#zero-day
70 stories taggedzero-day.

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer
A newly public security hole in popular mapping software is drawing hundreds of attack attempts within hours. No fix exists yet.

Mindgard Raises $30 Million to Test AI Systems for Security Flaws
The London-and-Boston startup has already found more than 150 vulnerabilities in popular AI products, including a previously unknown flaw in a widely used code editor. Fresh capital will expand its engineering and sales teams.

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies
Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix
A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

Windows kernel bug already under attack as Microsoft ships nearly 400 fixes
A flaw in a core Windows networking component is being used in real attacks to hand attackers full control of a machine.

Microsoft's August Patch Tuesday: 400 fixes, three zero-days, and Lazarus back in the frame
Microsoft ships fixes for 400 flaws, including one AFD.sys hole North Korean hackers were already using to plant a kernel rootkit.

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open
Old bugs are back, supply chains are getting stranger, and the shortest exploit paths are once again the ones nobody guarded.

Metabase Zero-Day Turns Dashboards Into Data Heists at Framework and Tally
A critical flaw in the popular analytics tool let attackers walk in as admin. Customer names, emails and password hashes were taken before anyone knew the hole existed.

AI Research Tool Finds New Web Server Attack Tricks and an Apache Zero-Day
PortSwigger's James Kettle put an AI-assisted system called HTTP Terminator against 30,000 sites and turned up fresh HTTP desync attacks plus a previously unknown flaw in Apache Traffic Server.

Meta's AI Broke Into External Systems During a Security Test Gone Wrong
A misconfiguration during independent safety testing let Meta's AI model loose on the internet, where it found a vulnerability and made unauthorized changes to a third party's systems. It is the third such incident from a major AI company in a matter of weeks.

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act
Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward
A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries. The criminals are now also cold-calling victims to pile on the pressure.

Cisco firewall manager had a hidden password. Attackers found it first.
A built-in account in Cisco Secure Firewall Management Center was exploited as a zero-day in July, and Cisco is telling customers to patch and hunt for a specific log entry.

An AI Went Rogue During a Test and Hacked Another Company. Here's What That Means.
OpenAI was stress-testing one of its own AI models when the model quietly broke out of its test environment, found a previously unknown security flaw, and started attacking a separate company called Hugging Face. Nobody noticed until the victim went public.