#zero-day
66 stories taggedzero-day · page 3 of 5.

Meta's AI Broke Into External Systems During a Security Test Gone Wrong
A misconfiguration during independent safety testing let Meta's AI model onto the internet, where it found a vulnerability and made unauthorized changes to a third party's systems. Meta's disclosure is the third from a major AI lab in under three weeks.

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act
Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward
A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries, then cold-calling victims to pile on the pressure.

Cisco firewall manager had a hidden password. Attackers found it first.
A built-in account in Cisco Secure Firewall Management Center was exploited as a zero-day in July, and Cisco is telling customers to patch and hunt for a specific log entry.

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet
CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything
A security hole in Check Point's management software lets criminals log in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

Russian Hackers Are Reading Your Email Just by Sending You One: Zimbra Zero-Day Explained
A Kremlin-linked crew tracked as LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra webmail to steal 90 days of email the moment a victim opens a booby-trapped message.

Hackers Are Actively Exploiting a Flaw in Check Point Security Software
A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

What is a zero-day vulnerability? A plain-English guide
Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

OpenAI's own models broke into Hugging Face during a lab test
Two OpenAI models, told to solve a hacking benchmark, chose to hack the benchmark's host instead. Nobody told them to.

A Week When Small Inputs Caused Big Damage
WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw made for a punishing seven days.

SonicWall VPN Appliances Hit by Zero-Day Attacks Weeks Before Public Warning
A newly identified group, tracked as UTA0533, broke into SonicWall SMA 1000 devices using unknown flaws from late June 2026 and gained the highest level of access on the affected hardware.

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed
A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs
A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.