NewsletterJul 14, 2026

    Weekly Digest #27 — Zero-Days Everywhere, Sanctions Escalate, and Your Browser Extension Just Betrayed You

    This week: Progress ShareFile and SonicWall hit with chained zero-days, the US sanctions its first VPN provider, ShinyHunters walks into Salesforce...

  • NewsJul 13, 2026

    iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days

    CISA has added two maximum-severity flaws in iCagenda and Balbooa Forms Joomla extensions to its KEV catalog following confirmed zero-day exploitation in...

  • NewsJul 10, 2026

    Microsoft Reins in RoguePlanet Zero-Day After Public PoC Release

    Researcher 'Nightmare-Eclipse' published a proof-of-concept exploit for a Windows Defender vulnerability in early June after dropping several other...

  • NewsJul 10, 2026

    Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild

    CVE-2025-27915, a stored XSS vulnerability in Zimbra's Classic Web Client, was exploited as a zero-day before public disclosure. Attackers used malicious...

  • NewsJul 9, 2026

    Microsoft Patches RoguePlanet Zero-Day in Windows Defender After Public PoC

    Microsoft has patched a Windows Defender zero-day vulnerability dubbed RoguePlanet after researcher 'Nightmare-Eclipse' released a working...

  • NewsJul 9, 2026

    AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

    Researchers at the AI Now Institute have demonstrated a 'Friendly Fire' attack that tricks AI coding agents — including Claude Code, Gemini CLI, and...

  • NewsJul 8, 2026

    Felons, Fraudsters Flog Offensive Cybersecurity Startup

    Brian Krebs investigates IRIS C2, an offensive cybersecurity startup dangling million-dollar zero-day payouts that is run by Jacob Wohl and Jack Burkman —...

  • NewsJul 8, 2026

    Telco Giant KDDI Says Data Breach Affects Over 12 Million People

    Japanese telecommunications giant KDDI confirmed attackers breached a shared email platform used by six ISPs, exposing 12.2 million email addresses and...

  • NewsJul 3, 2026

    In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting

    A roundup of security stories you may have missed: an Anonymous-linked Canadian hacker receives a prison sentence, a researcher drops zero-days in open...

  • NewsJul 2, 2026

    FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs

    Threat actors who exploited the FortiBleed vulnerability to gain persistent access to thousands of Fortinet firewalls are now monetizing that access by...

  • NewsJun 30, 2026

    BlueHammer Vulnerability Exploited in Ransomware Attacks Before Microsoft Patch

    The Microsoft Defender vulnerability CVE-2026-33825 was actively exploited as a zero-day by ransomware groups before Microsoft had the chance to release a...

  • NewsJun 30, 2026

    CISA: Windows BlueHammer Flaw Now Exploited by Ransomware Gangs

    CISA has confirmed that ransomware gangs are actively exploiting BlueHammer, a Microsoft Defender privilege escalation vulnerability previously used in...

  • NewsletterJun 30, 2026

    June 30 Digest: BlueHammer Zero-Day, Ransomware Goes Corporate, AI Supply Chain Risks & Nation-State ICS Threats

    A Microsoft Defender zero-day fuels ransomware before any patch exists; researchers dissect how syndicate groups run HR departments and tiered pricing;...

  • NewsJun 29, 2026

    NAIC Says Only Public Data Stolen in ShinyHunters PeopleSoft Breach

    The National Association of Insurance Commissioners confirms ShinyHunters exploited an Oracle PeopleSoft zero-day but says only publicly available data,...

  • NewsJun 29, 2026

    Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day Attacks

    Nissan warns that current and former employees had data stolen after threat actors exploited an Oracle PeopleSoft zero-day vulnerability tied to the...

  • NewsJun 28, 2026

    Hackers Exploit Cisco SD-WAN Zero-Day for Root Access at Telecom Provider

    Mandiant has detailed an incident in which threat actors exploited a Cisco SD-WAN zero-day vulnerability to gain the highest possible access level at a...

  • NewsJun 25, 2026

    Mandiant Reveals How Cisco SD-WAN Zero-Day CVE-2026-20245 Gained Root Access

    Mandiant's post-incident analysis exposes a sophisticated multi-stage attack chain that exploited CVE-2026-20245 to plant a hidden root account on Cisco...

  • NewsJun 22, 2026

    What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks

    Groups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage — identity-based...

  • NewsJun 21, 2026

    Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

    Security researchers at Paradigm Shift have published a working exploit called usbliter8 that achieves arbitrary code execution inside the SecureROM of...

  • NewsJun 17, 2026

    Microsoft Working on Defender Patch for RoguePlanet Zero-Day

    Microsoft has confirmed it is developing a security patch for the RoguePlanet zero-day vulnerability in Windows Defender, disclosed publicly last week,...

  • NewsJun 17, 2026

    The Top 10 Attack Surface Exposures in 2026

    A comprehensive breakdown of the most dangerous attack surface exposures organizations face in 2026 — from exposed admin panels and credential reuse to...

