#zero-day-vulnerabilities

[ follow ]
#coordinated-vulnerability-disclosure
Information security
fromComputerWeekly.com
1 day ago

Microsoft hits out over irresponsible vulnerability disclosure | Computer Weekly

Six zero-day vulnerabilities were published as proof-of-concept hacks without prior coordination, prompting Microsoft to say customers faced unnecessary risk.
Information security
fromThe Hacker News
2 days ago

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Microsoft urges coordinated vulnerability disclosure so vendors can assess impact and issue protections before public release.
Information security
fromComputerWeekly.com
1 day ago

Microsoft hits out over irresponsible vulnerability disclosure | Computer Weekly

Six zero-day vulnerabilities were published as proof-of-concept hacks without prior coordination, prompting Microsoft to say customers faced unnecessary risk.
Information security
fromThe Hacker News
2 days ago

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Microsoft urges coordinated vulnerability disclosure so vendors can assess impact and issue protections before public release.
#ai-assisted-cyberattacks
Information security
fromNextgov.com
2 days ago

AI is compressing attack timelines. Here's how agencies can respond.

AI-assisted vulnerability discovery is accelerating exploitation timelines, widening the public-sector gap between attacker speed and defender remediation capacity.
fromThe Verge
2 weeks ago
Information security

Google stopped a zero-day hack that it says was developed with AI

Google identified and disrupted an AI-assisted zero-day exploit targeting a web-based administration tool’s two-factor authentication by exploiting a hardcoded trust assumption.
Information security
fromNextgov.com
2 days ago

AI is compressing attack timelines. Here's how agencies can respond.

AI-assisted vulnerability discovery is accelerating exploitation timelines, widening the public-sector gap between attacker speed and defender remediation capacity.
Information security
fromThe Verge
2 weeks ago

Google stopped a zero-day hack that it says was developed with AI

Google identified and disrupted an AI-assisted zero-day exploit targeting a web-based administration tool’s two-factor authentication by exploiting a hardcoded trust assumption.
#cybersecurity
Information security
fromFuturism
2 weeks ago

Google Alarmed by Formidable AI-Powered Zero-Day Cyberattack

A cyberattack used AI to discover and weaponize an unknown zero-day flaw, potentially bypassing two-factor authentication on a web administration tool, but was thwarted.
Information security
fromthenextweb.com
3 weeks ago

Anthropic Mythos AI finds thousands of zero-day vulnerabilities as Fed and Treasury convene bank CEOs on cyber rik

Claude Mythos Preview identified thousands of zero-day vulnerabilities, prompting urgent bank discussions and warning of a six-to-twelve month patch window before adversaries replicate capability.
Information security
fromThe Hacker News
1 month ago

APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies

A Russian threat actor is conducting a spear-phishing campaign targeting Ukraine using a new malware suite called PRISMEX, exploiting zero-day vulnerabilities.
Information security
fromWIRED
5 days ago

The AI Era Is Creating a Bug Hunting Arms Race

Criminal actors dominate most security incidents, while AI-driven bug reports are reshaping vulnerability reward programs and mailing lists through quality and volume changes.
Information security
fromFuturism
2 weeks ago

Google Alarmed by Formidable AI-Powered Zero-Day Cyberattack

A cyberattack used AI to discover and weaponize an unknown zero-day flaw, potentially bypassing two-factor authentication on a web administration tool, but was thwarted.
Information security
fromthenextweb.com
3 weeks ago

Anthropic Mythos AI finds thousands of zero-day vulnerabilities as Fed and Treasury convene bank CEOs on cyber rik

Claude Mythos Preview identified thousands of zero-day vulnerabilities, prompting urgent bank discussions and warning of a six-to-twelve month patch window before adversaries replicate capability.
Information security
fromThe Hacker News
1 month ago

APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies

A Russian threat actor is conducting a spear-phishing campaign targeting Ukraine using a new malware suite called PRISMEX, exploiting zero-day vulnerabilities.
Information security
fromSecurityWeek
1 week ago

