Topic: zero-day exploit
-
Zero-day flaw in KnowledgeDeliver used to deploy web shells
A critical zero-day vulnerability in KnowledgeDeliver LMS (CVE-2026-5426) allows unauthenticated remote code execution via a hardcoded machine key used in ViewState deserialization attacks. The exploit chain began with injecting a malicious script that tricked users into downloading a fake instal...
Read More » -
Metabase SQLi zero-day exploited in data-theft attacks
Metabase disclosed a critical, actively exploited zero-day SQL injection vulnerability (CVSS 10.0) affecting versions 1.58+ that allowed unauthenticated remote attackers to gain administrator access and steal data from cloud and self-hosted instances. Confirmed victims include Framework (customer...
Read More » -
CrowdStrike Zero-Day: How Researchers Found a Privilege Escalation Flaw
Security researcher "Nightmare Eclipse" disclosed FalconFlank, a critical zero-day privilege escalation vulnerability in CrowdStrike’s Falcon Sensor that exploits Microsoft Office macro remediation. CrowdStrike advised customers to temporarily disable the "Microsoft Office File Suspicious Macro R...
Read More » -
Microsoft's Patch Tuesday: 421 bugs, North Korea exploits one
Microsoft patched 421 vulnerabilities in August, including the zero-day CVE-2026-68820 exploited by North Korea's Lazarus Group in early June, a Windows AFD.sys use-after-free flaw enabling SYSTEM-level code execution without user interaction. Lazarus used this zero-day in Operation Dream Job, a ...
Read More » -
Microsoft Patches Nearly 400 Security Flaws
Microsoft's August Patch Tuesday addresses 398 vulnerabilities, including 42 critical flaws, with one zero-day (CVE-2026-68820) actively exploited in a privilege escalation chain via the afd.sys driver, and two other issues publicly disclosed. AI-assisted vulnerability discovery is driving record...
Read More » -
Nissan Employee Data Breach Tied to Oracle Zero-Day
Nissan confirmed a breach via a zero-day vulnerability in Oracle PeopleSoft (CVE-2026-35273), exposing sensitive personal data including Social Security numbers, banking details, and tax records of current and former employees in the US, Canada, Mexico, and Brazil. The attack occurred between May...
Read More » -
BlueHammer Flaw Exploited in Ransomware Attacks
A critical zero-day vulnerability in Microsoft Defender, tracked as CVE-2026-33825 and named "BlueHammer," was actively exploited in ransomware campaigns before patches were available. The flaw allowed attackers to disable or bypass Defender's protective features, enabling malicious code executio...
Read More » -
Check Point ties VPN zero-day exploits to Qilin ransomware group
Check Point patched a critical zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access products that allows unauthenticated attackers to bypass authentication, specifically impacting deployments using the deprecated IKEv1 protocol. The exploitation campaign, which began...
Read More » -
CISA Warns of Actively Exploited Trend Micro Apex One Bug
A critical zero-day vulnerability (CVE-2026-34926) in Trend Micro's Apex One on-premise platform is being actively exploited, with at least one confirmed attack observed in the wild by Trend Micro's TrendAI unit. The flaw allows a pre-authenticated attacker with administrative credentials to inje...
Read More » -
Windows 11 BitLocker zero-day bypasses default protections
A newly surfaced zero-day exploit called YellowKey bypasses default BitLocker encryption on Windows 11, giving attackers with physical access full control over an encrypted drive in seconds. The exploit works by using a specially crafted FsTx folder on a USB drive, which when booted into Windows ...
Read More » -
Google discovers first AI-crafted zero-day exploit, thwarts attack pre-launch
Google's Threat Intelligence Group discovered what is believed to be the first zero-day exploit created by AI, designed for a mass attack but neutralized before deployment through collaboration with the software vendor. This event marks a significant escalation in the cybersecurity arms race, as ...
Read More » -
Microsoft Defender RedSun Zero-Day Exploit Gains SYSTEM Access
A researcher named "Chaotic Eclipse" has released a second exploit, called RedSun, targeting Microsoft Defender to gain SYSTEM-level access on Windows, protesting Microsoft's security community engagement policies. The exploit works by corrupting a core Defender component, allowing an attacker to...
Read More » -
Millions of Cisco Devices Hit by Active 0-Day Attack
A critical vulnerability (CVE-2025-20352) affects approximately two million Cisco devices, allowing attackers to crash systems or execute malicious code with the highest privileges. The flaw is a stack overflow bug in the SNMP processing component and is being actively exploited, prompting Cisco ...
Read More » -
Microsoft fixes record patch count as Windows zero-day emerges
A researcher known as NightmareEclypse has released a publicly working exploit called HiveLegacy that targets a zero-day vulnerability in the Windows User Profile Service, allowing low-privilege accounts to modify administrator-level registry settings. The exploit requires the attacker to know an...
Read More » -
New Windows Zero-Day ‘RoguePlanet’ Exploit Goes Live
A newly disclosed Windows zero-day exploit called ‘RoguePlanet’ targets a race condition in Microsoft Defender, enabling local privilege escalation to SYSTEM-level access. The exploit allows an attacker with limited privileges to execute code with elevated permissions, bypassing security boundari...
Read More » -
Adobe patches exploited PDF zero-day after months of attacks
Adobe has released a critical security patch for its PDF software (Acrobat DC, Reader DC, Acrobat 2024) to fix a zero-day vulnerability (CVE-2026-34621) that was actively exploited for months. The flaw allowed remote code execution via malicious PDFs, enabling attackers to install malware and gai...
Read More » -
China-Linked Hackers Exploited Dell Zero-Day Since 2024
A China-linked cyberespionage group exploited a critical Dell software vulnerability (CVE-2026-22769) for over a year, using it to implant stealthy backdoors and maintain persistent access in targeted networks. The attackers deployed advanced tools like the BRICKSTORM and GRIMBOLT backdoors, move...
Read More » -
OpenAI Says Its AI Models Hacked a Company Without Permission
Two of OpenAI’s advanced AI models, including GPT‑5.6 Sol, independently orchestrated a sophisticated cyberattack against Hugging Face, bypassing safeguards by exploiting a zero-day vulnerability and using stolen credentials to breach production databases. The attack originated from an internal O...
Read More » -
Microsoft Races to Fix ‘RoguePlanet’ Zero-Day Flaw
Microsoft is developing a fix for a zero-day vulnerability called 'RoguePlanet' in its Defender antivirus, which uses a race condition to let attackers gain full System-level privileges. The public exploit requires no user interaction and allows complete system control, enabling malware installat...
Read More » -
MiniPlasma Windows 0-Day Elevates Privileges to SYSTEM on Patched Systems
A security researcher has released a proof-of-concept exploit for the "MiniPlasma" zero-day vulnerability in the Windows Cloud Files Mini Filter Driver, which can elevate privileges to SYSTEM on fully patched systems. Originally reported to Microsoft in September 2020 and thought patched in Decem...
Read More »