Tag: zero-day
-
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Today is Microsoft’s August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/
-
Shattering the Dream When a Job Offer Becomes a Zero-Day Attack
ey Points Introduction Since early 2026, Check Point Research has tracked a wave of theOperation Dream Jobcampaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially…
-
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT”‘5.6″‘Cyber that it said is focused on vulnerability research, penetration testing, and incident response.”Built on GPT”‘5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk First seen on…
-
GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/openai-gpt-5-6-cyber-model/
-
OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains
OpenAI has expanded its Daybreak cybersecurity program with the introduction of GPT-5.6-Cyber, a purpose-trained model specifically designed for authorized vulnerability research, exploit validation, and advanced security testing. Built on the foundation of GPT-5.6 Sol, this new model serves as a controlled-access tool for trusted defenders as AI-assisted offensive capabilities continue to evolve. GPT-5.6-Cyber to Find…
-
Metabase Zero-Day Exploited in the Wild: Unauthenticated SQL Injection Leading to Full Admin Access
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/metabase-zero-day-exploited-in-the-wild-unauthenticated-sql-injection-leading-to-full-admin-access
-
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/metabase-sql-zero-day-attacks-wide-blast-radius
-
âš¡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed…
-
Metabase zero-day exploited to access Framework customer data
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/
-
Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials
Tags: attack, cloud, credentials, cyber, endpoint, exploit, flaw, security-incident, sql, update, vulnerability, zero-dayMetabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. According to the company, an attacker exploited this previously unknown flaw to target Metabase Cloud before the vulnerable endpoints were blocked and a patch was developed. Customers using Metabase…
-
Security Affairs newsletter Round 589 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild,…
-
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own…
-
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Tags: access, authentication, business, cve, data, exploit, flaw, intelligence, software, sql, vulnerability, zero-dayMetabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain…
-
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
-
New N-able Zero Day Puts MSPs on Defensive
Second Hotfix Issued for RMM Technology Widely Used by Managed Security Providers. Software developer N-able issued a second hotfix this week after more zero-day exploits against its remote management and monitoring tool. Successful attacks facilitate full account takeover. Hotfix 2 is required, even if you already applied the earlier hotfix, the company said. First seen…
-
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors.PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning First seen on thehackernews.com Jump…
-
Patch Me If You Can, The VPN, the Backup Server, and the Browser Zero-Day
Actively exploited VPN, browser and backup vulnerabilities show why effective patching depends on risk-based cybersecurity governance, not perfect security. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/patch-me-if-you-can-the-vpn-the-backup-server-and-the-browser-zero-day/
-
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.We observed production websites embedding hidden prompt injection payloads inside “Ask AI” buttons on marketing and competitor comparison pages.…
-
Prolific ransomware group behind SonicWall zero-day attacks
INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. First seen on cyberscoop.com Jump to article: cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/
-
INC Ransomware is Calling Victims Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since…
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control
SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted WebSocket request into root-level control on internet-facing VPN gateways. The campaign, dissected by Volexity and other researchers, shows how a previously undocumented threat actor, tracked as UTA0533, abused SonicWall’s wsproxy…
-
Autonomous AI Agent Exploits Zero-Day to Breach Hugging Face Infrastructure
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a zero-day vulnerability. Documented by HiddenLayer’s Research Team on July 31, the agent was undergoing an internal cyber capability evaluation on ExploitGym, a benchmark designed to test an AI’s ability to discover and…
-
CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix
Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall Management Center) software. The flaw, disclosed on July 29, 2026, allows a remote, unauthenticated attacker to log in to vulnerable systems using a built-in low-privilege account and access sensitive data. First seen on thecyberexpress.com Jump to article:…
-
We now have a better understanding how OpenAI hacked into Hugging Face
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story/
-
JFrog tries to spin OpenAI 0-day exploit of its app into a success story
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story/
-
FastJson RCE Zero-Day Actively Targets Organizations
Threat actors are actively exploiting the FastJson CVE-2026-16723 zero-day, with no patch available for affected FastJson 1.x versions. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/fastjson-rce-zero-day-actively-targets-organizations/
-
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/
-
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/
-
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for…