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Microsoft released patches for two Microsoft Defender vulnerabilities exploited in the wild, adding them to CISA’s KEV list with a June 3 patch deadline.
Information security
fromTNW | Anthropic
1 week ago

Project Glasswing partners can now share Mythos findings beyond the programme

Partners can share Mythos vulnerability findings with external security teams, regulators, open-source maintainers, and the public under responsible-disclosure norms.
#pwn2own
Berlin
fromZero Day Initiative
2 weeks ago

Zero Day Initiative - Pwn2Own Berlin 2026: Day Three Results and Master of Pwn

Pwn2Own Berlin 2026 day three features SharePoint and ESXi targets, with $908,750 awarded for 39 zero-days so far and strong odds to exceed $1M.
Berlin
fromZero Day Initiative
2 weeks ago

Zero Day Initiative - Pwn2Own Berlin 2026: Day Three Results and Master of Pwn

Pwn2Own Berlin 2026 day three features SharePoint and ESXi targets, with $908,750 awarded for 39 zero-days so far and strong odds to exceed $1M.
Information security
fromTNW | Data-Security
2 weeks ago

Google identifies first AI-developed zero-day exploit and thwarts planned mass exploitation event

Google identified an AI-assisted zero-day exploit, disrupted a planned mass exploitation event, and documented state-sponsored AI use in vulnerability research and malware development.
Information security
fromTechRepublic
2 weeks ago

Google Says Hackers Used AI to Build Zero-Day Exploit

A zero-day exploit with AI assistance targeted 2FA in an open-source web administration tool, but was disrupted before large-scale use.
Information security
fromThe Hacker News
2 weeks ago

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation

A zero-day 2FA bypass was found and fixed after likely AI-assisted exploit generation using a Python script targeting an open-source web administration tool.
Artificial intelligence
fromwww.theguardian.com
2 weeks ago

AI-powered hacking has exploded into industrial-scale threat, Google says

AI-powered hacking has scaled rapidly, with criminal and state-linked actors using commercial AI models to accelerate, improve, and exploit software vulnerabilities.
Information security
fromtheregister
2 weeks ago

Google says criminals used AI-built zero-day in planned mass hack spree

AI-enabled attackers identified and weaponized a zero-day using an AI model, and Google patched it before a mass-exploitation campaign began.
#ai-cybersecurity
London startup
fromTNW | Security
3 weeks ago

Intruder launches AI pentesting agents as GCHQ-backed startup automates $50K manual security tests

AI pentesting agents replicate human methodology to validate scanner findings and deliver vulnerability results in minutes at far lower cost than manual testing.
fromFortune
3 months ago
Information security

Anthropic's newest model excels at finding security vulnerabilities, but raises cybersecurity risks | Fortune

London startup
fromTNW | Security
3 weeks ago

Intruder launches AI pentesting agents as GCHQ-backed startup automates $50K manual security tests

AI pentesting agents replicate human methodology to validate scanner findings and deliver vulnerability results in minutes at far lower cost than manual testing.
fromFortune
3 months ago
Information security

Anthropic's newest model excels at finding security vulnerabilities, but raises cybersecurity risks | Fortune

Artificial intelligence
fromwww.theguardian.com
1 month ago

The Guardian view on Anthropic's Claude Mythos: when AI finds every flaw, who controls the internet? | Editorial

Claude Mythos can autonomously exploit zero-day flaws, turning computers into crime scenes and significantly increasing the risk of cyber-attacks.
Artificial intelligence
fromFortune
1 month ago

AI cybersecurity capabilities require urgent international cooperation, AI godfather Bengio says | Fortune

Yoshua Bengio emphasizes the urgent need for international cooperation in addressing AI's risks, particularly with the release of Anthropic's Mythos model.
Information security
fromComputerWeekly.com
1 month ago

April Patch Tuesday brings zero-days in Defender, SharePoint Server | Computer Weekly

Microsoft's April Patch Tuesday update addresses over 160 issues, including two critical zero-day vulnerabilities, marking one of the largest updates in history.
#ai
Information security
fromTheregister
1 month ago