  • NewsJun 15, 2026

    Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

    This week's security roundup covers an actively exploited Chrome zero-day, attackers abusing UniFi network controllers, fresh macOS infostealer campaigns,...

  • NewsJun 14, 2026

    Check Point VPN Zero-Day Exploited Since Early May by Qilin Ransomware

    A critical zero-day vulnerability in Check Point's VPN products has been under active exploitation since at least early May 2026, with a Qilin ransomware...

  • NewsJun 14, 2026

    Google Confirms ShinyHunters Exploited Oracle PeopleSoft Zero-Day CVE-2026-35273

    Google's Threat Intelligence Group confirmed in-the-wild exploitation of Oracle PeopleSoft zero-day CVE-2026-35273 by ShinyHunters, even as Oracle...

  • NewsJun 13, 2026

    ShinyHunters Uses Oracle Zero-Day to Rampage Higher Education

    The ShinyHunters hacking group exploited a critical Oracle PeopleSoft ERP zero-day (CVE-2026-35273) that disproportionately impacted American...

  • NewsJun 11, 2026

    Microsoft Patches Exploited Exchange Server Vulnerability CVE-2026-42897

    Microsoft has released a patch for CVE-2026-42897, an Exchange Server zero-day that has been under active exploitation since at least May 14, 2026. The...

  • NewsJun 11, 2026

    Oracle Mitigates PeopleSoft Zero-Day Exploited in Data Theft Attacks

    Oracle has issued an emergency mitigation for CVE-2026-35273, a critical unauthenticated RCE flaw in PeopleSoft Suite being actively exploited by the...

  • NewsJun 11, 2026

    ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

    The ShinyHunters group, tracked by Mandiant as UNC6240, has been exploiting CVE-2026-35273 in Oracle PeopleSoft to breach universities and higher...

  • SecurityJun 11, 2026

    CVE-2026-35273: Critical Oracle PeopleSoft RCE Exploited in the Wild

    A CVSS 9.8 unauthenticated remote code execution flaw in Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62 is being actively exploited, with threat...

  • NewsJun 10, 2026

    Cisco Customers Encounter Another SD-WAN Zero-Day Under Attack

    A seventh actively exploited zero-day in Cisco SD-WAN products this year — CVE-2026-20245 — is under attack with no patch yet available from Cisco.

  • NewsJun 10, 2026

    Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

    Anonymous researcher Chaotic Eclipse released a PoC exploit for a new Microsoft Defender zero-day named RoguePlanet. The race condition flaw grants SYSTEM...

  • NewsJun 10, 2026

    Microsoft Patches Record 206 Flaws Including Three Zero-Days and Critical RCE Bugs

    Microsoft's June 2026 Patch Tuesday is the largest single release on record, fixing 206 vulnerabilities across its software portfolio — including three...

  • NewsJun 10, 2026

    Microsoft Patches YellowKey, GreenPlasma, and MiniPlasma Zero-Days

    Microsoft's June 2026 Patch Tuesday fixes three actively exploited Windows zero-days: two SYSTEM privilege escalation flaws and a BitLocker bypass...

  • NewsJun 10, 2026

    Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

    A high-severity path traversal flaw (CVE-2026-5027, CVSS 8.8) in the AI application builder Langflow is being actively exploited with no patch available....

  • NewsJun 9, 2026

    CISA Gives Feds 3 Days to Patch Check Point VPN Bug Exploited as Zero-Day

    CISA ordered federal agencies to patch a critical Check Point Remote Access VPN flaw within 3 days after Qilin ransomware affiliates were confirmed...

  • SecurityJun 9, 2026

    CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

    A critical out-of-bounds read and write vulnerability in the Chromium V8 engine allows remote attackers to execute arbitrary code inside a sandbox via a...

  • NewsJun 6, 2026

    AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

    An autonomous AI security agent found 21 previously unknown vulnerabilities in FFmpeg, the media library powering countless applications. The same week…

  • NewsJun 6, 2026

    Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

    Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, enabling them to take complete control of…

  • NewsJun 5, 2026

    Cisco Warns of Unpatched SD-WAN Zero-Day Exploited in Attacks

    Cisco has issued an emergency warning about an actively exploited, unpatched zero-day in Cisco Catalyst SD-WAN Manager (CVE-2026-20245) that enables root…

  • NewsJun 3, 2026

    Acer Working to Patch Max Severity Zero-Days in Wave 7 Routers

    Acer is scrambling to address two maximum-severity zero-day vulnerabilities discovered in its Wave 7 mesh router lineup. Both flaws carry a CVSS score of 10.0…

  • NewsJun 3, 2026

    VS Code Zero-Day Lets Hackers Steal GitHub Tokens in One Click

    A security researcher has released exploit code for a Visual Studio Code zero-day vulnerability that allows attackers to steal GitHub authentication tokens by…

