Tag: zero-day
-
âš¡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Tags: ai, attack, breach, data-breach, malware, rce, remote-code-execution, service, wordpress, zero-dayA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being…
-
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.The overflow lets…
-
Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks…
-
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this First…
-
LegacyHive: Neuer WindowsDay hebelt selbst vollständig gepatchte Systeme aus
LegacyHive ist ein neuer Windows-Zero-Day, der selbst vollständig gepatchte Systeme betrifft. Microsoft untersucht die Schwachstelle. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/legacyhive-windows-zero-day-gepatchte-systeme-331579.html
-
Inc Ransomware Exploits SonicWall SMA Zero-Days
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall’s mobile access appliances. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
-
Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026
Weekly summary of Cybersecurity Insider newsletters in July 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/
-
Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026
Weekly summary of Cybersecurity Insider newsletters in July 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/
-
Warum KI-gestützte Schwachstellensuche das Patchen unter Druck setzt
Der Juli-Patchday von Microsoft fällt außergewöhnlich umfangreich aus. Insgesamt wurden 570 Schwachstellen behoben, davon 57 als kritisch und 510 als wichtig eingestuft. Darunter befinden sich drei Zero-Day-Lücken, von denen zwei bereits aktiv in Angriffen ausgenutzt werden und eine öffentlich bekannt gemacht wurde. Auffällig ist zudem die enorme Zahl von 468 Schwachstellen in Microsoft-Edge/Chromium, von denen…
-
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses Windows’ User Profile Service to mount a target user’s UsrClass.dat hive into a registry location…
-
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/
-
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, rce, remote-code-execution, vulnerability, zero-dayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization First seen…
-
7-Zip Vulnerability Lets Attackers Trigger Heap Buffer Overflow Using Malicious Files
A newly disclosed vulnerability in 7-Zip could allow attackers to execute arbitrary code by tricking users into opening a specially crafted XZ-compressed file. Tracked as CVE-2026-14266 and identified by Trend Micro’s Zero Day Initiative as ZDI-26-444 (ZDI-CAN-30169), the flaw is a heap-based buffer overflow in the archive utility’s handling of XZ chunked data. The vulnerability…
-
AnyDesk Zero-Day Flaw Allows Local Attackers to Trigger System-Wide DenialService
A newly disclosed zero-day vulnerability in AnyDesk has the potential to allow a local attacker to trigger a denial-of-service condition by exploiting the remote-access software’s “Send Support Information” feature. The advisory, tracked as ZDI-26-401 and ZDI-CAN-26645, was published by Trend Micro’s Zero Day Initiative (ZDI) on July 8, 2026. The flaw has been assigned CVE-2026-15682…
-
Hackers Exploit SonicWall SMA1000 Zero-Days to Execute Commands as Root
Hackers are actively exploiting two zero-day vulnerabilities in the SonicWall SMA 1000 Series remote access appliances. They are chaining a critical server-side request forgery flaw with a local code injection bug to execute commands with root privileges. Rapid7’s Managed Detection and Response team detected targeted attacks before SonicWall publicly disclosed these vulnerabilities on July 14,…
-
Chaotic Eclipse: Verärgerter Forscher leakt neuen Zero-Day-Exploit für Windows
Mit einem neuen Exploit namens Legacyhive können sich Angreifer unter Windows Adminrechte verschaffen. Einen Patch gibt es bisher nicht. First seen on golem.de Jump to article: www.golem.de/news/chaotic-eclipse-veraergerter-forscher-leakt-neuen-zero-day-exploit-fuer-windows-2607-210933.html
-
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Today is Microsoft’s July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
-
SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/sonicwall-sma-attacks-via-cve-2026-15409-cve-2026-15410/
-
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/
-
(g+) Cybersecurity: Wie eine Erpressergruppe reihenweise Peoplesoft-Systeme abräumt
Eine ungepatchte Peoplesoft-Lücke wird als Zero Day ausgenutzt, mit prominenten Opfern. Worauf Admins achten müssen. First seen on golem.de Jump to article: www.golem.de/news/cybersecurity-wie-eine-erpressergruppe-reihenweise-peoplesoft-systeme-abraeumt-2607-210692.html
-
CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities
Tags: attack, cisa, cvss, cybersecurity, exploit, flaw, infrastructure, kev, malicious, vulnerability, zero-dayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities (KEV) catalog after reports confirmed active zero-day attacks targeting the iCagenda and Balbooa extensions for Joomla. Both flaws carry the maximum CVSS severity score of 10.0 and can allow attackers to upload malicious files that ultimately lead to remote code execution. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/
-
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below – CVE-2026-48939 – A vulnerability in the First…
-
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft has released a security patch to address a Defender zero-day vulnerability known as “RoguePlanet,” disclosed after the June 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/
-
The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Vercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticated nation-state infrastructure implant. Instead, it unfolded when an…
-
FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs
After gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/fortibleed-actors-inc-lynx-ransomware-gangs
-
FortiBleed Credential Theft Connected to INC and Lynx Ransomware
FortiBleed, the Fortinet credential theft campaign, is now connected to INC Ransom and Lynx, with a Nextcloud zero-day vulnerability also under investigation. First seen on hackread.com Jump to article: hackread.com/fortibleed-credential-theft-in-lynx-ransomware/
-
FortiBleed campaign traced to INC and Lynx ransomware operations
Researchers are also investigating the role of a suspected zero-day vulnerability. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/fortibleed-campaign-traced-to-inc-and-lynx-ransomware-operations/824348/
-
Researcher Behind ‘Exploitarium’ Explains Release of Undisclosed Zero-Day Exploits
Infosecurity spoke with the researcher who dumped over 30 proof-of-concept exploits without disclosing the vulnerabilities first First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/researcher-exploitarium-exploits/
-
CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks
CISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to gain SYSTEM privileges through Microsoft Defender. BlueHammer, tracked as CVE-2026-33825, has moved from proof-of-concept noise to real ransomware attacks in the wild, the US CISA confirms. BlueHammer allows attackers to escalate privileges locally in Microsoft Defender. The vulnerability, along with two other zero-days dubbed…
-
Exploitarium: Anonymer Forscher leakt massenweise Zero-Day-Exploits
Ein öffentliches Github-Repository enthält 26 Exploits für Zero-Day-Lücken in mehreren populären Softwaretools. Und es werden immer mehr. First seen on golem.de Jump to article: www.golem.de/news/exploitarium-anonymer-forscher-leakt-massenweise-zero-day-exploits-2607-210388.html

