Tag

Zero Day

All articles tagged with #zero day

ShinyHunters Claims Massive FBI Data Breach via Zero-Day Exploit
cybersecurity16 days ago

ShinyHunters Claims Massive FBI Data Breach via Zero-Day Exploit

The hacking group ShinyHunters claims to have breached the Federal Bureau of Investigation, stealing data on nearly all current and former agents and job applicants. The group alleges it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers and exfiltrate two to three terabytes of data. ShinyHunters stated the breach was a retaliatory response to a May 2026 FBI advisory warning targets not to pay ransoms. The group defaced the FBI job application portal, which remained unavailable on Tuesday. While the FBI has not officially confirmed the breach, Reuters partially verified nine records from a sample of stolen data against credit bureau records. The incident follows a pattern of high-profile intrusions by ShinyHunters, including breaches of Rockstar Games and the education platform Canvas.

CISA Mandates Urgent Patching for Three Actively Exploited Linux Kernel Flaws
cybersecurity16 days ago

CISA Mandates Urgent Patching for Three Actively Exploited Linux Kernel Flaws

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch them by September 23, 2026. The flaws, ranging from medium to critical severity, are being actively exploited in the wild. While CISA has not disclosed details about the threat actors, Red Hat and other vendors have confirmed public exploits exist for two of the issues. The most critical flaw, CVE-2025-39964, has existed in the kernel for 14 years and allows for privilege escalation and container escape.

Zero-day flaw lets attackers hijack Meta’s Muse via transcription endpoint abuse
technology17 days ago

Zero-day flaw lets attackers hijack Meta’s Muse via transcription endpoint abuse

A zero-day in Meta's Muse AI lets attackers hijack the assistant by manipulating its cloud-based transcription endpoint, enabling any locally run app or terminal command to obtain the Muse authentication token and take full control of the account; security researcher Patrick Wardle demonstrated PoCs that could write files or snap photos, highlighting risky design choices around cloud dictation and broad app privileges. Amazon has begun blocking Muse on its site, and questions about Muse’s security and privacy remain despite Meta’s public statements.

Microsoft pushes emergency Windows 11 patch after Patch Tuesday glitches
technology23 days ago

Microsoft pushes emergency Windows 11 patch after Patch Tuesday glitches

Microsoft released an out-of-band emergency patch (KB5129194) for Windows 11 26H1 to fix two actively exploited zero-days and hundreds of other flaws from September’s Patch Tuesday. The fix comes a week after the major update caused issues with Remote Desktop Services, some USB audio devices, and Hyper-V Linux VMs; although it resolves several USB audio problems and is cumulative with September updates, some USB Audio Class 1.0 devices may still fail to start or produce sound. Users are urged to install the latest update promptly. The two zero-days addressed were CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (ALPC).

Chrome patches in-the-wild V8 zero-day as part of 230 fixes
security1 month ago

Chrome patches in-the-wild V8 zero-day as part of 230 fixes

Google pushed Chrome updates to fix 230 vulnerabilities, including CVE-2026-87491 — an out-of-bounds write in V8 that has been exploited in the wild to run arbitrary code in the sandbox. The patch, for Windows/macOS versions 153.0.8010.36/37 and Linux 153.0.8010.36, also addresses multiple WebGL and WebPackaging flaws and follows seven actively exploited Chrome zero-days reported this year. Users of Chrome and other Chromium-based browsers should update promptly, noting that some bug details may remain restricted until most users are patched. OpenAI Codex Security is credited for a separate high-severity finding in WebPackaging.

Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days
security1 month ago

Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days

Microsoft’s September Patch Tuesday patches a record 974 vulnerabilities across Windows, Office, SQL, and Developer Tools, including two zero-days actively exploited in the wild (CVE-2026-85880 and CVE-2026-81963). The fixes bring the total resolved vulnerabilities to 999 (including 25 non-Microsoft CVEs), with over 110 rated critical and the bulk involving privilege escalation, remote code execution, and information disclosure. CISA added both CVEs to the Known Exploited Vulnerabilities catalog, ordering federal agencies to apply updates by September 22, 2026. Despite the high volume, attackers’ exploitation rates remain limited, so organizations should prioritize remediation based on exposure and relevance.

