- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates 2026-09-22 20:39 The Hacker News Swati KhandelwalSep 22, 2026Vulnerability / Endpoint Security A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19 …
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks 2026-09-22 20:39 The Hacker News Swati KhandelwalSep 22, 2026Network Security / Vulnerability Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows …
- Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistant 2026-09-22 19:16 Gizmodo Meta’s do-it-all AI assistant Muse launched two weeks ago, and the company has already had to patch a pretty serious zero-day vulnerability in its app for Mac computers. David Singleton, who works at Meta Superintelligence Labs, said shortly after midnight …
- Meta’s Muse reportedly has zero-day vulnerability that lets attackers take over your Mac 2026-09-22 16:21 Mashable SE Asia Meta launched its new AI assistant Muse to much fanfare earlier this month. Now, just a few weeks later, a zero-day vulnerability has reportedly been discovered that could put access to your entire Mac computer in the wrong hands. (Meta currently does not …
- Muse tops ChatGPT, then zero-day flaw emerges 2026-09-22 16:18 Ynet Meta has scored an early success in the artificial intelligence race, with its new AI agent Muse climbing to the top of download charts less than two weeks after launch and, in initial figures, even outpacing ChatGPT, Claude and Grok. Muse launched on …
- Meta Muse already has a majorly worrying zero-day security issue 2026-09-22 13:47 TechRadar Pro Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Researcher Patrick Wardle finds zero‑day in Meta’s new Muse AI assistant, Dubbed not‑a‑mused, the exploit requires local compromise, voice dictation, and app …
- Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits 2026-09-22 11:48 Cyber Security News Hackers are using convincing copies of trusted websites to turn an ordinary browser visit into a full Windows compromise. The campaign pairs targeted phishing emails with a chained set of previously unknown flaws in Google Chrome and Microsoft Windows, …
- Zero-day is being exploited: Google urgently advises Pixel users to update 2026-09-22 10:12 RS News Google has closed a zero-day security flaw in Pixel smartphones that the company says has already been exploited in some limited and targeted attacks. Targeted attacks The vulnerability listed under CVE-2026-58704 is in the cellular modem of the devices …
- Meta Muse AI Assistant Suffers From Zero-Day Vulnerability Despite Promise of Privacy and Security 2026-09-22 06:43 Tech Times Meta's ambitious personal AI agent is facing its first real security test just weeks after launch. A researcher managed to find a way around the very safeguards Meta built to keep the assistant from being manipulated, raising fresh questions about how …
- Researchers warn of Safari zero-day exploit targeting Apple iPhones and crypto wallets 2026-09-21 16:42 Crypto Briefing A full-chain iOS exploit can silently extract private keys and seed phrases from crypto wallets, affecting devices running iOS 13 through 26.5. A critical security vulnerability is making its way through Apple’s mobile ecosystem, and the target is not just …
- ShinyHunters vs Cl0p: Cybercrime Feud Over Oracle Zero-Day Spills Into the Open 2026-09-21 11:50 Technology Org ShinyHunters Versus Cl0p Two of the world’s most prolific data-extortion crews are fighting over who deserves credit for an Oracle software bug. ShinyHunters says rival gang cl0p stole its exploit for a flaw in Oracle’s E-Business Suite last year. On …
- Cisco Zero-Day Highlights API Endpoint Authentication Issues 2026-09-18 21:04 Dark Reading Cisco this week disclosed a slew of critical security vulnerabilities impacting its Identity Services Engine (ISE), including a maximum-severity zero-day flaw that's under exploitation. CVE-2026-76460 is an authentication bypass vulnerability impacting …
- BlueMoon Zero-Day Exploit Kit Chains Chrome and Windows Flaws 2026-09-18 02:48 Cybersecurity Insiders Four state-aligned espionage crews picked up the same zero-day exploit kit within roughly twelve days of each other, Proofpoint reported, naming the kit BlueMoon. It chains two Google Chrome flaws with a Windows kernel bug to take over a browser that …
- Cisco alerts customers to second actively exploited zero-day in as many days 2026-09-18 02:00 CyberScoop Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a maximum-severity rating and was …
- Google patches a Pixel modem zero-day used in limited targeted attacks 2026-09-18 01:54 ZoomBangla iNews Google says a modem vulnerability in supported Pixel phones was used in limited, targeted attacks. The flaw is tracked as CVE-2026-58704 and was included in the September Pixel security work. The report uses Pixel modem as its central search phrase. …
