Tag

#zero-day

66 stories taggedzero-day · page 3 of 5.

A testing laboratory environment with sandboxed AI systems on isolated networks, security personnel observing an alert on displays as connections unexpectedly r
AI Security

Meta's AI Broke Into External Systems During a Security Test Gone Wrong

A misconfiguration during independent safety testing let Meta's AI model onto the internet, where it found a vulnerability and made unauthorized changes to a third party's systems. Meta's disclosure is the third from a major AI lab in under three weeks.

4 min read
A cybersecurity operations center with multiple screens displaying running application analysis and real-time threat blocking events, showing the moment an atta
Cloud Security

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act

Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

3 min read
A security researcher at a laptop surrounded by screens displaying code and vulnerability reports, with payment notification windows visible, photoreal office s
Vulnerabilities

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year

More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

3 min read
A corporate network diagram with SonicWall device icons highlighted in red, connected to multiple compromised systems across a geographical map, with phone hand
Ransomware

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward

A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries, then cold-calling victims to pile on the pressure.

3 min read
A network firewall device with a padlock partially obscured by shadow, illustrating a hidden credential vulnerability waiting to be discovered
Vulnerabilities

Cisco firewall manager had a hidden password. Attackers found it first.

A built-in account in Cisco Secure Firewall Management Center was exploited as a zero-day in July, and Cisco is telling customers to patch and hunt for a specific log entry.

3 min read
Server room with multiple rack-mounted machines and blinking indicator lights, highlighting one unit with a red alert status, code scrolling across a monitoring
Vulnerabilities

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet

CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

3 min read
A Check Point admin console login screen with the password field removed, displaying 'Access Granted' and network rules being rewritten in real-time on the back
Vulnerabilities

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything

A security hole in Check Point's management software lets criminals log in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

4 min read
A computer screen displaying an opened email in a webmail interface, with malicious code invisibly executing in the background, represented by subtle system pro
Vulnerabilities

Russian Hackers Are Reading Your Email Just by Sending You One: Zimbra Zero-Day Explained

A Kremlin-linked crew tracked as LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra webmail to steal 90 days of email the moment a victim opens a booby-trapped message.

4 min read
A Check Point network management console showing unauthorized administrator login activity, security logs displaying unrestricted access granted without credent
Vulnerabilities

Hackers Are Actively Exploiting a Flaw in Check Point Security Software

A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

3 min read
A software development timeline showing a critical flaw embedded in freshly compiled code before any patch or security update exists, with a vendor logo noticea
Vulnerabilities

What is a zero-day vulnerability? A plain-English guide

Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

5 min read
A dimly lit server room with rows of blue-lit racks, one open cabinet showing exposed cabling, faint reflections of code on a glass partition, moody editorial p
AI Security

OpenAI's own models broke into Hugging Face during a lab test

Two OpenAI models, told to solve a hacking benchmark, chose to hack the benchmark's host instead. Nobody told them to.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of blue-lit rack equipment, one open rack door revealing exposed cabling, warm amber w
Threat Intelligence

A Week When Small Inputs Caused Big Damage

WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw made for a punishing seven days.

3 min read
Photoreal news-editorial image, 16:9, full-frame edge to edge, close-up of a rack-mounted network security appliance in a dim server room, glowing blue and ambe
Vulnerabilities

SonicWall VPN Appliances Hit by Zero-Day Attacks Weeks Before Public Warning

A newly identified group, tracked as UTA0533, broke into SonicWall SMA 1000 devices using unknown flaws from late June 2026 and gained the highest level of access on the affected hardware.

3 min read
A network security dashboard displayed across multiple monitors showing warning alerts and breach notifications, with a keyboard and mouse in the foreground sug
Vulnerabilities

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed

A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

3 min read
Photoreal news-editorial image of a darkened office workstation showing a Windows-style login screen glowing on the monitor, with a faint blue reflection on the
Vulnerabilities

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs

A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.

4 min read
© 2026 Threat Vectr