Anthropic Mythos model can find and exploit 0-days

AI model Mythos can generate zero-day vulnerabilities, surpassing human capabilities, but Anthropic chose not to release it to prevent widespread exploitation.
Podcast
fromTheregister
1 month ago

Anthropic's Mythos has The Kettle crew curious, skeptical

Kettle Anthropic launched Mythos, an AI model capable of finding and exploiting zero-day vulnerabilities.
Information security
fromTheregister
1 month ago

Anthropic Mythos model can find and exploit 0-days

AI model Mythos can generate zero-day vulnerabilities, surpassing human capabilities, but Anthropic chose not to release it to prevent widespread exploitation.
Information security
fromSecurityWeek
2 months ago

'DarkSword' iOS Exploit Kit Used by State-Sponsored Hackers, Spyware Vendors

Security researchers discovered DarkSword, a sophisticated iOS exploit kit used by Russian state-sponsored hackers and commercial spyware vendors to compromise Apple devices with minimal user interaction.
Information security
fromComputerworld
2 months ago

Google warns of two actively exploited Chrome zero days

Critical Chromium browser vulnerabilities with active exploitation require immediate updates across all Chromium-based browsers to prevent drive-by attacks.
fromTheregister
2 months ago

Google rushes Chrome update to fix zero-days under attack

CVE-2026-3909 is an out-of-bounds write flaw in Skia, the graphics library Chrome uses to render web content and parts of its user interface. Memory corruption bugs like this can sometimes be abused by attackers to crash applications or run their own code if successfully exploited.
Information security
fromSecurityWeek
2 months ago

Chrome 146 Update Patches Two Exploited Zero-Days

Google is aware that exploits for both CVE-2026-3909 & CVE-2026-3910 exist in the wild. CVE-2026-3909 is described as an out-of-bounds write defect in the Skia graphics library. It could be triggered via malicious HTML pages to corrupt memory, which could lead to arbitrary code execution or crashes.
Information security
Games
fromZero Day Initiative
2 months ago

Zero Day Initiative - Announcing Pwn2Own Berlin for 2026

Pwn2Own returns to Berlin in 2026 with expanded AI categories, AWS co-sponsorship, over $1,000,000 in prizes, and 31 targets across 10 categories including browsers, containers, servers, virtualization, and operating systems.
fromThe Hacker News
2 months ago

Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

This month, over half (55%) of all Patch Tuesday CVEs were privilege escalation bugs, and of those, six were rated exploitation more likely across Windows Graphics Component, Windows Accessibility Infrastructure, Windows Kernel, Windows SMB Server, and Winlogon. We know these bugs are typically used by threat actors as part of post-compromise activity, once they get onto systems through other means (social engineering, exploitation of another vulnerability).
Information security
fromArs Technica
2 months ago

Feds take notice of iOS vulnerabilities exploited under mysterious circumstances

How this proliferation occurred is unclear, but suggests an active market for 'second hand' zero-day exploits. Beyond these identified exploits, multiple threat actors have now acquired advanced exploitation techniques that can be re-used and modified with newly identified vulnerabilities.
Information security
Information security
fromTechzine Global
2 months ago

China and spyware companies dominate zero-day attacks

Zero-day vulnerability exploits reached 90 cases in 2025, with Chinese cyber espionage groups and commercial spyware companies driving attacks increasingly toward enterprise infrastructure and security equipment.
#enterprise-security
Information security
fromTechCrunch
2 months ago

Google says half of all zero-days it tracked in 2025 targeted buggy enterprise tech | TechCrunch

Nearly half of tracked zero-day vulnerabilities in 2024 targeted enterprise devices, with security infrastructure like firewalls and VPNs being primary targets for hackers seeking corporate data access.
Information security
fromTechCrunch
2 months ago

Google says half of all zero-days it tracked in 2025 targeted buggy enterprise tech | TechCrunch

Nearly half of tracked zero-day vulnerabilities in 2024 targeted enterprise devices, with security infrastructure like firewalls and VPNs being primary targets for hackers seeking corporate data access.
fromComputerWeekly.com
2 months ago