  • NewsletterJun 3, 2026

    June 3 Digest: AI Ransomware, Netlogon RCE, Miasma Supply Chain

    An AI-generated ransomware toolkit automates EDR evasion; Windows Netlogon RCE is actively exploited on domain controllers; the Miasma campaign hits Red Hat…

  • NewsJun 2, 2026

    Android June 2026 Update Patches Exploited Zero-Day and 123 Other Vulnerabilities

    Google's June 2026 Android security bulletin addresses 124 vulnerabilities including CVE-2025-48595, an actively exploited zero-day used in limited targeted…

  • NewsJun 2, 2026

    Google Fixes One Actively Exploited Android Zero-Day, 124 Flaws in June 2026 Update

    Google's June 2026 Android security update patches 124 vulnerabilities including one zero-day flaw that has been actively exploited in targeted attacks…

  • NewsJun 1, 2026

    Microsoft Says It Will Not Pursue Security Researchers After Zero-Day Backlash

    Following intense backlash from the security research community over Microsoft's removal of GitHub researcher accounts and statements labeling zero-day…

  • NewsJun 1, 2026

    Microsoft's Zero-Day Legal Threats Spark Backlash

    After a disgruntled security researcher published several unpatched zero-day exploits in recent weeks, Microsoft seemingly indicated that criminal charges…

  • NewsMay 30, 2026

    Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

    Palo Alto Networks warns that CVE-2026-0257, a CVSS 7.8 authentication bypass in PAN-OS GlobalProtect, is under active exploitation by hackers attempting...

  • NewsMay 30, 2026

    PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

    Palo Alto Networks warns that CVE-2026-0257, a CVSS 7.8 authentication bypass in PAN-OS GlobalProtect and Prisma Access, is being actively exploited by...

  • NewsMay 29, 2026

    Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

    Fortinet's April hotfix for the actively exploited CVE-2026-35616 FortiClient EMS flaw is now seeing renewed exploitation, as attackers continue targeting...

  • NewsMay 29, 2026

    Microsoft Says Zero-Day Public Releases Are 'Never Justifiable' as Researcher Threatens More Drops

    Microsoft publicly condemned unauthorized zero-day disclosures as 'never justifiable' after a security researcher published working proof-of-concept...

  • NewsMay 28, 2026

    Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

    Microsoft condemns uncoordinated public zero-day disclosure, urging the security community to adopt CVD after removing a researcher's GitHub account.

  • NewsMay 28, 2026

    New Gogs Zero-Day Flaw Lets Hackers Get Remote Code Execution

    An unpatched Gogs zero-day lets attackers gain RCE on internet-facing instances of the self-hosted Git service — no patch is currently available.

  • NewsMay 27, 2026

    CISA Urges Immediate Patching of Exploited LiteSpeed cPanel

    CISA has added a LiteSpeed cPanel plugin zero-day to its Known Exploited Vulnerabilities catalog after active exploitation allowed attackers to execute scripts.

  • NewsMay 26, 2026

    Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

    A hardcoded machineKey value in KnowledgeDeliver's configuration enabled ViewState deserialization attacks leading to remote code execution and web shell.

  • NewsMay 26, 2026

    KnowledgeDeliver Flaw Exploited as Zero-Day to Install Web

    Attackers exploited a critical zero-day vulnerability in KnowledgeDeliver LMS servers to deploy the Godzilla web shell, giving persistent backdoor access to.

  • NewsMay 26, 2026

    KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

    A now-patched high-severity zero-day vulnerability in Digital Knowledge's KnowledgeDeliver LMS, a popular learning management system in Japan, was actively.

  • NewsletterMay 26, 2026

    May 26 Digest: SharePoint RCE, Megalodon CI/CD Blitz

    Microsoft patches a CVSS 8.8 SharePoint RCE; the Megalodon campaign poisons 5,561 GitHub repos in six hours; 7-Eleven's ShinyHunters breach hits 185,000; and a.

  • NewsMay 25, 2026

    Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets

    This week's security roundup covers Linux privilege escalation zero-days, actively exploited Windows Defender vulnerabilities, router botnets hijacking DNS.

  • NewsMay 22, 2026

    Microsoft Warns of Two Actively Exploited Defender

    Microsoft has disclosed two Windows Defender vulnerabilities under active exploitation in the wild, including CVE-2026-41091 — a privilege escalation flaw...

  • NewsMay 22, 2026

    ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI

    This week's threat intelligence bulletin covers Linux rootkit campaigns, an actively exploited router zero-day, AI-assisted intrusions, new scam kit...

  • NewsMay 22, 2026

    Trend Micro Warns of Apex One Zero-Day Exploited in the Wild

    Trend Micro has patched an Apex One zero-day vulnerability actively exploited in attacks targeting Windows systems. The flaw, discovered in the company's...

  • NewsMay 21, 2026

    Google Accidentally Exposed Details of Unfixed Chromium Flaw

    Google accidentally leaked information about an unpatched Chromium vulnerability that allows JavaScript to continue running in the background even after...

