Topic: zero-day attacks
-
Microsoft patches critical Office zero-day under active attack
Microsoft has urgently patched a critical, actively exploited Office vulnerability (CVE-2026-21509) that bypasses security features, requiring immediate updates to prevent system compromise. The flaw allows attackers to bypass OLE mitigations by tricking users into opening a malicious file, with ...
Read More » -
CISA Orders Agencies to Patch Critical Fortinet Flaw in 7 Days
CISA has mandated a 7-day deadline for U.S. government agencies to patch CVE-2025-58034, a critical Fortinet FortiWeb vulnerability being actively exploited in zero-day attacks. The vulnerability is an OS command injection flaw that allows authenticated attackers to execute arbitrary code with ro...
Read More » -
CISA: Ransomware gangs exploit SonicWall SMA1000 flaws
CISA has confirmed ransomware operators are actively exploiting two recently patched SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410), both added to its Known Exploited Vulnerabilities catalog with a three-day remediation mandate for federal agencies. Threat actor UTA0533 has...
Read More » -
Critical Adobe ColdFusion bug exploited in active attacks
Attackers are actively exploiting a critical Adobe ColdFusion vulnerability, CVE-2026-48282, which allows unauthenticated remote code execution on unpatched versions 2025.9, 2023.20, and earlier. Adobe released a patch on Tuesday urging immediate deployment within 72 hours, and real-world exploit...
Read More » -
Google Patches Actively Exploited Chrome Zero-Day Flaws
Google has urgently patched two actively exploited Chrome vulnerabilities (CVE-2026-3909 & CVE-2026-3910) and advises users to update immediately. The flaws involve an out-of-bounds write in the Skia graphics library and an inappropriate implementation in the V8 JavaScript engine, both posing ser...
Read More » -
Cisco ASA Zero-Day & Fortra GoAnywhere Under Active Attack
A wave of sophisticated cyberattacks is exploiting newly discovered zero-day vulnerabilities in critical enterprise infrastructure, including Cisco's ASA and Fortra's GoAnywhere, posing significant risks to organizational networks and sensitive data. Law firms are increasingly targeted by cybercr...
Read More » -
300k+ Plex Servers Still Vulnerable to Attack, Git RCE Exploited
Over 300,000 Plex Media Server systems remain vulnerable to attack due to an unpatched critical flaw, risking media libraries and personal data. Multiple sectors face active threats, including Git systems exploited for remote code execution and NetScaler devices targeted via a zero-day vulnerabil...
Read More » -
CISA Warns: VMware ESXi Flaw Actively Exploited by Ransomware
CISA warns that a critical, patched VMware ESXi vulnerability (CVE-2025-22225) is now being actively exploited by ransomware groups to escape virtual machine sandboxes. The flaw, part of a trio of zero-days, impacts a wide range of VMware products and has reportedly been used by threat actors sin...
Read More » -
CISA Mandates Urgent Patch for Actively Exploited Gogs Flaw
A critical remote code execution flaw (CVE-2025-8110) in Gogs is being actively exploited, allowing attackers to run arbitrary commands by manipulating Git configuration files. CISA has mandated all federal agencies to patch the vulnerability by February 2026, as over 1,400 public Gogs servers ar...
Read More » -
Cisco Patches Critical Zero-Day Flaw Actively Under Attack
Cisco has released critical security patches for 14 vulnerabilities in its IOS and IOS XE software, including a high-severity flaw (CVE-2025-20352) that has been actively exploited as a zero-day. The vulnerability is a stack overflow in the SNMP subsystem, affecting a wide range of devices, and c...
Read More » -
SonicWall SMA1000 Zero-Day Exploited in Active Attacks
SonicWall has issued an urgent alert for SMA1000 appliance users to apply a critical update, as active attacks exploit a new medium-severity local privilege escalation flaw (CVE-2025-40602) chained with a previously patched critical bug to achieve remote code execution with root privileges. The v...
Read More » -
Cisco Zero-Day Exploited to Plant Rootkits on Network Switches
A critical vulnerability (CVE-2025-20352) in Cisco's network operating systems allowed attackers with administrative credentials to execute remote code and install persistent Linux rootkits on switches. Attackers implanted a rootkit that sets a universal password, uses memory hooks to hide filele...
Read More » -
CISA Mandates Federal Patch for Actively Exploited Zimbra Flaw
A critical, actively exploited security flaw (CVE-2025-66376) in Zimbra's Classic UI allows attackers to hijack sessions and steal data via malicious emails, prompting an urgent federal mandate. CISA has ordered all federal agencies to patch by April 1st and strongly advises all Zimbra users to d...
Read More » -
Microsoft warns of active Defender zero-day exploits
Microsoft has issued an urgent security update for two zero-day vulnerabilities in its Microsoft Defender antivirus engine that are actively being exploited in real-world attacks. The flaws allow attackers to bypass security checks and execute malicious code or escalate privileges, marking a rare...
Read More » -
Apple Issues Critical Security Update for Older iPhones and iPads
Apple has released a critical security update for older iPhone and iPad models to patch actively exploited vulnerabilities, including those from the Coruna exploit kit, which are used for espionage and financial theft. The update addresses several critical WebKit and kernel flaws, such as CVE-202...
Read More » -
Clop Ransomware Group Claims Oracle Data Theft in New Extortion Emails
A sophisticated extortion campaign is targeting corporate executives with emails alleging data theft from Oracle E-Business Suite systems, tracked by security firms Mandiant and Google. Attackers, potentially linked to the Clop ransomware group and historically connected to FIN11, demand payment ...
Read More » -
Check Point and Wiz Partner to Unify CNAPP and Cloud Security
Check Point and Wiz have launched an integrated cloud security platform that combines prevention-first network security with CNAPP capabilities, enhancing visibility and AI-driven threat prevention. The partnership enables organizations to shift from remediation to prevention, offering real-time ...
Read More » -
Cyberattack Targets European Commission's Mobile Platform
The European Commission's mobile device management platform was breached, potentially exposing staff names and phone numbers, but the attack was contained within nine hours and did not compromise the mobile devices themselves. Evidence points to the Ivanti EPMM platform, which had a critical vuln...
Read More » -
CISA orders federal patch for exploited TrueConf Server bugs
CISA has added two actively exploited TrueConf Server vulnerabilities (CVE-2026-72529 and CVE-2026-72530) to its KEV catalog, mandating that U.S. federal agencies patch them by September 3, 2026. The critical flaws allow unauthenticated remote code execution: one via a missing authentication issu...
Read More » -
CISA Warns Active Exploits Target Critical VMware RCE Flaw
A critical security flaw (CVE-2024-37079) in VMware vCenter Server is under active exploitation, allowing remote code execution via a low-complexity attack. U.S. federal agencies are mandated to patch the vulnerability within three weeks, as there are no available workarounds, only the vendor-pro...
Read More »