Advertisement
Gogs Self-Hosted Git RCE via Zero-Day: Mitigation Guide
An unpatched zero-day vulnerability in Gogs self-hosted Git service allows attackers to achieve remote code execution, impacting Internet-facing instances.
Microsoft Condemns Public Zero-Day Disclosures, Advocates CVD
Microsoft reiterates strong support for Coordinated Vulnerability Disclosure, criticizing immediate public zero-day disclosures after a researcher's account removal.
CVE-2023-41179: Trend Micro Apex One RCE Exploited in Attacks
Trend Micro patches CVE-2023-41179, a critical zero-day in Apex One and Worry-Free Business Security exploited to execute arbitrary commands on Windows systems.
CVE-2026-34926: TrendAI Apex One Directory Traversal Exploit Analysis
TrendAI patches a critical zero-day directory traversal vulnerability (CVE-2026-34926) in Apex One on-premise currently exploited in the wild.
AI-Assisted macOS Kernel Exploit on Apple M5 Hardware
Security researchers used Anthropic’s Mythos AI to develop a macOS kernel memory corruption exploit for the Apple M5 chip in just five days. Patch now.
Chromium RCE Risk: Unfixed Flaw Allows Background JavaScript
Google accidentally exposed details of an unfixed Chromium flaw. This enables RCE via persistent background JavaScript execution, affecting many browsers.
Advertisement
Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis
Recent intelligence highlights a surge in Linux rootkits and router zero-day vulnerabilities targeting trusted system components and AI-driven intrusions.
CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus
Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.
YellowKey Zero-Day: Mitigating BitLocker Encryption Bypasses in Windows
Microsoft releases mitigation guidance for the YellowKey zero-day, a Windows BitLocker vulnerability allowing unauthorized access to encrypted data volumes.
CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack
Active Zero-Day XSS vulnerability, CVE-2026-42897, impacts Microsoft Exchange OWA, allowing mailbox compromise. No patch available.
Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use
Critical security briefing on the active exploitation of an Exchange Server zero-day, npm supply chain worms, and Cisco network control vulnerabilities.
MiniPlasma 0-Day: Windows SYSTEM Privilege Escalation via cldflt.sys
Technical analysis of the MiniPlasma zero-day vulnerability in cldflt.sys enabling SYSTEM privilege escalation on fully patched Windows systems.
Pwn2Own Berlin 2026: Critical RCE and Escalation Targets Identified
Security researchers demonstrate critical zero-day exploits against Windows, VMware, and AI systems at Pwn2Own Berlin 2026, earning over $1.3 million.
Windows MiniPlasma Zero-Day Exploit: How to Mitigate LPE Threats
A new zero-day exploit dubbed MiniPlasma allows local attackers to gain SYSTEM privileges on fully patched Windows systems. Learn detection and mitigation steps.
Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits
Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.
CVE-2026-42897: Microsoft Exchange Server Zero-Day Exploited in Wild
Microsoft warns of CVE-2026-42897, a critical Exchange Server zero-day exploited in the wild. Implement Extended Protection mitigations immediately to secure systems.
CVE-2024-49040: Microsoft Exchange Server Spoofing Vulnerability
Microsoft warns of CVE-2024-49040, a zero-day spoofing vulnerability in Exchange Server exploited to bypass security filters and impersonate trusted senders.
Cisco SD-WAN RCE via CVE-2026-20182 — Mitigation Guide
Cisco patches CVE-2026-20182, the sixth SD-WAN zero-day exploited in 2026. Learn how threat actor UAT-8616 leverages this flaw for targeted attacks.
CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server
Microsoft warns of active exploitation of CVE-2026-42897, a critical spoofing and XSS vulnerability in on-premise Exchange Server triggered via email.
Cisco Catalyst SD-WAN Controller Authentication Bypass via CVE-2026-20182 Exploited in Zero-Day Attacks
Cisco warns of a critical authentication bypass in Catalyst SD-WAN Controller (CVE-2026-20182) actively exploited in zero-day attacks, granting admin access.
Windows BitLocker Zero-Day Bypass and Privilege Escalation PoC Released
Security researcher releases PoC for YellowKey and GreenPlasma, unpatched vulnerabilities allowing BitLocker bypass and SYSTEM privilege escalation on Windows.
AI-Developed Zero-Day 2FA Bypass: Analyzing Google's Disclosure
Google identifies the first in-the-wild zero-day exploit for 2FA bypass developed using AI, signaling a shift in cybercriminal vulnerability discovery.
AI-Augmented Zero-Day Exploitation and Autonomous Malware Orchestration
GTIG report reveals how threat actors leverage generative AI for zero-day discovery, autonomous Android malware orchestration, and AI supply chain attacks.
Google’s Big Sleep AI Agent Discovers Real-World SQLite Zero-Day
Google Project Zero and DeepMind’s Big Sleep agent identifies an exploitable stack-based buffer underflow in SQLite, marking a shift in AI vulnerability discovery.