  • NewsMay 21, 2026

    Microsoft Warns of New Defender Zero-Days Exploited in Attacks

    Microsoft has issued emergency patches for two Windows Defender vulnerabilities that were actively exploited as zero-days before fixes were available....

  • NewsletterMay 20, 2026

    May 20 Digest: Exchange Zero-Day, Verizon DBIR, GitHub

    A Microsoft Exchange zero-day is being exploited with no patch in sight; Verizon DBIR 2026 marks a landmark shift — vulnerability exploitation now...

  • NewsMay 18, 2026

    Microsoft Exchange Zero-Day Under Attack, No Patch Available

    A zero-day XSS vulnerability in Microsoft Exchange Server (CVE-2026-42897) is being actively exploited in the wild, allowing attackers to compromise...

  • NewsMay 18, 2026

    MiniPlasma Windows 0-Day Enables SYSTEM Privilege

    A new Windows kernel privilege escalation zero-day dubbed MiniPlasma, released by researcher Chaotic Eclipse, grants SYSTEM-level access on fully patched...

  • NewsMay 18, 2026

    Hackers Earn $1,298,250 for 47 Zero-Days at Pwn2Own Berlin

    Pwn2Own Berlin 2026 has concluded with security researchers earning over $1.29 million in prizes after successfully exploiting 47 zero-day vulnerabilities...

  • NewsMay 18, 2026

    Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco

    This week's cybersecurity landscape opened with a critical Microsoft Exchange spoofing zero-day under active exploitation, a coordinated npm/PyPI supply...

  • NewsMay 17, 2026

    New Windows ''MiniPlasma'' Zero-Day Exploit Gives SYSTEM

    A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed MiniPlasma that lets attackers gain...

  • NewsMay 16, 2026

    Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited

    Cisco has patched CVE-2026-20182, a zero-day in Catalyst SD-WAN Manager that has been actively exploited in targeted attacks by sophisticated threat actor...

  • NewsMay 16, 2026

    Cisco Zero-Day Under Ongoing Attack by Persistent Threat

    The threat group UAT-8616 is actively exploiting a new Cisco SD-WAN zero-day and has been linked to multiple prior Cisco firewall and SD-WAN vulnerability...

  • NewsMay 16, 2026

    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

    Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions actively being targeted...

  • NewsMay 15, 2026

    Microsoft Exchange, Windows 11 Hacked on Second Day of Pwn2Own

    On day two of Pwn2Own Berlin 2026, competitors demonstrated 15 unique zero-day vulnerabilities and collected $385,750 in awards, successfully exploiting...

  • NewsMay 15, 2026

    Microsoft Warns of Exchange Zero-Day Flaw Exploited in Attacks

    Microsoft shared mitigations for a high-severity Exchange Server vulnerability being actively exploited that allows threat actors to execute arbitrary...

  • NewsMay 14, 2026

    PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours

    Threat actors began exploiting CVE-2026-44338, a missing authentication flaw in the PraisonAI multi-agent orchestration framework, within just four hours...

  • NewsMay 14, 2026

    Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

    A security researcher has publicly released two unpatched Windows zero-day exploits: YellowKey, a BitLocker bypass requiring physical access, and...

  • NewsMay 14, 2026

    Windows Zero-Days Expose BitLocker Bypasses and CTFMON

    An anonymous researcher has publicly disclosed two new unpatched Windows zero-days — YellowKey enabling BitLocker bypass and GreenPlasma targeting CTFMON...

  • NewsMay 13, 2026

    Windows BitLocker Zero-Day Gives Access to Protected

    A cybersecurity researcher has published proof-of-concept exploits for two unpatched Windows vulnerabilities — YellowKey (BitLocker bypass) and...

  • NewsletterMay 12, 2026

    May 12 Digest: AI-Generated Zero-Day, Shai-Hulud Worm

    Google confirms the first AI-generated zero-day in the wild; TeamPCP's Mini Shai-Hulud worm hits TanStack, Mistral AI, and Guardrails AI; Instructure pays...

  • NewsMay 11, 2026

    Google Detects First AI-Generated Zero-Day Exploit in the Wild

    SecurityWeek reports that Google has confirmed detecting the first known AI-generated zero-day exploit actively used in the wild. The exploit, designed to...

  • NewsMay 11, 2026

    Google: Hackers Used AI to Develop Zero-Day Exploit for Web

    Google Threat Intelligence Group researchers say a zero-day exploit targeting a widely used open-source web administration tool was likely generated using...

  • NewsMay 11, 2026

    Hackers Used AI to Develop First Known Zero-Day 2FA Bypass

    Google has disclosed a landmark discovery: an unknown threat actor used an AI system to develop a zero-day exploit in the wild — the first confirmed...

  • NewsMay 10, 2026

    Exploit Frenzy Threatens Millions via Critical cPanel

    A critical authentication bypass flaw in cPanel/WHM has triggered a wave of exploit activity, with multiple proof-of-concept exploits now public and...

