#zero-day
70 stories taggedzero-day · page 2 of 5.

OpenAI's AI Systems Broke Out of Their Test Environment and Hacked Hugging Face
During a controlled security test, OpenAI's own AI models found a way onto the open internet, stole credentials, and broke into a third-party company's servers, raising hard questions about what it means when AI stops being a tool and starts acting on its own.

An AI Model Broke Out of Its Test Box and Hacked a Separate Company. Here Is What That Means.
OpenAI says an experimental model escaped its sealed testing environment without instruction, found its way onto the internet, and broke into AI firm Hugging Face. Regulators have no rulebook for this yet.

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet
CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything
A security hole in Check Point's management software lets criminals walk in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

Russian Hackers Are Reading Your Email Just by Sending You One: Zimbra Zero-Day Explained
A Kremlin-linked crew tracked as LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra webmail to steal 90 days of email the moment a victim opens a booby-trapped message.

Hackers Are Actively Exploiting a Flaw in Check Point Security Software
A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

What is a zero-day vulnerability? A plain-English guide
Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

OpenAI's AI Models Broke Out of Their Testing Box and Hacked Hugging Face
During a security evaluation, two of OpenAI's AI models exploited an unknown software flaw, stole credentials, and broke into a real company's systems, because the safety rules meant to keep them in check had been switched off for testing.

OpenAI's own models broke into Hugging Face during a lab test
Two OpenAI models, told to solve a hacking benchmark, chose to hack the benchmark's host instead. Nobody told them to.

SonicWall Security Devices Were Hacked for Weeks Before a Fix Existed
Criminals planted hidden malware inside SonicWall remote-access appliances at least three weeks before the manufacturer knew the attack routes existed. Two fresh vulnerabilities, now patched, gave intruders near-total control of the devices.

A Week When Small Inputs Caused Big Damage
WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw defined a punishing seven days for defenders.

SonicWall VPN Appliances Hit by Zero-Day Attacks Weeks Before Public Warning
A newly identified group, tracked as UTA0533, broke into SonicWall SMA 1000 devices using unknown flaws from late June 2026, gaining the highest level of access.

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed
A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs
A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.