#zero-day

[ follow ]
#chrome
Apple
fromTheregister
6 days ago

Apple patches decade-old iOS zero-day exploited in the wild

A dyld zero-day (CVE-2026-20700) enables arbitrary code execution with memory-write capability and was exploited in targeted, highly sophisticated attacks.
#windows
fromTechCrunch
1 week ago
Information security

Microsoft says hackers are exploiting critical zero-day bugs to target Windows and Office users | TechCrunch

fromTechCrunch
1 week ago
Information security

Microsoft says hackers are exploiting critical zero-day bugs to target Windows and Office users | TechCrunch

Information security
fromSecurityWeek
1 week ago

6 Actively Exploited Zero-Days Patched by Microsoft With February 2026 Updates

Microsoft patched roughly 60 vulnerabilities, including six actively exploited zero-days impacting Windows, Office, Remote Desktop Services, and local privilege escalation/DoS vectors.
Information security
fromSecurityWeek
1 week ago

Singapore: Rootkits, Zero-Day Used in Chinese Attack on Major Telecom Firms

Chinese APT UNC3886 targeted all four major Singapore telcos using a firewall zero-day and rootkits, gaining limited access but no evidence of customer data exfiltration.
Information security
fromSecurityWeek
2 weeks ago

Russia's APT28 Rapidly Weaponizes Newly Patched Office Vulnerability

APT28 quickly weaponized Microsoft's patched Office vulnerability CVE-2026-21509, deploying droppers and additional malware such as MiniDoor within days of the patch release.
fromSecurityWeek
2 weeks ago

Ivanti Patches Exploited EPMM Zero-Days

Ivanti on Thursday announced emergency patches for two critical-severity vulnerabilities in Endpoint Manager Mobile (EPMM) that have been exploited in the wild as zero-days. Tracked as CVE-2026-1281 and CVE-2026-1340 (CVSS score of 9.8), the bugs are described as code injection issues that could be exploited by unauthenticated attackers to achieve remote code execution (RCE). The flaws impact the in-house application distribution and the Android file transfer configuration features of EPMM.
Information security
Information security
fromSecurityWeek
3 weeks ago

Fortinet Patches Exploited FortiCloud SSO Authentication Bypass

A FortiCloud SSO authentication bypass (CVE-2026-24858) was exploited in the wild; Fortinet released emergency patches for FortiOS, FortiManager, and FortiAnalyzer.
#cve-2026-21509
fromZDNET
3 weeks ago

Use Microsoft Office? Hackers can infect your PC with a malicious document - patch it ASAP

Microsoft has issued an emergency patch designed to resolve a zero-day security vulnerability affecting several versions of Microsoft Office. Already exploited in the wild, the flaw could allow an attacker to skirt past Office's built-in security measures and send victims a malicious document. Zero-day vulnerability In a note published Monday, Microsoft revealed details behind the flaw, known as a Microsoft Office Security Feature Bypass Vulnerability.
Information security
Apple
fromZDNET
2 months ago

5 reasons to update your iPhone to iOS 26.2 - including security patches

Install iOS 26.2 now to patch two exploited WebKit zero-day vulnerabilities and receive app and feature improvements across Apple devices.
Apple
fromThe Hacker News
2 months ago

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

Apple released security updates across platforms to patch two WebKit vulnerabilities exploited in the wild, one matching a Chrome ANGLE/Metal out-of-bounds flaw.
#fortiweb
fromThe Hacker News
3 months ago

Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack

Microsoft on Tuesday released patches for 63 new security vulnerabilities identified in its software, including one that has come under active exploitation in the wild. Of the 63 flaws, four are rated Critical and 59 are rated Important in severity. Twenty-nine of these vulnerabilities are related to privilege escalation, followed by 16 remote code execution, 11 information disclosure, three denial-of-service (DoS), two security feature bypass, and two spoofing bugs.
Information security
fromIT Pro
3 months ago

Threat actors are exploiting flaws more quickly - here's what business leaders should do

In July, Microsoft fixed a flaw in its file sharing service SharePoint that was already being exploited by attackers. Later that month, Microsoft warned that hackers were making use of the zero-day to distribute ransomware, adding even more risk to the serious vulnerability. The SharePoint flaw is just one example of attackers becoming faster at exploiting vulnerabilities before they can be properly addressed by vendors and patched by organizations.
Information security
fromThe Hacker News
4 months ago

Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in "Zero Disco' Attacks

The activity, codenamed Operation Zero Disco by Trend Micro, involves the weaponization of CVE-2025-20352 (CVSS score: 7.7), a stack overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow an authenticated, remote attacker to execute arbitrary code by sending crafted SNMP packets to a susceptible device. The intrusions have not been attributed to any known threat actor or group.
Information security
Information security
fromTechCrunch
4 months ago

'Dozens' of organizations had data stolen in Oracle-linked hacks | TechCrunch

Clop used a zero-day in Oracle E-Business Suite to steal corporate executive and company data from dozens of organizations since at least July 10.
#oracle-e-business-suite
fromTechCrunch
4 months ago
Information security

Clop hackers caught exploiting Oracle zero-day bug to steal executives' personal data | TechCrunch

fromTechCrunch
4 months ago
Information security

Clop hackers caught exploiting Oracle zero-day bug to steal executives' personal data | TechCrunch

Information security
fromTheregister
4 months ago

ZDI, Wiz in hacking contest kerfuffle over copied rules

Wiz launched Zero Day Cloud, a $4.5M cloud-hacking contest rewarding 0-click RCE and container-escape exploits in 20 open-source cloud projects.
fromSecurityWeek
4 months ago

Cisco Firewall Zero-Days Exploited in China-Linked ArcaneDoor Attacks

Tracked as CVE-2025-20333 (CVSS score of 9.9) and CVE-2025-20362 (CVSS score of 6.5), the bugs impact the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The issues, Cisco explains, exist because user-supplied input in HTTP(S) requests is not properly validated, allowing a remote attacker to send crafted requests and execute arbitrary code with root privileges or access a restricted URL without authentication.
Information security
Gadgets
fromTechCrunch
5 months ago

Samsung patches zero-day security flaw used to hack into its customers' phones | TechCrunch

Samsung fixed a zero-day in its image-display library that allowed remote planting of malicious code on devices running Android 13–16.
Information security
fromThe Hacker News
5 months ago

FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available

A critical CVE-2025-57819 FreePBX vulnerability enables unauthenticated arbitrary database manipulation and remote code execution; internet-exposed ACPs should be upgraded and restricted.
Information security
fromComputerWeekly.com
5 months ago

Apple iOS update fixes new iPhone zero-day flaw | Computer Weekly

A zero-day in Apple's ImageIO enables zero-click image-based memory-corruption exploits; iOS/iPadOS 18.6.2 adds improved bounds checking to mitigate active exploitation.
fromTheregister
5 months ago

Apple rushes out fix for active zero-day in iOS and macOS

Apple has shipped emergency updates to fix an actively exploited zero-day in its ImageIO framework, warning that the flaw has already been abused in targeted attacks. Logged as CVE-2025-43300, the bug is an out-of-bounds write issue in ImageIO, the component apps rely on to read and write standard image formats. Apple warned that the flaw could let miscreants hijack devices with a booby-trapped image - and for some iDevice users, it sounds like the damage has already been done.
Apple
Apple
fromIT Pro
5 months ago

Apple just released an emergency patch for a zero-day exploited in the wild - here's why you need to update now

Critical Image I/O zero-day (CVE-2025-43300) enables arbitrary code execution via malicious images on iPhone, iPad, and Mac; install the emergency update immediately.
Information security
fromTechCrunch
5 months ago

New zero-day startup offers $20 million for tools that can hack any smartphone | TechCrunch

A UAE-based startup offers up to $20 million for smartphone zero-day exploits, marketing powerful hacking tools to governments and intelligence agencies.
Privacy professionals
fromThe Hacker News
6 months ago

WinRAR Zero-Day Under Active Exploitation - Update to Latest Version Immediately

WinRAR released an update addressing CVE-2025-8088, a zero-day vulnerability causing path traversal and allowing arbitrary code execution.
fromZDNET
6 months ago

Microsoft fixes two SharePoint zero-days under attack, but one is still unresolved - how to patch

CVE-2025-53770 gives a threat actor the ability to remotely execute code, bypassing identity protections (like single sign-on and multi-factor authentication), giving access to content on the SharePoint server including configurations and system files, opening up lateral access across the Windows domain.
Information security
#cybersecurity
[ Load more ]