#zero-day
68 stories taggedzero-day · page 2 of 5.

Researcher publishes FalconFlank zero-day targeting CrowdStrike Falcon Sensor
A privilege escalation flaw abuses Falcon's own Office macro cleanup routine to hand attackers SYSTEM-level access on Windows machines.

SonicWall Patches Two VPN Zero-Days Already Being Used by Hackers
A perfect-10 flaw in SonicWall's SMA 1000 remote-access boxes lets attackers slip past the login screen, and it's being paired with a second bug in real attacks.

OpenAI's Astra Becomes the First AI to Hit a Landmark Hacking Benchmark
A new designation marks the moment an AI model can hunt down and exploit unknown software flaws on its own. OpenAI says Astra got there first.

Researcher Drops 'HardBreacher' Exploit for Kaspersky Security Software
A bug-hunter who has repeatedly embarrassed Microsoft now has Kaspersky in the crosshairs, releasing a proof-of-concept exploit that can hand an attacker near-total control of a Windows machine running Kaspersky Endpoint Security.

When Your AI Assistant Goes Rogue: What To Do in the First 24 Hours
An hour-by-hour guide for what actually happens when an AI agent starts doing things nobody asked it to do, drawn from real incidents and written for everyone who might be caught in the fallout.

PaperCut print servers under active attack via unpatched flaw
PaperCut says hackers are breaking into print management servers using a bug that affects every version of NG and MF. Emergency patches are out.

OpenAI's AI Models Broke Into a Real Website. The Safety Fixes Came After.
An OpenAI test model found its own way out of a controlled exercise, reached Hugging Face's live infrastructure, and forced a reckoning with containment gaps that critics say should never have existed.

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them
Attackers are using AI to move faster, employees are leaking sensitive data into consumer tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer
A newly public security hole in popular mapping software drew hundreds of attack attempts within hours. No fix exists yet.

Mindgard Raises $30 Million to Test AI Systems for Security Flaws
The London-and-Boston startup has already found more than 150 vulnerabilities in popular AI products, including a previously unknown flaw in a widely used code editor. Fresh capital will expand its engineering and sales teams.

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies
Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix
A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

Windows kernel bug already under attack as Microsoft ships nearly 400 fixes
A flaw in a core Windows networking component is being used in real attacks to hand attackers full control of a machine.

Microsoft's August Patch Tuesday: 400 fixes, three zero-days, and Lazarus back in the frame
Microsoft ships fixes for 400 flaws, including one AFD.sys hole North Korean hackers were already using to plant a kernel rootkit.

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open
Old bugs are back, supply chains are getting stranger, and the shortest exploit paths keep being the ones nobody guarded.