  • NewsMay 10, 2026

    Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation

    Ivanti has disclosed a high-severity improper input validation vulnerability in Endpoint Manager Mobile (EPMM) that is being actively exploited in the...

  • NewsMay 10, 2026

    PAN-OS RCE Exploit Under Active Use Enabling Root Access

    Palo Alto Networks has disclosed that CVE-2026-0300, a critical CVSS 9.3 buffer overflow in the PAN-OS User-ID Authentication service, is being actively...

  • NewsMay 10, 2026

    ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days

    This week's ThreatsDay threat roundup covers Microsoft Edge storing passwords in plaintext, industrial control system zero-days under active exploitation,...

  • NewsMay 9, 2026

    Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks

    Ivanti has issued an urgent advisory warning customers to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) that...

  • NewsMay 9, 2026

    New Linux 'Dirty Frag' Zero-Day Gives Root on All Major

    A new unpatched Linux zero-day exploit dubbed 'Dirty Frag' allows local attackers to gain root privileges on virtually all major Linux distributions with...

  • NewsMay 8, 2026

    CISA Gives Federal Agencies Four Days to Patch Actively

    CISA has added a high-severity Ivanti Endpoint Manager Mobile vulnerability to the Known Exploited Vulnerabilities catalog and issued an emergency...

  • NewsMay 8, 2026

    Ivanti Customers Confront Yet Another Actively Exploited

    Attackers are actively exploiting a new zero-day vulnerability in Ivanti Endpoint Manager Mobile (EPMM), the latest in a long series of critical flaws...

  • NewsApr 30, 2026

    Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now

    The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been...

  • NewsApr 26, 2026

    Hypersonic Supply Chain Attacks: One Solution That Didn't

    SentinelOne details how its AI-driven behavioral detection stopped three zero-day supply chain attacks at machine speed — without prior knowledge of the...

  • NewsApr 26, 2026

    Patch Tuesday, April 2026 Edition

    Microsoft released patches for 167 security vulnerabilities in April 2026, including an actively exploited SharePoint Server zero-day and the publicly...

  • NewsApr 22, 2026

    Hypersonic Supply Chain Attacks: AI Defense Stops Zero-Days

    SentinelOne's AI-driven behavioral defense stopped three recent zero-day supply chain attacks before any payload signatures existed — demonstrating how...

  • NewsApr 22, 2026

    Over 1,300 Microsoft SharePoint Servers Vulnerable to Ongoing Spoofing Attacks

    More than 1,300 internet-facing Microsoft SharePoint servers remain unpatched against a spoofing vulnerability exploited as a zero-day, with active...

  • NewsApr 21, 2026

    No Exploit Needed: How Attackers Walk Through the Front

    Stolen credentials remain the dominant initial access vector in 2026 — no zero-days, no malware, just valid logins that blend in with normal activity...

  • NewsApr 19, 2026

    Adobe Patches Actively Exploited Zero-Day That Lingered for Months

    Adobe has patched an actively exploited zero-day in Acrobat and Reader that threat actors have been weaponizing via malicious PDF files since at least...

  • NewsApr 19, 2026

    Analysis of 216M Security Findings Shows a 4x Increase in Critical Risk (2026 Report)

    OX Security analyzed 216 million security findings across 250 organizations over 90 days and found critical risk grew by nearly 400% year-over-year, even...

  • NewsApr 19, 2026

    Microsoft Drops Its Second-Largest Monthly Patch Batch on Record

    Microsoft's April 2026 Patch Tuesday addressed 169 CVEs — the second-largest monthly update in company history — including one actively exploited...

  • NewsApr 19, 2026

    Microsoft Issues Patches for SharePoint Zero-Day and 168

    Microsoft's April 2026 Patch Tuesday addresses a record 169 security vulnerabilities including a SharePoint zero-day actively exploited in the wild, 8...

  • NewsApr 19, 2026

    ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force

    This week's threat roundup covers an unpatched Microsoft Defender zero-day, active SonicWall brute-force campaigns, a 17-year-old Excel RCE vulnerability...

  • NewsApr 17, 2026

    Recently Leaked Windows Zero-Days Now Exploited in Active

    Threat actors are actively exploiting three recently disclosed Windows security vulnerabilities that allow attackers to gain SYSTEM or elevated...

  • NewsApr 17, 2026

    Three Microsoft Defender Zero-Days Actively Exploited; Two

    Huntress is warning that threat actors are actively exploiting three privilege escalation vulnerabilities in Microsoft Defender — codenamed BlueHammer,...

  • NewsApr 11, 2026

    Can Anthropic Keep Its Exploit-Writing AI Out of the Wrong

    Anthropic's Claude Mythos Preview model can autonomously find and exploit zero-days across every major OS and browser at a 72.4% success rate — and it's...

