Skip to main content

Tag: zero day

367 articles

Retail checkout counter with point-of-sale terminal and shopping cart amidst scattered items.

SAP Exploits Maximum-Severity Commerce Cloud Flaw in Active Attacks

SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.

Analyst 207
Rows of computer servers and storage equipment in a data center or server room.

China-nexus APT Exploits VMware Flaw to Deploy Ransomware

A China-linked APT group has been exploiting a recently patched VMware vCenter vulnerability to deploy ransomware in a widespread campaign that hit 361 victims across 47 countries. The attackers used the flaw to gain root access and, in some cases, installed a Babuk-derived ransomware that locks files with a ".babyk" extension.

Analyst 207
Modern office lab setting with a laptop workstation and muted equipment in soft focus under natural light.

Microsoft Scrambles to Patch Defender Zero-Day Exploited in Wild

Microsoft is racing against the clock to patch a zero-day vulnerability in Defender, known as ShieldBreak, that's being exploited in the wild. The tech giant is working on a high-quality security update to address the elevation of privilege issue in the Microsoft Malware Protection Engine.

Analyst 207
French government office interior with blurred emblem in background.

French Tax Authority Confirms Data Breach After Hacker Touts 2M Records

The French Tax Authority has confirmed a data breach after a hacker claimed to have stolen sensitive information from over 2 million taxpayers, exploiting stolen credentials and a security loophole. The breach was detected in June, and an immediate audit helped sever the unauthorized access.

Analyst 207
Retail store checkout counter with point-of-sale terminal and shopping cart.

SAP Commerce Cloud Vulnerability Now Under Active Attack

Hackers are actively exploiting a critical vulnerability in SAP Commerce Cloud, allowing them to remotely execute code without any login credentials. This severe flaw, tracked as CVE-2026-58231, was patched by SAP just three days before attacks began.

Analyst 207
iPhone on a neutral surface with soft ambient lighting and subtle shadows.

Apple Warns Users of Mercenary Spyware Attacks on iPhones

Got a warning from Apple about a mercenary spyware attack on your iPhone? This means hackers are trying to secretly access your device, and Apple is stepping in to alert and protect you.

Analyst 207
Generic Windows desktop computer on a beige work surface in a neutral office setting.

Microsoft patches LegacyHive zero-day vulnerability

Microsoft just patched a nasty zero-day vulnerability, known as LegacyHive, that could let hackers gain administrator privileges on your Windows PC - but thankfully, it's now fixed in the August Patch Tuesday updates.

Analyst 207
Technicians work on server racks in a brightly-lit cloud computing facility.

Google Cloud Accelerates Post-Quantum Security Push with 2027 Milestone

Google Cloud is proactively bolstering its defenses against future quantum computer threats, aiming to complete a major milestone in its post-quantum security migration by 2027. The tech giant has mapped out a multi-year plan to adopt quantum-resistant cryptography, tackling key risks in data security and digital signatures.

Analyst 207
Defense sector office with computer workstation and blurred monitor screen.

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks

The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

Analyst 207
Technicians work in a network operations center with modern and legacy equipment, including a Fortinet device.

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

Analyst 207
Modern office workspace with laptop, papers, and pen, hinting at secure networking setup.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics

Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

Analyst 207
Modern office interior with a blank laptop screen on a desk surrounded by neutral-colored furniture.

Adobe Fixes Zero-Day Flaws in ColdFusion, Campaign Classic

Adobe has patched critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic, including a zero-day flaw with a perfect 10.0 CVSS score that could allow hackers to execute arbitrary code or escalate privileges. These high-severity flaws, including operating system command injection and eval injection, require immediate attention to prevent exploitation.

Analyst 207
Windows laptop on a desk in a modern office with a blurred background and scribbled notes nearby.

Microsoft Defender Zero-Day Exploited to Gain System Privileges

A security researcher known as Nightmare Eclipse has unveiled a new exploit, ShieldBreak, which can bypass Microsoft's patch for the RoguePlanet vulnerability and grant SYSTEM privileges on fully patched Windows systems. This alarming development highlights a significant gap in Microsoft Defender's defenses, leaving users vulnerable to potential attacks.

Analyst 207
IT professional standing in data center with server rack and open laptop.

Microsoft Patch Tuesday Disrupts 400 Vulnerabilities, Zero-Day Exploits

Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 vulnerabilities, including an actively exploited zero-day threat that demands immediate attention from sysadmins. With high-risk impacts on confidentiality, integrity, and availability, these fixes should be top priority.

Analyst 207
Windows 11 laptop screen with security software interface and scattered notes and USB drive on desk.

Microsoft Defender Faces ShieldBreak Exploit With SYSTEM Access

A security researcher known as Chaotic Eclipse has unleashed a powerful proof-of-concept exploit called ShieldBreak, which cleverly bypasses Microsoft's patch for the RoguePlanet vulnerability, granting SYSTEM-level access. This devastating exploit has been tested on the latest Windows 11 and Server 2025 with a 100% success rate.

Analyst 207
Microsoft Disrupts Hundreds of Flaws in Massive Patch Update

Microsoft Disrupts Hundreds of Flaws in Massive Patch Update

Microsoft just dropped a massive patch update to fix a whopping 398 security flaws in Windows and its software, including a critical vulnerability that's already being exploited by hackers. This crucial update tackles a range of weaknesses, from a zero-day privilege-escalation flaw in a key Windows driver to other publicly known vulnerabilities.

Analyst 207
Brightly-lit retail setting with a cloud-connected device in the foreground.

SAP Patches Critical Flaw Allowing Unauthenticated Code Execution

A critical flaw in SAP Commerce Cloud, rated 10.0 on the CVSS scale, allows hackers to execute malicious code without any authentication, putting your entire system at risk. This severe vulnerability can be exploited with specially crafted input, making it essential to patch ASAP.

Analyst 207
A typical defense sector industrial setting with a computer workstation in the mid-ground, surrounded by ordinary activity.

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks

North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Analyst 207
Blurred laptop screen on a table surrounded by chairs in a bright, daytime office setting.

Zoom Flaws Let Meeting Participants Hijack Other Attendees' Clients

Critical security flaws in Zoom's annotation code, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could have allowed a meeting participant to hijack others' clients without warning. Fortunately, Zoom has patched these vulnerabilities, and no exploitation has been reported.

Analyst 207
Windows computer workstation on a clean office desk with a blank laptop screen.

Microsoft Patches Zero-Day Windows Driver Flaw Under Active Attack

Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

Analyst 207
Employees work at computer desks in a brightly-lit tech facility with city view.

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits

Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.

Analyst 207
WordPress admin dashboard on a laptop screen with a cityscape background and office items nearby.

BdThemes Plugins Targeted in Supply Chain Attack

A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

Analyst 207
Cybersecurity professional working in a lab with technology and security equipment.

OpenAI Unveils GPT-5.6-Cyber, Model With Reduced Safeguards

Meet GPT-5.6-Cyber, a game-changing AI model that supercharges cybersecurity tasks like vulnerability research and penetration testing with unprecedented success rates. This powerhouse model crushes 95% of advanced exploit-chain and privilege-escalation requests, leaving its predecessor in the dust.

Analyst 207
Person's hands on a keyboard with a blurred laptop screen in a neutral workspace.

OpenAI Halts Astra Model Testing on Cyber Risk Concerns

OpenAI is hitting the pause button on internal testing of its Astra model due to concerns that it could pose a critical cyber risk, and is implementing stricter security controls to mitigate potential threats. The move comes as part of the company's efforts to prioritize safety and adhere to its Preparedness Framework.

Analyst 207