#zero-day-exploit

[ follow ]
fromCSS-Tricks
2 weeks ago

An Exploit ... in CSS?! | CSS-Tricks

Google credits security researcher Shaheen Fazim with reporting the exploit to Google. The dude's LinkedIn says he's a professional bug hunter, and I'd say he deserves the highest possible bug bounty for finding something that a government agency is saying "in CSS in Google Chrome before 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page."
Information security
Information security
fromThe Hacker News
2 weeks ago

Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More

Critical zero-day in Dell RecoverPoint for VMs (CVE-2026-22769) is actively exploited, enabling root access and backdoor deployment via hard-coded Tomcat credentials.
Information security
fromTheregister
2 weeks ago

Attacker gets into France's DB listing all bank accounts

A January breach exposed 1.2 million French bank account records, while attackers actively exploit two critical Ivanti EPMM zero-days targeting unpatched systems worldwide.
#cve-2026-22769
Information security
fromSecurityWeek
3 weeks ago

Google Patches First Actively Exploited Chrome Zero-Day of 2026

An actively exploited high-severity use-after-free vulnerability in Chrome's CSS component (CVE-2026-2441) has been patched in emergency updates for Windows, Mac, and Linux.
Apple
fromTechRepublic
4 weeks ago

Critical Apple Flaw Exploited in 'Sophisticated' Attacks, Company Urges Rapid Patching

A dyld zero-day (CVE-2026-20700) enables arbitrary code execution across Apple OSes and was exploited in targeted, highly sophisticated attacks; users must update immediately.
World news
fromThe Hacker News
1 month ago

China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign

China-linked APT UNC3886 conducted a deliberate cyber-espionage campaign against all four major Singapore telcos, using zero-day exploits and rootkits to access critical systems.
Information security
fromTheregister
1 month ago

Office zero-day exploited, forces Microsoft OOB patch

Zero-day CVE-2026-21509 lets attackers bypass Office security to run legacy COM/OLE components via malicious files; patches available for newer Office versions.
#clop
fromNextgov.com
5 months ago

CISA issues emergency patching directive for Cisco devices on federal networks

The Cybersecurity and Infrastructure Security Agency is ordering federal agencies to patch Cisco devices that have been exploited by an advanced hacker group, it said in a Thursday alert. The hacking activity targeting the devices "is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution" on various Cisco Adaptive Security Appliances, CISA said. A "zero-day" refers to a software flaw that's being exploited but has not been previously discovered, giving developers zero days to fix it.
Information security
fromTheregister
5 months ago

Zero-day deja vu: Another Cisco IOS bug is under attack

Attackers with low-privilege SNMP creds can crash a device, while those with higher-privilege access can run arbitrary code as root - a straight shot to total box compromise. "The Cisco Product Security Incident Response Team (PSIRT) became aware of successful exploitation of this vulnerability in the wild after local Administrator credentials were compromised," the company said. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."
Information security
Apple
fromTheregister
5 months ago

Apple backports patch to older kit after 0-day exploitation

Apple backported an ImageIO out-of-bounds write fix to older iPhones and iPads after evidence of exploitation in extremely sophisticated attacks possibly tied to commercial surveillanceware.
#citrix-netscaler
Apple
fromThe Hacker News
6 months ago

Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks

Apple patched an ImageIO out-of-bounds write zero-day (CVE-2025-43300) actively exploited to cause memory corruption across iOS, iPadOS, and macOS.
#cybersecurity
fromFast Company
7 months ago
Information security

Microsoft SharePoint hack: An active cybersecurity incident could impact tens of thousands of servers

fromFast Company
7 months ago
Information security

Microsoft SharePoint hack: An active cybersecurity incident could impact tens of thousands of servers

fromTheregister
7 months ago

Blame a leak for Microsoft SharePoint attacks: researcher

A leak happened here somewhere,” Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative (ZDI), told The Register. “And now you’ve got a zero-day exploit in the wild, and worse than that, you’ve got a zero-day exploit in the wild that bypasses the patch, which came out the next day.
Privacy professionals
Information security
fromThe Verge
7 months ago

Microsoft SharePoint servers are under attack because of a major security flaw

Microsoft's SharePoint software vulnerabilities expose tens of thousands of servers to active attacks, prompting urgent security measures and patch releases.
Privacy professionals
fromTechRepublic
11 months ago

Patch Tuesday: Microsoft Fixes 134 Vulnerabilities, Including 1 Zero-Day

Microsoft's April Patch Tuesday update addressed 134 flaws, including a zero-day vulnerability, raising concerns about security in Windows systems.
[ Load more ]