#zero-day
66 stories taggedzero-day · page 4 of 5.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

AI Is Finding Software Flaws Faster Than Companies Can Fix Them. Something Has to Change.
Security experts are calling time on the old 'scan once a month, patch when you can' model. Artificial intelligence now finds vulnerabilities faster than human teams can close them.

Nightmare Eclipse Releases 'LegacyHive' Windows Zero-Day on Patch Tuesday
A prolific anonymous researcher drops another unpatched Windows flaw, this time one that lets ordinary users quietly read administrator account data.

Intruder's AI 'vulnerability vending machine' finds a WordPress zero-day on its own
A security firm wired large language models into code-analysis tools and produced a working exploit for an unknown plugin flaw. It says more disclosures are on the way.

569 Patches in One Month: Microsoft Just Broke Every Record on the Books
AI tools are finding software flaws faster than any human team ever could. The result is a single monthly update that dwarfs every full-year fix count from the past two decades.

SonicWall says two SMA1000 flaws are being used in live attacks
One bug scores a perfect 10 on the severity scale. Federal agencies have until 17 July 2026 to patch or pull the plug.

Microsoft ships Windows 10 KB5099539 as record 570-flaw Patch Tuesday lands
The July 2026 update patches two actively exploited zero-days and quietly extends free security fixes for home users into 2027.

Microsoft ships fixes for 570 flaws in July, including two bugs already used in attacks
The July 2026 Patch Tuesday is the largest on record, driven partly by an AI system Microsoft is using to hunt bugs in Windows.

Progress ShareFile zero-day forced emergency server shutdowns; patch is out
A path traversal flaw in Storage Zone Controllers let admin users read and write files they shouldn't. Progress says no customer breach has been found.

Hackers Are Breaking Into Websites Through Two Popular Joomla Add-Ons
Two widely used plugins for the Joomla website-building platform have critical security flaws that let criminals take full control of a site without needing a password. Patches exist, but attacks started before most site owners knew there was a problem.

US Cyber Agency Flags Two Joomla Add-On Flaws Already Being Exploited
CISA says attackers are actively abusing critical bugs in the iCagenda and Balbooa extensions, both carrying the maximum severity score.

12.2 Million People Hit by Data Breach at Japanese Telecom Giant KDDI
A previously unknown flaw in email software exposed the addresses and passwords of millions of customers across five internet providers. Mandatory password resets are now underway.

Three Quick Hits: Canadian Hacker Jailed, Open-Source Flaws Dropped, ATM Jackpotters Sentenced
A week's worth of security stories that deserve a second look, from an Anonymous-linked arrest in Canada to cash-machine criminals facing US prison time.

Google Patches Fifth Chrome Zero-Day of 2022 as Hackers Actively Exploit the Flaw
A flaw in how Chrome handles a mobile-linking feature is being weaponised in real attacks. It's the fifth time this year Google has had to rush out an emergency fix for its browser.

Apple Pushes Emergency Fixes for Two Flaws Already Being Used to Attack iPhones and Macs
Two previously unknown security holes, one in the heart of Apple's operating system and one in its browser engine, are being actively exploited. Every iPhone, iPad, and Mac owner should update today.