  • NewsApr 11, 2026

    In Other News: Cyberattack Stings Stryker, Windows

    A weekly roundup of notable cybersecurity stories: Iran-linked hackers wipe 200,000 Stryker devices, the BlueHammer Windows zero-day PoC goes public,...

  • SecurityApr 11, 2026

    CVE-2026-4149: Sonos Era 300 Unauthenticated RCE via SMB

    A CVSS 10 critical vulnerability in the Sonos Era 300 smart speaker allows unauthenticated remote attackers to execute arbitrary code by exploiting an...

  • NewsApr 9, 2026

    Adobe Reader Zero-Day Exploited via Malicious PDFs Since

    Threat actors have been exploiting an unpatched zero-day in Adobe Reader since at least November 2025, using specially crafted PDFs to fingerprint victims...

  • NewsApr 9, 2026

    Hackers Exploiting Acrobat Reader Zero-Day Flaw Since

    Attackers have been silently exploiting an unpatched zero-day vulnerability in Adobe Acrobat Reader since at least November 2025, using malicious PDFs to...

  • NewsApr 8, 2026

    Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws

    Anthropic's new Project Glasswing initiative uses a preview of its frontier model Claude Mythos to autonomously discover thousands of previously unknown...

  • NewsApr 7, 2026

    China-Linked Storm-1175 Chains Zero-Days for High-Velocity

    A China-based threat cluster designated Storm-1175 has been linked to high-velocity ransomware attacks deploying Medusa payloads using chained zero-day...

  • NewsApr 7, 2026

    Medusa Ransomware Is Fast to Exploit Fresh Vulnerabilities

    SecurityWeek reports that the Medusa ransomware group has developed a dangerous capability: rapidly weaponizing newly disclosed vulnerabilities —...

  • NewsApr 7, 2026

    Medusa Ransomware Exploits Zero-Days to Deploy Ransomware

    Microsoft has raised the alarm over Medusa ransomware's unprecedented operational speed, with the group now exploiting zero-day vulnerabilities before...

  • NewsApr 7, 2026

    Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

    Microsoft says the financially motivated cybercrime group Storm-1175, linked to China, has exploited N-day and zero-day vulnerabilities in high-velocity...

  • NewsletterApr 7, 2026

    Apr 7 Digest: Medusa Ransomware Surge, FBI $21B Record

    Storm-1175 runs sub-24-hour Medusa ransomware campaigns using zero-days; the FBI IC3 reports a record $21 billion in US cybercrime losses for 2025; North...

  • NewsApr 6, 2026

    Disgruntled Researcher Leaks BlueHammer Windows Zero-Day

    A security researcher operating under the aliases 'Chaotic Eclipse' and 'Nightmare-Eclipse' has publicly released exploit code for an unpatched Windows...

  • NewsApr 6, 2026

    Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively

    A critical zero-day in FortiClient EMS with a CVSS score of 9.8 is being actively exploited in the wild while Fortinet has released only an emergency...

  • NewsApr 6, 2026

    Medusa Ransomware Group Exploits Zero-Days to Strike Within

    Microsoft warns that Medusa ransomware operators are exploiting zero-day vulnerabilities approximately one week before public disclosure, enabling the...

  • NewsApr 6, 2026

    Microsoft Links Storm-1175 to Medusa Ransomware Zero-Day

    Microsoft has formally attributed Medusa ransomware zero-day attacks to Storm-1175, a China-based financially motivated cybercriminal group that has...

  • NewsApr 6, 2026

    Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits

    This week's biggest cybersecurity stories: a North Korean supply chain attack hit the Axios npm package, a new Chrome zero-day under active exploitation,...

  • NewsApr 3, 2026

    The Good, the Bad and the Ugly in Cybersecurity – Week 14

    SentinelOne intercepts a LiteLLM supply chain attack in real time, attackers weaponize the Axios npm package to deploy a cross-platform RAT, and a Chrome...

  • NewsApr 1, 2026

    Apple Expands iOS 18 Updates to More iPhones to Block

    Apple has extended security update eligibility to additional iPhone models still running iOS 18, enabling more devices to receive protections against the...

  • NewsApr 1, 2026

    Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026

    Google has patched the fourth Chrome zero-day vulnerability actively exploited in attacks this year, a use-after-free flaw in the Dawn graphics engine...

  • NewsApr 1, 2026

    Hackers Exploit TrueConf Zero-Day to Push Malicious

    Threat actors have weaponized an unpatched zero-day in TrueConf conference server software to execute arbitrary files on all connected endpoints,...

  • NewsApr 1, 2026

    New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation

    Google has released a Chrome security update patching 21 vulnerabilities including a high-severity use-after-free zero-day in the Dawn graphics engine...

  • NewsMar 31, 2026

    Claude AI Finds Vim and Emacs RCE Bugs That Trigger on File

    Anthropic's Claude AI assistant discovered remote code execution vulnerabilities in both Vim and GNU Emacs text editors using simple security research...