- Cisco Identity Services Engine Zero-Day (CVE-2025-20281) Actively Exploited — Patch Immediately 2026-09-17 22:00 WebProNews - Kentucky Cisco has disclosed a maximum-severity zero-day vulnerability in its Identity Services Engine that is already being actively exploited in the wild. Security teams responsible for enterprise network access control should treat the flaw as an immediate …
- Cisco patches max-severity ISE flaw, the second critical zero-day this week 2026-09-17 21:24 Network World Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco …
- Cisco hit by max severity zero-day exploit targeting Identity Services Engine, so it's time to patch up 2026-09-17 14:32 TechRadar Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Cisco fixed critical ISE flaw (CVE‑2026‑76460) allowing unauthenticated API authentication bypass Actively exploited; no workarounds exist—patching is the only …
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks 2026-09-17 13:49 The Hacker News Ravie LakshmananSep 17, 2026Vulnerability / Web Security Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS …
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day 2026-09-17 10:23 SecurityWeek Cisco on Wednesday released urgent patches for a critical-severity authentication bypass vulnerability in Identity Services Engine (ISE) that has been exploited in the wild as a zero-day. Tracked as CVE-2026-76460 (CVSS score of 10/10), the security …
- Pixel phones targeted in zero-day attacks: Google urges users to update now 2026-09-17 06:23 Business Today Google has not disclosed details about who may be behind the exploitation or how the attacks are being carried out. However, its security bulletin indicates that the vulnerability may already be actively targeted. Pixel users should check the latest …
- Zero-day flaws in TP-Link security cameras could let hackers eavesdrop on you — but there's a fix 2026-09-16 23:23 Tom's Guide Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter If you use a TP-Link Tapo C200 camera, you'll want to update its firmware right away. Security researchers OPSWAT recently released details of two zero-day …
- Pixel Modem Zero-Day Exploited in Targeted Attacks 2026-09-16 18:51 SecurityWeek Google on Tuesday informed Pixel phone owners that it has patched a zero-day vulnerability exploited in targeted attacks. The zero-day is tracked as CVE-2026-58704, and Google said it’s aware of “limited, targeted exploitation”. The vulnerability has been …
- Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks 2026-09-16 18:29 Security Affairs Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its …
- Hackers exploit zero-day flaw in Cisco email gateway 2026-09-16 18:15 Cybersecurity Dive - Massachusetts Cisco is urging customers to immediately patch a critical vulnerability in Cisco Secure Email Gateway, which has already been exploited in the wild. The zero-day flaw can allow an unauthenticated hacker to execute arbitrary commands using root privileges …
- Google says some Pixel phone owners were hacked in zero-day attacks 2026-09-16 14:56 TechCrunch Google says that a bug in its Pixel smartphones’ software was exploited in limited and targeted cyberattacks. The company said Tuesday that the bug, tracked as CVE-2026-58704, has now been patched. According to the limited details about the vulnerability …
- Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping 2026-09-16 10:00 Infosecurity Magazine Security researchers have released details of two zero-day vulnerabilities found in TP-Link security cameras commonly used in home and small offices, one of which could enable attackers to spy on users. OPSWAT said the bugs affect the TP-Link Tapo C200 …
- Critical Cisco Secure Email Gateway zero-day gives attackers root access 2026-09-15 20:13 Network World If exploitation is suspected on physical devices, Cisco recommends contacting the Cisco Technical Assistance Center. For virtual devices, customers are advised to save all forensic information then deploy a new instance with rebuilt configuration and …
- Cisco warns customers of actively exploited zero-day in email gateways 2026-09-15 18:20 CyberScoop Attackers of unknown origins and motivations are exploiting a critical zero-day vulnerability in Cisco Secure Email Gateway, authorities and researchers said Monday. The vulnerability — CVE-2026-76461 — was exploited before Cisco disclosed and patched …
- Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day 2026-09-15 16:41 Security Affairs Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026- …
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) 2026-09-15 13:13 Help Net Security Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of …
- Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation 2026-09-15 09:44 SecurityWeek Cisco warned customers on Monday that a zero-day vulnerability affecting Secure Email Gateway appliances has been exploited in the wild. The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco describes it as an email parsing …
- Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk 2026-09-15 09:26 Security Affairs Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed …
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE 2026-09-15 05:43 The Hacker News A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat …
- China-linked hackers deploy chained Chrome-Windows zero-day exploits 2026-09-13 08:55 Arabian Post China-linked threat actors have been caught chaining two Google Chrome flaws with a Windows kernel vulnerability to compromise selected targets, including non-governmental organisations, in espionage campaigns detected this month.Cybersecurity firm …
- China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks 2026-09-12 14:24 GBHackers China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, …
- New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender 2026-09-10 12:19 SecurityWeek The security researcher known as Nightmare Eclipse has released another Microsoft Defender zero-day exploit, right after Microsoft’s record-breaking September 2026 patches. Dubbed ‘ShieldCrash’, the exploit targets fully patched Windows systems for …
- Hosted.com Adds Monarx and Imunify360 to Counter Zero-Day Website Threats 2026-09-10 09:00 EIN Presswire Hosted.com has integrated Monarx and Imunify360 across its hosting platform, pairing runtime behavioral prevention with signature-based malware scanning. CA, UNITED STATES, September 10, 2026 /EINPresswire.com/ -- Hosted.com has integrated two …
- Google Chrome 153 patches a zero-day under active attack, restart required 2026-09-10 08:02 Notebook Check Google promoted Chrome 153 to the stable channel on Tuesday. The release includes 230 security fixes, and Google rates five of them critical. One line further down the page matters more than any severity rating. "Google is aware that an exploit for …
- Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days 2026-09-10 06:08 Security Affairs Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome- …
- Multiple Chinese hacking groups seen using identical Chrome zero-day exploit 2026-09-09 19:14 The Record At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week, cybersecurity firm Proofpoint said …
- Google fixes the seventh actively exploited Chrome zero-day of 2026 2026-09-09 18:17 Security Affairs Google fixes the seventh actively exploited Chrome zero-day of 2026 Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 …
- Google Fixes 230 Chrome Vulnerabilities, Including Active Zero-Day 2026-09-09 11:59 WindowsReport.com Google has fixed 230 Chrome vulnerabilities with the release of Chrome 153, including a zero-day that attackers are already exploiting in the wild. The flaw, tracked as CVE-2026-87491, affects Chrome’s V8 engine and marks the seventh actively exploited …
- Chrome 153 Patches Seventh Zero-Day of 2026 2026-09-09 10:53 SecurityWeek Google on Tuesday released Chrome 153 to the stable channel with patches for 230 vulnerabilities, including an exploited zero-day. Tracked as CVE-2026-87491, the medium-severity security defect is described as an out-of-bounds write issue in Chrome’s V8 …
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox 2026-09-09 10:46 The Hacker News Ravie LakshmananSep 09, 2026Vulnerability / Browser Security Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned …
- ShieldCrash Zero-Day Exploit Works Even on Fully Updated Windows Systems 2026-09-09 10:46 WindowsReport.com Microsoft Defender zero-day ShieldCrash has been released shortly after Microsoft shipped its September 2026 Patch Tuesday security updates. Security researcher Nightmare Eclipse published the new proof-of-concept, describing ShieldCrash as a bypass for a …
- Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day 2026-09-09 10:39 Security Affairs Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, …
- Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day 2026-09-09 10:33 Security Affairs Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE …
- Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) 2026-09-09 09:50 Help Net Security Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has …
- September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows 2026-09-09 03:31 CSO Tyler Reguly, Fortra’s associate director of security R&D, pointed out that as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning. “This is not a Microsoft-specific problem,” he noted. “We see the same …