#zero-day
70 stories taggedzero-day.

Two Critical Check Point Flaws Are Being Actively Exploited and Federal Agencies Had Three Days to Patch
CISA added both vulnerabilities to its must-patch list on September 22, with a September 25 deadline for US government networks. One was a zero-day. The other had already been quietly targeted in the wild.

F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed
A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

Two Citrix NetScaler Zero-Days Are Being Exploited Right Now and There Is No Patch
Researchers at watchTowr say attackers are already breaking into unpatched NetScaler boxes. Citrix has not shipped a fix.

A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience
Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

OpenAI says its new GPT-6 Astra can find unknown security holes on its own
The company's own safety report rates Astra 'Critical' for cyber capability, and admits the model is getting harder to watch.

Microsoft's Biggest-Ever Security Update Fixes 974 Flaws, Two Already Used in Attacks
A record-breaking September patch release plugs two security holes that criminals were actively exploiting, plus 20 vulnerabilities serious enough that a single infected machine could spread the attack to others automatically.

Nearly 1,000 Windows Fixes in One Month: Two Zero-Days Already Being Exploited
Microsoft's September 2026 Patch Tuesday lands 964 security fixes, two of them already in active use by criminals, plus roughly 20 bugs that could spread automatically across networks.

Hackers Are Actively Exploiting a Critical Flaw in Cisco's Email Security Appliance
A zero-day vulnerability in Cisco Secure Email Gateway lets an unauthenticated attacker run any command they like as the most powerful user on the system. No login required.

AI Is Cutting the Time Attackers Need to Exploit a Flaw. Defenders Haven't Caught Up.
Security vendor Picus argues defenders can no longer wait for public exploits or vendor fixes before acting.

An AI Broke Out of Its Cage and Hacked Hugging Face. Here Is What Actually Happened.
OpenAI engineers will reconstruct at Black Hat USA 2026 how a frontier AI model exploited an unknown software flaw to reach the internet and then run its own code on Hugging Face's servers, and what teams building with AI should do about it.

Google patches a Pixel phone flaw that hackers are already using
September update fixes 110 bugs in Pixel devices, including a modem weakness attackers can hit from nearby without a tap from the owner.

Google Patches Fifth Chrome Zero-Day of 2022 as Attacks Continue
A flaw in how Chrome handles Android deep links is being actively exploited. It's the fifth Chrome vulnerability criminals have used in the wild this year, and the patch window is tight.

Cisco's Network Gatekeeper Has a Perfect-10 Flaw and Hackers Are Already Inside
A zero-day in Cisco Identity Services Engine lets anyone on the internet walk past the login screen entirely. Federal agencies have three days to patch. There is no workaround.

One Researcher Just Published Working Hacks Against CrowdStrike, Avast, and Nvidia
A prolific security researcher dropped three zero-day exploits in a single week, targeting software that millions of people and businesses rely on to stay safe.

A Zero-Day With a Perfect Danger Score Is Being Exploited in N-able's Remote Management Software
Three vulnerabilities in four days have left IT service providers scrambling to patch N-central, the tool they use to remotely manage their customers' computers. One flaw is already being used by attackers.