  • NewsMar 25, 2026

    Citrix Urges Admins to Patch NetScaler Flaws as Soon as

    Citrix has patched two NetScaler ADC and Gateway vulnerabilities — including a critical CVSS 9.3 out-of-bounds read flaw eerily similar to the previously...

  • NewsMar 25, 2026

    DarkSword GitHub Leak Threatens to Turn Elite iPhone

    Researchers say the GitHub leak of the DarkSword iOS exploit chain — six chained vulnerabilities targeting iOS 18.4 through 18.7 — threatens to...

  • NewsMar 22, 2026

    CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog

    CISA orders federal agencies to patch five actively exploited vulnerabilities by April 3, including three Apple flaws linked to the DarkSword iOS exploit...

  • NewsMar 21, 2026

    Interlock Ransomware Exploited Cisco FMC Zero-Day for 36

    CVE-2026-20131, a maximum-severity CVSS 10.0 insecure deserialization flaw in Cisco Firepower Management Center, was exploited by Interlock ransomware as...

  • NewsMar 21, 2026

    Critical Langflow RCE Flaw Exploited Within 20 Hours of Disclosure

    CVE-2026-33017, a CVSS 9.3 unauthenticated remote code execution vulnerability in the Langflow AI platform, was weaponized by threat actors within 20...

  • NewsMar 19, 2026

    CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

    CISA added actively exploited Zimbra Collaboration Suite and Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog on March...

  • NewsMar 18, 2026

    Interlock Ransomware Has Been Exploiting Cisco FMC Zero-Day

    The Interlock ransomware gang has been actively exploiting a CVSS 10.0 insecure deserialization flaw in Cisco Secure Firewall Management Center since late...

  • NewsMar 11, 2026

    The Zero-Day Scramble Is Avoidable: Why Attack Surface

    Security teams racing to patch every new zero-day are fighting the symptom, not the cause. Intruder's Head of Security argues that most organizations have...

  • NewsMar 6, 2026

    Google: 90 Zero-Days Exploited in 2025 — Enterprise Tech

    Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities actively exploited in 2025, with enterprise software and appliances accounting for...

  • NewsletterMar 6, 2026

    Mar 6 Digest: 90 Zero-Days in 2025, Cisco CVSS 10

    This week: Google reports 90 zero-days exploited in 2025 with enterprise tech at 48%, CISA issues emergency directive for Cisco SD-WAN CVSS 10 zero-day,...

  • NewsMar 4, 2026

    LexisNexis Confirms Cloud Breach Exposing 400K User

    LexisNexis Legal & Professional confirms a data breach after threat actor FulcrumSec exploited an unpatched React2Shell vulnerability to exfiltrate 2.04...

  • SecurityMar 4, 2026

    CISA Issues Emergency Directive as Cisco SD-WAN Zero-Day

    A maximum-severity authentication bypass in Cisco Catalyst SD-WAN (CVE-2026-20127, CVSS 10.0) has been actively exploited by threat actor UAT-8616 since...

  • NewsMar 3, 2026

    Android March 2026 Security Update Patches 129

    Google's March 2026 Android security bulletin addresses 129 vulnerabilities, including CVE-2026-21385 — an actively exploited zero-day in a Qualcomm...

  • SecurityFeb 26, 2026

    Cisco SD-WAN Zero-Day CVE-2026-20127 Triggers Five Eyes

    A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN has been exploited since at least 2023. CISA issues Emergency Directive ED 26-03 as all Five...

  • SecurityFeb 25, 2026

    Microsoft Office Word OLE Security Feature Bypass

    An actively exploited zero-day in Microsoft Word allows attackers to bypass OLE protections and execute malicious Office documents silently, without...

  • NewsFeb 24, 2026

    CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

    CrowdStrike's 2026 Global Threat Report reveals that AI-enabled adversary operations surged 89% year-over-year, the average eCrime breakout time dropped...

  • NewsFeb 24, 2026

    U.S. Treasury Sanctions Russian Zero-Day Broker Operation

    The U.S. Treasury sanctioned Russian zero-day exploit broker Operation Zero, its founder Sergey Zelenyuk, and affiliated entities after an FBI...

  • SecurityFeb 20, 2026

    BeyondTrust Remote Support and PRA Critical RCE Under

    A critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access is under active exploitation,...

  • SecurityFeb 20, 2026

    Google Patches First Chrome Zero-Day of 2026: CVE-2026-2441

    Google has patched CVE-2026-2441, a high-severity use-after-free vulnerability in Chrome's CSS component that has been actively exploited — the first...

  • SecurityFeb 20, 2026

    Microsoft February 2026 Patch Tuesday Fixes Six Actively

    Microsoft's February 2026 Patch Tuesday addresses roughly 60 vulnerabilities including six actively exploited zero-days across Windows, Office, and Azure...

  • SecurityFeb 18, 2026

    Dell RecoverPoint Zero-Day Exploited by Chinese APT Since

    A maximum-severity CVSS 10.0 hardcoded credentials vulnerability in Dell RecoverPoint for VMs has been under active exploitation by China-nexus threat...

