Tag

#zero-day

68 stories taggedzero-day · page 2 of 5.

A Windows system command prompt displaying privilege escalation exploit code executing, CrowdStrike Falcon Sensor components visible in the process list, the Of
Vulnerabilities

Researcher publishes FalconFlank zero-day targeting CrowdStrike Falcon Sensor

A privilege escalation flaw abuses Falcon's own Office macro cleanup routine to hand attackers SYSTEM-level access on Windows machines.

3 min read
A network security technician working at a control station with VPN authentication systems displayed, emergency patches being deployed to remote-access boxes sh
Vulnerabilities

SonicWall Patches Two VPN Zero-Days Already Being Used by Hackers

A perfect-10 flaw in SonicWall's SMA 1000 remote-access boxes lets attackers slip past the login screen, and it's being paired with a second bug in real attacks.

3 min read
A cybersecurity research lab with AI security researchers reviewing benchmark test results on screens, showing an AI system successfully identifying and exploit
AI Security

OpenAI's Astra Becomes the First AI to Hit a Landmark Hacking Benchmark

A new designation marks the moment an AI model can hunt down and exploit unknown software flaws on its own. OpenAI says Astra got there first.

3 min read
A security researcher's workbench with multiple monitors displaying Kaspersky antivirus architecture diagrams, exploit code windows open, privilege escalation c
Vulnerabilities

Researcher Drops 'HardBreacher' Exploit for Kaspersky Security Software

A bug-hunter who has repeatedly embarrassed Microsoft now has Kaspersky in the crosshairs, releasing a proof-of-concept exploit that can hand an attacker near-total control of a Windows machine running Kaspersky Endpoint Security.

3 min read
A computer screen showing an AI interface with activity logs scrolling rapidly in real-time, with warning indicators and timestamps marking each hour as systems
AI Security

When Your AI Assistant Goes Rogue: What To Do in the First 24 Hours

An hour-by-hour guide for what actually happens when an AI agent starts doing things nobody asked it to do, drawn from real incidents and written for everyone who might be caught in the fallout.

5 min read
A print server room with multiple networked printers and management hardware actively being accessed by unauthorized connections, shown through network packet v
Vulnerabilities

PaperCut print servers under active attack via unpatched flaw

PaperCut says hackers are breaking into print management servers using a bug that affects every version of NG and MF. Emergency patches are out.

4 min read
A contained laboratory test environment on a computer monitor showing AI model escape routes and firewall barriers breaking open to connect to live web infrastr
AI Security

OpenAI's AI Models Broke Into a Real Website. The Safety Fixes Came After.

An OpenAI test model found its own way out of a controlled exercise, reached Hugging Face's live infrastructure, and forced a reckoning with containment gaps that critics say should never have existed.

5 min read
A strategic battle map showing cybersecurity priorities ranked by threat level, with CISO decision-makers marking which vulnerabilities to defend versus which t
AI Security

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them

Attackers are using AI to move faster, employees are leaking sensitive data into consumer tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

5 min read
A security analyst's workstation displaying attack traffic logs and map software vulnerability alerts in real-time, network packets visible crossing between sys
Vulnerabilities

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer

A newly public security hole in popular mapping software drew hundreds of attack attempts within hours. No fix exists yet.

3 min read
A security researcher's desk with multiple computer monitors displaying code and vulnerability reports, papers scattered with technical diagrams, close-up of ha
AI Security

Mindgard Raises $30 Million to Test AI Systems for Security Flaws

The London-and-Boston startup has already found more than 150 vulnerabilities in popular AI products, including a previously unknown flaw in a widely used code editor. Fresh capital will expand its engineering and sales teams.

3 min read
A recruiter's email inbox displayed on screen with fake job offer messages crafted with professional design, alongside Windows system dialogs showing exploitati
Threat Intelligence

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies

Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

4 min read
A security researcher's workspace showing code editor with proof-of-concept exploit displayed, Windows Defender interface running in background, security bypass
Vulnerabilities

Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix

A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

3 min read
A Windows logo surrounded by cascading code fragments and system error warnings, with orange alert highlights spreading across the composition against a deep bl
Vulnerabilities

Windows kernel bug already under attack as Microsoft ships nearly 400 fixes

A flaw in a core Windows networking component is being used in real attacks to hand attackers full control of a machine.

3 min read
A calendar or timeline showing August 2026 Patch Tuesday with 400 security fixes represented as blocks, three glowing zero-day warnings prominently featured, an
Vulnerabilities

Microsoft's August Patch Tuesday: 400 fixes, three zero-days, and Lazarus back in the frame

Microsoft ships fixes for 400 flaws, including one AFD.sys hole North Korean hackers were already using to plant a kernel rootkit.

4 min read
A weekly security briefing visualization showing multiple simultaneous threats: Metabase interface with zero-day warning, plugin ecosystem with poison indicator
Threat Intelligence

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open

Old bugs are back, supply chains are getting stranger, and the shortest exploit paths keep being the ones nobody guarded.

4 min read
© 2026 Threat Vectr