Spyware suppliers exploit more zero-days than nation states | Computer Weekly

Historically, traditional state-sponsored cyber espionage groups have been the most prolific attributed users of zero-day vulnerabilities. [But] over the last few years, the increase of zero-day exploitation attributed to CSVs and their customers has demonstrated the growing ability of these vendors to provide zero-day access to a wider range of threat actors than ever before.
Information security
Information security
fromThe Hacker News
2 months ago

Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

Multiple attack vectors across network systems, cloud infrastructure, and AI platforms exploit access control gaps, exposed credentials, and trusted service misuse to target high-value sectors.
Information security
fromSecurityWeek
3 months ago

US Sanctions Russian Exploit Broker Operation Zero

The US government sanctioned seven individuals and entities for acquiring and distributing cyber exploits, including a Russian broker who paid $1.3 million for stolen zero-day exploits intended for government use.
#microsoft-security-updates
Artificial intelligence
fromInfoWorld
3 months ago

Claude AI finds 500 high-severity software vulnerabilities

Claude Opus 4.6 uncovered 500 high-severity zero-day vulnerabilities in open-source projects while running in a VM with standard analysis tools and no guidance.
fromTheregister
4 months ago

Automotive systems get pwned at Pwn2Own Automotive 2026

infosec in brief T'was a dark few days for automotive software systems last week, as the third annual Pwn2Own Automotive competition uncovered 76 unique zero-day vulnerabilities in targets ranging from Tesla infotainment to EV chargers. A record 73 entries were included in this year's competition at Automotive World in Tokyo, and, while not all were successful, Trend Micro's Zero Day Initiative still ended up paying out more than $1 million to successful competitors. For those unfamiliar with the structure of a Pwn2Own competition, ethical hackers and security experts enter with plans to perform a certain exploit, which they must do in a limited time.
#microsoft-patch-tuesday
fromThe Hacker News
4 months ago

China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines

Chinese-speaking threat actors are suspected to have leveraged a compromised SonicWall VPN appliance as an initial access vector to deploy a VMware ESXi exploit that may have been developed as far back as February 2024. Cybersecurity firm Huntress, which observed the activity in December 2025 and stopped it before it could progress to the final stage, said it may have resulted in a ransomware attack.
Information security
Apple
fromTheregister
5 months ago

Apple and Google forced into emergency patching 0-day

Apple and Google issued emergency patches for zero-day vulnerabilities actively exploited in sophisticated, targeted attacks.
Information security
fromThe Hacker News
5 months ago

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw

Update Chrome immediately to patch a high-severity, actively exploited vulnerability and multiple other zero-day and medium-severity flaws.
Information security
fromComputerworld
6 months ago

More work for admins as Google patches latest zero-day Chrome vulnerability

Zero-day Chrome vulnerabilities force enterprises to rush manual patches within days, disrupting regular eight-week ESC testing and causing significant operational strain.
Information security
fromDataBreaches.Net
8 months ago

CISA Emergency Directive 25-03: Identify and Mitigate Potential Compromise of Cisco Devices - DataBreaches.Net

Critical Cisco ASA zero-day vulnerabilities enable unauthenticated remote code execution and ROM persistence; agencies must immediately mitigate, assess compromise, and remediate ASA and Firepower devices.
Information security
fromThe Hacker News
8 months ago

Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

Threat actors exploited Cisco ASA zero-day vulnerabilities to deploy advanced RayInitiator and LINE VIPER malware, bypassing protections and achieving persistence.
fromZDNET
10 months ago

Microsoft fixes two SharePoint zero-days under attack, but it's not over - how to patch

CVE-2025-53771 is a SharePoint Server spoofing vulnerability allowing attackers to impersonate trusted users or resources, while CVE-2025-53770 permits remote code execution.
Privacy professionals
Privacy technologies
fromZDNET
11 months ago

Qualcomm patches three exploited security flaws, but you could still be vulnerable

Qualcomm has patched three critical zero-day security vulnerabilities related to its Adreno GPU driver, indicating ongoing exploitation risks.
[ Load more ]