Tag: zero-day
-
AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in the Linux packet scheduling subsystem (net/sched) and arises from a use-after-free condition involving traffic-control action objects. AI-Discovered Linux Kernel Zero-Day Star Labs researcher developed a reliable exploit…
-
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
-
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
-
Adversaries Don’t Need a Zero-Day, They Read Your Rulebook
Confidence in autonomous security tools is declining, and here’s why. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/adversaries-do-not-need-zero-day-they-read-your-rulebook
-
Weekly Cybersecurity Newsletter Top 50 Biggest Cybersecurity Stories SonicWall Zero-Day, Cl0p Windchill Attack, AI-Weaponized Threats, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from July 2024, 2026. It was a heavy week: Cl0p turned internet-exposed Windchill servers into a global data-theft campaign, attackers rode SonicWall SMA zero-days to root, a Bluetooth flaw put 2 million cars at […]…
-
Zero-day flaw in Check Point SmartConsole is under exploitation
Researchers warned the vulnerability offers an attacker the ability to make key changes to security configurations. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/zero-day-flaw-check-point-smartconsole-exploitation/826149/
-
Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks
Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims. First seen on hackread.com Jump to article: hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
-
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code…
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed Laundry Bear, sends half-click phishing emails that require a victim only to open or preview the message. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
-
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.The NSA, CISA…
-
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. First seen on cyberscoop.com Jump to article: cyberscoop.com/russian-laundry-bear-zimbra-exploit/
-
Russia-backed threat actor targets Western organizations in phishing campaign
The threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/russia-threat-actor-western-organizations-Zimbra-phishing/826029/
-
Künstliche Intelligenz hat Hugging Face nicht an Cleverness übertroffen, sie hat das Mittelmaß optimiert
Die in der Diskussion stehende Attacke einer OpenAI-KI auf Hugging Face hat eine Zero-Day-Lücke in einem Package-Registry-Proxy ausgenutzt, um die Isolation zu durchbrechen. Die KI eskalierte in der Folge Privilegien, startete Seitwärtsbewegungen und erreichte so einen Knotenpunkt mit Internetzugang. Sie nutzte einen bösartigen Datensatz, um über unsichere Loader und Template-Injection die Ausführung von Remote-Code auszulösen.…
-
OpenAI Models Breached Hugging Face During Internal Cyber Test
OpenAI models escaped from a controlled cyber test, exploited zero-day flaws and breached Hugging Face while searching its production database for test answers. First seen on hackread.com Jump to article: hackread.com/openai-models-breached-hugging-face/
-
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/
-
OpenAI Models Escaped Test Environment and Breached Hugging Face
OpenAI models escaped from a controlled cyber test, exploited zero-day flaws and breached Hugging Face while searching its production database for test answers. First seen on hackread.com Jump to article: hackread.com/openai-models-breached-hugging-face/
-
OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
OpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were behind the cyberattack on Hugging Face disclosed the previous week. The models weren’t acting under attacker control.…
-
OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers
OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers…
-
OpenAI Models Escaped Containment and Hacked Hugging Face
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. First seen on wired.com Jump to article: www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
OpenAI Models Escaped Sandbox, Breached Hugging Face
Tags: ai, attack, breach, credentials, cybersecurity, exploit, infrastructure, openai, risk, zero-dayReduced Guardrails Enabled Advanced Models to Pursue Unrestricted Attack Paths. OpenAI said advanced frontier models escaped a constrained testing environment, exploited multiple zero-days and stolen credentials and breached Hugging Face infrastructure while attempting to obtain answers for an internal ExploitGym evaluation, highlighting the growing cybersecurity risks posed by autonomous AI agents. First seen on govinfosecurity.com…
-
OpenAI Models Escaped Containment and Hacked HuggingFace
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. First seen on wired.com Jump to article: www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
MCTTP 2026 – Forscher stellt noch unbekannte WER-Zero-Day in München vor
Tags: zero-dayFirst seen on security-insider.de Jump to article: www.security-insider.de/windows-error-reporting-exploits-cves-zero-day-mcttp-2026-a-01282b3520b80220e82dcaa6a4002c62/
-
SonicWall SMA zero-days were exploited weeks before disclosure
Two recently disclosed SonicWall SMA 1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited in zero-day attacks for weeks, allowing threat … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/
-
Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/
-
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances. The affected SonicWall SMA models include the 1000 series, specifically models 6210, 7210, and 8200.…
-
SSRF und Code Injection – SonicWall warnt vor Zero-Day-Angriffen auf SMA1000-Serie
First seen on security-insider.de Jump to article: www.security-insider.de/sonicwall-sma1000-zero-day-ssrf-code-injection-aktiv-ausgenutzt-a-8f7983e5666a6c63dc3fb556e9e6c379/
-
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/

