Advertisement
CVE-2026-33825: BlueHammer Zero-Day in Microsoft Defender Exploited by Ransomware
Analysis of the BlueHammer zero-day, CVE-2026-33825, in Microsoft Defender, actively exploited by ransomware groups. Learn detection and mitigation strategies.
ShinyHunters Breach NAIC via PeopleSoft Zero-Day: Public Data Stolen
ShinyHunters exploited an Oracle PeopleSoft zero-day to breach NAIC, exfiltrating public data, logs, and configuration files. Review PeopleSoft security.
Nissan Breach: Oracle PeopleSoft Zero-Day Exploited by ShinyHunters
Nissan discloses a data breach impacting current and former employees, attributed to an exploited Oracle PeopleSoft zero-day vulnerability linked to the ShinyHunters…
CVE-2026-20245: Zero-Day Root Privilege Escalation in Cisco SD-WAN
Attackers are exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN Manager to gain root access. Learn how to detect and remediate CVE-2026-20245.
Cisco Catalyst SD-WAN CVE-2026-20245 Root Access Exploit Analysis
Exploitation of Cisco Catalyst SD-WAN zero-day CVE-2026-20245 allows root access. Mandiant reveals active abuse months prior to the June 2026 disclosure.
Cisco SD-WAN CVE-2023-20252 Exploited via Rogue Peering - Patch Now
Attackers exploited Cisco SD-WAN Manager flaws like CVE-2023-20252 for two months before disclosure. Learn how to secure your vManage infrastructure today.
Advertisement
Proactive Exploit Validation: Mitigating Rapidly Weaponized Vulnerabilities
Security teams face rapidly weaponized vulnerabilities. Learn how to proactively validate exploitability and fortify defenses against emerging threats, even before…
CVE-2026-20262: Cisco SD-WAN vManage Root Privilege Escalation Fix
Cisco patches CVE-2026-20262, a critical Zero-Day flaw in Catalyst SD-WAN Manager allowing authenticated attackers to escalate to root privileges.
ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed
ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.
CVE-2026-35273: Oracle PeopleSoft RCE Exploited as Zero-Day by ShinyHunters
Mandiant and GTIG identified ShinyHunters (UNC6240) exploiting CVE-2026-35273, a critical RCE in Oracle PeopleSoft, targeting higher education.
Ivanti Sentry Max-Severity Flaw Exploited Within 24 Hours
A critical Ivanti Sentry vulnerability was actively exploited within 24 hours of public disclosure. Defenders must patch immediately to prevent compromise.
CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters
Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.
Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges
Analysis of 'RoguePlanet' zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.
Google Patches CVE-2026-11645: 5th Chrome Zero-Day Exploited in 2026
Google addresses CVE-2026-11645, a critical zero-day vulnerability in Chrome being actively exploited. Learn about patch guidance and detection strategies.
CVE-2024-4947: Google Patches Fifth Chrome Zero-Day of 2024
Google addresses CVE-2024-4947, a high-severity V8 type confusion vulnerability in Chrome being exploited in the wild. Update to version 125.0.6422.60 now.
CVE-2024-24919: Check Point VPN Zero-Day Exploited by Qilin Affiliate
Check Point Security Gateway vulnerability CVE-2024-24919 is being exploited in the wild, enabling unauthenticated information disclosure and network access.
CVE-2024-24919: Qilin Ransomware Gang Exploits Check Point VPN Zero-Day
Check Point confirms that the Qilin ransomware group exploited CVE-2024-24919, a critical flaw in VPN gateways, to gain unauthorized network access.
Cisco Catalyst SD-WAN Manager RCE via CVE-2024-20468 — Patch Now
Cisco warns of a high-severity zero-day vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2024-20468, currently exploited for root privilege escalation.
VS Code Zero-Day Exploit: Stealing GitHub Tokens via URI Handlers
Security researcher mthcht reveals a VS Code zero-day vulnerability allowing GitHub token theft via URI handlers. Learn how to defend against this exploit.
CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day
Google's June 2026 security update fixes 124 vulnerabilities, including CVE-2025-48595, a zero-day privilege escalation flaw under active exploitation.
Windows 11 BitLocker Bypass: Nightmare Eclipse Exploit Analysis
Microsoft threatens legal action against researcher Nightmare Eclipse after the release of a Windows 11 BitLocker bypass. Learn how to detect and mitigate.
Android June 2024 Update: CVE-2024-32896 Zero-Day Exploit Patched
Google fixes 124 vulnerabilities including an actively exploited Pixel firmware zero-day and critical RCE flaws in the June 2024 Android security update.
Microsoft's Zero-Day Disclosure Stance Sparks Industry Debate
Microsoft's legal threats against a researcher for Zero-Day exploit disclosure spark industry backlash, prompting scrutiny of responsible disclosure practices.
VMware Workspace ONE Access RCE via CVE-2022-22960 — Patch Now
VMware Workspace ONE Access and Identity Manager face critical RCE vulnerabilities (CVE-2022-22960, CVE-2022-22957) actively exploited.