- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores 2026-09-05 21:37 The Hacker News Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on …
- Google’s Sixth Chrome Zero-Day of 2026 Exposes Browser Fragility as EU Rules Loom 2026-09-05 15:49 WebProNews - Kentucky Google pushed out Chrome version 152.0.7977.82 this week. The update fixes a dozen security holes. One stands out. CVE-2026-85046. A type confusion flaw in the V8 JavaScript engine. Attackers already use it in the wild. The company confirmed the …
- Chrome Patches Sixth Zero-Day Of 2026 As V8 Compiler Exploit Hits Wild 2026-09-05 15:36 Tech Times Google confirmed Thursday that attackers were already exploiting a type confusion flaw in Chrome's V8 JavaScript engine before a patch existed, marking the sixth zero-day of 2026 — and the third to target V8 directly — a pattern security analysts say …
- CrowdStrike Falcon Zero-Day Turns Enterprise Security Agent Into Attack Surface 2026-09-05 15:36 Tech Times A researcher who has spent months systematically exploiting the security software trusted to protect Windows machines turned that same logic against CrowdStrike Falcon this week — publishing working exploit code for a previously unknown privilege …
- Google Confirms Sixth Chrome Zero-Day Exploit in 2026 as Browser Attacks Mount 2026-09-04 23:31 WebProNews - Kentucky Google just shipped another urgent Chrome update. Attackers already use the flaw in real operations. The company confirmed an exploit exists in the wild for a high-severity bug in its V8 JavaScript engine. Users must update now. The vulnerability, tracked …
- Google Patches 6th Chrome Zero-Day of 2026 2026-09-04 17:29 SecurityWeek Google on Thursday rolled out fresh Chrome 152 security updates that resolve 12 vulnerabilities, including an exploited zero-day. Tracked as CVE-2026-85046, the high-severity bug is described as a type confusion issue in Chrome’s V8 JavaScript and …
- Google Confirms Active Chrome Zero-Day Attacks as Emergency Fix Rolls Out 2026-09-04 14:10 WindowsReport.com Google has patched an actively exploited Chrome zero-day affecting the browser’s V8 JavaScript and WebAssembly engine. The company confirmed that an exploit for CVE-2026-85046 exists in the wild. The fix is now rolling out to Chrome 152 users on Windows, …
- Google patches actively exploited Chrome zero-day (CVE-2026-85046) 2026-09-04 12:19 Help Net Security Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security …
- Google fixes the sixth actively exploited Chrome zero-day of 2026 2026-09-04 11:15 Security Affairs Google fixes the sixth actively exploited Chrome zero-day of 2026 Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing …
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day 2026-09-04 07:38 The Hacker News Ravie LakshmananSep 04, 2026Vulnerability / Browser Security Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE- …
- OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests 2026-09-04 05:59 GBHackers OpenAI has introduced GPT-6 Astra, a groundbreaking model that has reportedly achieved perfect results on ExploitBench and demonstrated improved controls during cybersecurity testing. This announcement positions Astra as a significant advancement in …
- Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell 2026-09-03 16:05 GBHackers A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This vulnerability allows an attacker to dump the Windows Security Account Manager (SAM) database and launch a …
- OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI 2026-09-03 00:21 Security Affairs OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity …
- AI closes vulnerability window as zero-day exploits surge 2026-09-02 16:10 IT Brief - New Zealand For years, security teams have assumed that some vulnerabilities stay hidden because they're too buried, too old, too proprietary or based on too obscure interactions for humans or traditional tools to find. AI is challenging that assumption. Frontier …
- SonicWall SMA 1000 appliances under attack via zero-day flaws 2026-09-02 11:52 Help Net Security Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a …
- Hackers Chain Two New SonicWall Zero-Day Vulnerabilities 2026-09-02 09:25 Infosecurity Magazine SonicWall has notified customers of two new zero-day vulnerabilities that are being exploited in the wild, one of which is a maximum-severity flaw. A security advisory published by the vendor on September 1 revealed that the bugs affect SMA1000 appliances …
- OpenAI’s New Astra AI Can Discover Zero-Day Security Flaws and Build Exploits 2026-09-02 07:28 Cyber Security News OpenAI says its upcoming Astra model has reached the company’s Critical cybersecurity capability threshold, meaning it can independently discover unknown vulnerabilities and develop working exploits against hardened systems when given the right tools and …
- Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher 2026-09-01 10:41 Security Affairs Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known …
- HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation 2026-09-01 01:34 GBHackers A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by a GitHub user …
- Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities 2026-08-31 12:32 GBHackers Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving print …
- PaperCut Zero-Day Exploit: NG, MF Vulnerability Warning 2026-08-28 15:28 Asume Tech Active Exploitation Warning: PaperCut has confirmed a zero-day vulnerability in NG and MF software allowing unauthenticated remote Java code execution. Emergency Remediation: Priority patches are available for versions 25 and 26, while administrators are …
- PaperCut Releases Emergency Patch for Exploited Zero-Day 2026-08-28 12:18 SecurityWeek PaperCut Software is warning users of its NG and MF print management solutions that a zero-day vulnerability is being exploited in the wild. The flaw has yet to be assigned a CVE identifier and no technical details have been shared. The vendor released …
- PaperCut Zero-Day Under Active Attack: Emergency Patch Released 2026-08-28 12:03 Security Affairs PaperCut Zero-Day Under Active Attack: Emergency Patch Released PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it. PaperCut Software warns that attackers are actively exploiting a …
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions 2026-08-28 08:40 The Hacker News Ravie LakshmananAug 28, 2026Vulnerability / Enterprise Security PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day …
- PaperCut NG/MF vulnerabilities exploited in zero-day attacks 2026-08-27 12:03 Help Net Security Two vulnerabilities (CVE-2026-82078, CVE-2026-81578) affecting print management solutions PaperCut NG and PaperCut MF are being exploited by attackers, PaperCut Software has warned. “We are aware of confirmed customer incidents and are treating this matter …
- MOVEit Zero-Day Breach Exposes Data of 2,500 Organizations Worldwide 2026-08-21 13:54 WebProNews - Kentucky A massive data breach has exposed terabytes of sensitive information from government agencies, major corporations, and critical infrastructure operators after attackers compromised a widely used file transfer service. The incident, first reported by …
- Waratek Launches Reflection Protection, a Zero-Configuration Defense Against Known & Zero-Day Reflection Attacks 2026-08-18 07:30 EIN Presswire The new Reflection Protection rule protects apps and dependencies against reflection attacks from known vulnerabilities to AI-discovered zero-days. DUBLIN, IRELAND, August 18, 2026 /EINPresswire.com/ -- Waratek, the leader in runtime application …
- Alarming Zero-Day Mac Attack Gives Hackers Full System Control, Active Exploit 2026-08-17 19:31 Hot Hardware The National Cyber Security Centrum (NCSC) of the Netherlands says it has evidence that hackers are actively exploiting a vulnerability in one of macOS’ sharing features, which can provide attackers with complete access over a victim’s computer. This flaw …
- Zero‑Day hack exposes Lego Certified Stores SA customer data 2026-08-17 03:04 The Citizen (South Africa) The incident exposed customer email addresses and mobile numbers. Lego Certified Stores South Africa has confirmed a data breach after hackers exploited a zero‑day vulnerability in Metabase, a third‑party reporting tool. It is believed the incident, which …
- Clop Hacks Shell, GE, Philips In 43-Victim PTC Windchill Zero-Day Campaign 2026-08-15 15:49 Tech Times The Clop ransomware gang has named Shell, General Electric, and Philips among 43 organizations it claims to have breached in a sweeping campaign exploiting a critical flaw in PTC's widely used industrial software — and the engineering blueprints, …
- GeoServer Zero-Day Is Already Being Probed. That’s the Problem 2026-08-15 08:35 Security Affairs GeoServer Zero-Day Is Already Being Probed. That’s the Problem GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting …
- Microsoft Finally Patches LegacyHive Windows Zero-Day 2026-08-14 20:24 WindowsReport.com Microsoft has patched the LegacyHive Windows vulnerability through the August 2026 Patch Tuesday updates, as BleepingComputer writes. The flaw could allow a local attacker to gain administrator privileges without user interaction. Tracked as CVE-2026-62832 …
- Ghostemane – “Zero Day” 2026-08-14 17:25 Stereogum Hey, Ghostemane's back! The Florida SoundCloud-rap renegade emerged about a decade ago, and I was pretty fascinated with the ways that he incorporated, metal, hardcore, goth, and industrial into what he was doing, even before he got his rap name …
- North Korea’s Lazarus Group exploited a Windows zero-day for five weeks before Microsoft patched it 2026-08-14 12:18 GCN North Korea’s Lazarus Group spent at least five weeks silently exploiting an unpatched vulnerability in Microsoft Windows to break into defense, aerospace, and aviation companies across Europe and India before a patch arrived this week. Microsoft fixed …
- Hackers Exploiting Unpatched GeoServer Zero-Day 2026-08-14 11:59 SecurityWeek Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says. The security defect, described as an SQL injection issue that could be exploited to …
