Tag: zero day
367 articles

SAP Exploits Maximum-Severity Commerce Cloud Flaw in Active Attacks
SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.

China-nexus APT Exploits VMware Flaw to Deploy Ransomware
A China-linked APT group has been exploiting a recently patched VMware vCenter vulnerability to deploy ransomware in a widespread campaign that hit 361 victims across 47 countries. The attackers used the flaw to gain root access and, in some cases, installed a Babuk-derived ransomware that locks files with a ".babyk" extension.

Microsoft Scrambles to Patch Defender Zero-Day Exploited in Wild
Microsoft is racing against the clock to patch a zero-day vulnerability in Defender, known as ShieldBreak, that's being exploited in the wild. The tech giant is working on a high-quality security update to address the elevation of privilege issue in the Microsoft Malware Protection Engine.

French Tax Authority Confirms Data Breach After Hacker Touts 2M Records
The French Tax Authority has confirmed a data breach after a hacker claimed to have stolen sensitive information from over 2 million taxpayers, exploiting stolen credentials and a security loophole. The breach was detected in June, and an immediate audit helped sever the unauthorized access.

SAP Commerce Cloud Vulnerability Now Under Active Attack
Hackers are actively exploiting a critical vulnerability in SAP Commerce Cloud, allowing them to remotely execute code without any login credentials. This severe flaw, tracked as CVE-2026-58231, was patched by SAP just three days before attacks began.

Apple Warns Users of Mercenary Spyware Attacks on iPhones
Got a warning from Apple about a mercenary spyware attack on your iPhone? This means hackers are trying to secretly access your device, and Apple is stepping in to alert and protect you.

Microsoft patches LegacyHive zero-day vulnerability
Microsoft just patched a nasty zero-day vulnerability, known as LegacyHive, that could let hackers gain administrator privileges on your Windows PC - but thankfully, it's now fixed in the August Patch Tuesday updates.

Google Cloud Accelerates Post-Quantum Security Push with 2027 Milestone
Google Cloud is proactively bolstering its defenses against future quantum computer threats, aiming to complete a major milestone in its post-quantum security migration by 2027. The tech giant has mapped out a multi-year plan to adopt quantum-resistant cryptography, tackling key risks in data security and digital signatures.

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks
The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

Gunra Ransomware Targets Infrastructure via Fortinet Flaws
Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics
Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

Adobe Fixes Zero-Day Flaws in ColdFusion, Campaign Classic
Adobe has patched critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic, including a zero-day flaw with a perfect 10.0 CVSS score that could allow hackers to execute arbitrary code or escalate privileges. These high-severity flaws, including operating system command injection and eval injection, require immediate attention to prevent exploitation.

Microsoft Defender Zero-Day Exploited to Gain System Privileges
A security researcher known as Nightmare Eclipse has unveiled a new exploit, ShieldBreak, which can bypass Microsoft's patch for the RoguePlanet vulnerability and grant SYSTEM privileges on fully patched Windows systems. This alarming development highlights a significant gap in Microsoft Defender's defenses, leaving users vulnerable to potential attacks.

Microsoft Patch Tuesday Disrupts 400 Vulnerabilities, Zero-Day Exploits
Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 vulnerabilities, including an actively exploited zero-day threat that demands immediate attention from sysadmins. With high-risk impacts on confidentiality, integrity, and availability, these fixes should be top priority.

Microsoft Defender Faces ShieldBreak Exploit With SYSTEM Access
A security researcher known as Chaotic Eclipse has unleashed a powerful proof-of-concept exploit called ShieldBreak, which cleverly bypasses Microsoft's patch for the RoguePlanet vulnerability, granting SYSTEM-level access. This devastating exploit has been tested on the latest Windows 11 and Server 2025 with a 100% success rate.

Microsoft Disrupts Hundreds of Flaws in Massive Patch Update
Microsoft just dropped a massive patch update to fix a whopping 398 security flaws in Windows and its software, including a critical vulnerability that's already being exploited by hackers. This crucial update tackles a range of weaknesses, from a zero-day privilege-escalation flaw in a key Windows driver to other publicly known vulnerabilities.

SAP Patches Critical Flaw Allowing Unauthenticated Code Execution
A critical flaw in SAP Commerce Cloud, rated 10.0 on the CVSS scale, allows hackers to execute malicious code without any authentication, putting your entire system at risk. This severe vulnerability can be exploited with specially crafted input, making it essential to patch ASAP.

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks
North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Zoom Flaws Let Meeting Participants Hijack Other Attendees' Clients
Critical security flaws in Zoom's annotation code, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could have allowed a meeting participant to hijack others' clients without warning. Fortunately, Zoom has patched these vulnerabilities, and no exploitation has been reported.

Microsoft Patches Zero-Day Windows Driver Flaw Under Active Attack
Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits
Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.

BdThemes Plugins Targeted in Supply Chain Attack
A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

OpenAI Unveils GPT-5.6-Cyber, Model With Reduced Safeguards
Meet GPT-5.6-Cyber, a game-changing AI model that supercharges cybersecurity tasks like vulnerability research and penetration testing with unprecedented success rates. This powerhouse model crushes 95% of advanced exploit-chain and privilege-escalation requests, leaving its predecessor in the dust.

OpenAI Halts Astra Model Testing on Cyber Risk Concerns
OpenAI is hitting the pause button on internal testing of its Astra model due to concerns that it could pose a critical cyber risk, and is implementing stricter security controls to mitigate potential threats. The move comes as part of the company's efforts to prioritize safety and adhere to its Preparedness Framework.