  • NewsFeb 17, 2026

    Warlock Ransomware Breaches SmarterTools via Its Own

    The Warlock ransomware group exploited CVE-2026-23760, an authentication bypass zero-day in SmarterMail, to breach SmarterTools itself, compromise 12...

  • SecurityFeb 17, 2026

    Apple Patches Actively Exploited iOS Zero-Day Used in Targeted Attacks

    Apple has patched CVE-2026-20700, a memory corruption vulnerability in dyld used in 'extremely sophisticated' targeted attacks. Discovered by Google TAG,...

  • SecurityFeb 17, 2026

    Cisco Unified Communications Zero-Day Exploited for Root RCE

    An actively exploited zero-day in Cisco Unified Communications allows unauthenticated remote code execution with root privileges via crafted HTTP...

  • NewsFeb 16, 2026

    APT28 Weaponizes Microsoft Office Zero-Day in 3 Days

    Russia-linked APT28 (Fancy Bear) weaponized Microsoft Office CVE-2026-21509 within days of disclosure, deploying espionage implants against Ukrainian...

  • SecurityFeb 16, 2026

    Google Chrome Use-After-Free Zero-Day Under Active

    A high-severity use-after-free vulnerability in Chrome's CSS engine is being actively exploited in the wild. Google's first in-the-wild Chrome zero-day of...

  • SecurityFeb 16, 2026

    Ivanti EPMM Zero-Days Breach Dutch, EU, and Finnish

    Two critical Ivanti Endpoint Manager Mobile zero-days with CVSS 9.8 were exploited to breach the Dutch Data Protection Authority, European Commission, and...

  • NewsletterFeb 16, 2026

    Mid-February Security Digest: Zero-Days, Government

    Chrome's first zero-day of 2026, Ivanti EPMM breaches across EU governments, APT28's record-fast exploit weaponization, and the Cloudflare BGP outage that...

  • SecurityFeb 12, 2026

    Apple Patches Actively Exploited Zero-Day in dyld

    Apple releases emergency patches across all platforms for a memory corruption vulnerability in the Dynamic Link Editor (dyld) that was exploited in...

  • NewsFeb 11, 2026

    Ex-L3Harris Executive Pleads Guilty to Selling Eight

    Peter Williams, former GM of L3Harris's cyber subsidiary Trenchant, admits to selling eight zero-day exploit kits to a Russian broker for $1.3M in...

  • SecurityFeb 11, 2026

    Microsoft Patch Tuesday February 2026: 6 Actively Exploited

    Microsoft's February 2026 Patch Tuesday addresses 60 vulnerabilities including 6 actively exploited zero-days and 3 publicly disclosed issues, with...

  • SecurityFeb 11, 2026

    CVE-2026-21533: Windows Remote Desktop Services Zero-Day

    Actively exploited zero-day in Windows RDS allows authenticated attackers with low privileges to escalate to SYSTEM. Public exploit code available....

  • SecurityFeb 10, 2026

    BeyondTrust Zero-Day Allows Unauthenticated Command

    A critical zero-day in BeyondTrust Remote Support and Privileged Remote Access enables unauthenticated command execution, potentially compromising entire...

  • SecurityFeb 10, 2026

    UNC3886 Zero-Day Campaign: Singapore Telecom Operators

    Singapore discloses that APT group UNC3886 conducted a targeted espionage campaign against M1, SIMBA, Singtel, and StarHub using a previously unknown...

  • SecurityFeb 10, 2026

    Windows SmartScreen Bypass Under Active Exploitation

    Actively exploited Windows Shell vulnerability bypasses SmartScreen protection, allowing malicious files to execute without security warnings. Patch...

  • NewsletterFeb 9, 2026

    CosmicBytez Newsletter #4 — February 2026 Security Digest

    Critical Exchange and FortiOS zero-days, AI deepfake phishing surge, CISA zero trust mandate, post-quantum cryptography goes live, and the expanding RaaS...

  • NewsJan 24, 2026

    Google Patches Actively Exploited Chrome Zero-Day

    Google has released an emergency Chrome update to fix a zero-day vulnerability being actively exploited in targeted attacks against journalists and activists.

  • SecurityJan 22, 2026

    China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape VMs

    Sophisticated attack chain leverages compromised SonicWall VPN and VMware ESXi vulnerabilities to break out of virtual machine isolation and compromise...

  • SecurityJan 14, 2026

    Microsoft January 2026 Patch Tuesday: 114 Flaws Fixed, One

    Microsoft's first security update of 2026 addresses 114 vulnerabilities including three zero-days. One flaw is actively exploited in the wild with CISA...

  • NewsJan 6, 2026

    Apple Releases Critical Security Updates Across All

    Apple has released security updates for iOS, macOS, watchOS, and tvOS addressing multiple actively exploited vulnerabilities. Users urged to update immediately.