- Disgruntled security researcher just dropped another Windows zero-day, right on schedule 2026-08-14 05:03 TechSpot Sounding off: NightmareEclipse did it again. The security researcher who's been on a crusade against Microsoft has published a new zero-day flaw affecting all supported Windows versions. Redmond threatened to sue, but the researcher is keeping his …
- New ShieldBreak zero-day gives hackers full access to Windows 2026-08-14 00:48 Dataconomy Security researcher Nightmare Eclipse has published details of a new Windows zero-day called ShieldBreak that can give attackers system-wide access to affected devices. ShieldBreak exploits a flaw in Windows Defender, the security engine built into Windows …
- Security researcher publishes a new Windows zero-day bug 2026-08-13 22:24 Ammon News Ammon News - A security researcher has published details of a new vulnerability in the latest versions of Windows that allows hackers to gain system-wide access to the user’s device and data, despite facing a legal threat from Microsoft weeks earlier over …
- Attackers target zero-day vulnerability in geospatial data platform GeoServer 2026-08-13 21:39 CSO If the database runs with administrator permissions on Microsoft SQL Server, the account also has the ability to execute commands on the system, so the SQL injection becomes a remote code execution vector. Another user confirmed on X that they were able to …
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE 2026-08-13 21:13 The Hacker News Ravie LakshmananAug 13, 2026Zero-Day / Vulnerability A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection …
- Microsoft's nemesis drops new zero-day privilege escalation vulnerability — attack grants system-level privileges, but it could already be patched 2026-08-13 20:35 Tom's Hardware Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Prolific hacker and Microsoft nemesis 'Nightmare Eclipse' has just published ShieldBreak, yet another Windows zero-day vulnerability that ought to get you …
- Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users 2026-08-13 18:29 TechRadar Pro Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑day Flaw bypasses a recent patch and works on fully updated Windows 11 systems …
- North Korea's Lazarus Uses Quantum-Resistant Encryption To Hide Zero-Day Attacks on Defence and Aviation Firms 2026-08-13 17:12 International Business Times - United Kingdom North Korea's Lazarus Group used a previously unknown Windows flaw and quantum-resistant encryption in a campaign against defence, aerospace and aviation organisations, according to researchers. Check Point Research said the group combined the zero-day …
- Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ 2026-08-13 13:18 SecurityWeek Security researcher Nightmare Eclipse has dropped a fresh zero-day exploit leading to privilege escalation on Windows. Also known as Chaotic Eclipse, the disgruntled researcher released multiple zero-day exploits targeting Microsoft products over the past …
- North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job 2026-08-13 12:37 Security Affairs North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered …
- Lazarus exploits Windows zero-day in defence attacks 2026-08-13 08:24 Arabian Post North Korea-linked hackers exploited a previously unknown Windows vulnerability to gain the highest level of system privileges while targeting defence, aerospace and aviation organisations across several countries. The flaw, tracked as CVE-2026-68820, …
- Kristof Milak: “Building Myself Back Up From Zero” — Day 3 European Championship Quotes 2026-08-13 07:10 SwimSwam - Texas 2026 EUROPEAN SWIMMING CHAMPIONSHIPS The third night of swimming at the 2026 European Aquatics Championships featured a world record from Sara Curtis, European records from Hubert Kos and Johannes Liebmann, and individual victories for Sarah Sjostrom and …
- New Windows zero-day flaw could give hackers deep access to your PC — how to stay safe 2026-08-13 02:20 Tom's Guide Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter This week two different Windows vulnerabilities were revealed that attack your PC from different angles. However, there is one unfortunate thread that connects them; …
- New Zero-Day Exploit Used in Operation Dream Job Attack on Defense Sector 2026-08-13 01:25 Times News Global Check Point Research has traced a new wave of the Operation Dream Job campaign, a cyber-espionage effort that has been active since early 2026. The campaign is heavily focused on the defense sector, with a particular emphasis on aerospace and aviation …
- Lazarus Group Hacked Defense Workers With Windows Kernel Zero-Day For Five Weeks 2026-08-12 23:48 Tech Times A kernel-level flaw buried in the Windows networking stack let North Korean spies seize full system control over defense and aerospace targets while dressed as LinkedIn recruiters — for weeks before a patch arrived. Defense contractors, aerospace engineers …