Chrome Zero-Day Exploited in the Wild Gets Quick Patch (CVE-2026-87491)
technology1 month ago

Chrome Zero-Day Exploited in the Wild Gets Quick Patch (CVE-2026-87491)

Google issued patches for a new actively exploited Chrome zero-day in the V8 engine (CVE-2026-87491), rolling updates to Windows, macOS, and Linux; exploitation could allow remote code execution via crafted HTML and heap corruption, with Google restricting full exploit details until most users are updated. This marks the seventh Chrome zero-day addressed in 2026, following several earlier flaws.

Patch Tuesday Sets a 974-CVE Record as Microsoft and Adobe Push Urgent Updates
technology1 month ago

Patch Tuesday Sets a 974-CVE Record as Microsoft and Adobe Push Urgent Updates

Microsoft’s Patch Tuesday breaks a record with 974 CVEs across its products, including two zero-days already being exploited (CVE-2026-85880 in ALPC and CVE-2026-81963 in the Windows Update Stack); the US CISA added them to its Known Exploited Vulnerabilities catalog with patch deadlines. Adobe followed with 172 CVEs across 10 bulletins, including the Magento/Adobe Commerce zero-day StyleSmuggler (CVE-2026-75650) under active abuse targeting online shops. The release also highlights Exchange Server vulnerabilities (CVE-2026-55007) as wormable and notes ongoing chatter about a Chromium-based V8 flaw (CVE-2026-85046) without a Microsoft advisory, underscoring urgency to patch across ecosystems.

technology1 month ago

Microsoft Stages Massive Patch Tuesday as AI Aids Historic Vulnerability Sweep

Microsoft released its largest patch batch ever, fixing at least 974 vulnerabilities across Windows and related software, with AI-assisted vulnerability discovery contributing to the surge and pushing this year’s total past 2,600. The update includes two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880) and 113 critical flaws, notably CVE-2026-69730 (Windows DNS) and CVE-2026-69829 (Windows Shell). Security experts caution that patch volume complicates prioritization and testing for organizations, underscoring the need for careful risk-based remediation and potentially after-hours deployment. The article also notes broader AI-driven patch increases across the industry and urges admins to follow per-patch guidance from sources like SANS and AskWoody.

Microsoft's September patch blitz shatters vulnerability records amid AI-driven bug hunting
technology1 month ago

Microsoft's September patch blitz shatters vulnerability records amid AI-driven bug hunting

Microsoft's September patch release fixes a record ~972 vulnerabilities (997 with Edge/Chromium), including 112 critical flaws and two zero-days in Windows Update and Windows Local Procedure; AI-assisted vulnerability discovery is driving these record numbers as the industry braces for AI-enabled exploits, though active exploitation remains limited so far.

Microsoft fixes 966 flaws in September 2026 Patch Tuesday, including two zero-days
technology1 month ago

Microsoft fixes 966 flaws in September 2026 Patch Tuesday, including two zero-days

Microsoft’s September 2026 Patch Tuesday addresses 966 vulnerabilities across a wide range of products, including two zero-days. Flaws span .NET, ASP.NET Core, Windows components (DNS, Kerberos, HTTP.sys, Win32K, etc.), Office, Exchange Server, SQL Server, Azure services, PowerShell, Visual Studio, and more. Flaws include remote code execution, elevation of privilege, information disclosure, and denial-of-service vectors, with several critical issues affecting important attack surfaces. Organizations should apply these patches promptly to reduce risk from both the two zero-days and the large variety of other vulnerabilities disclosed.

Chrome patched after active zero-day exploit hits V8 engine
technology1 month ago

Chrome patched after active zero-day exploit hits V8 engine

Google released Chrome updates to fix a high‑severity zero‑day in the V8 engine (CVE-2026-85046) that is already being exploited in the wild, along with nine other high‑severity flaws. The patches cover Chrome on Windows/macOS (versions 152.0.7977.82/.83) and Linux (152.0.7977.82); users should install the update via Settings > About Chrome and restart the browser. The fixes also apply to Chromium‑based browsers like Edge, Brave, Opera, and Vivaldi as updates roll out.

Chrome Patch Fends Off Actively Exploited V8 Zero-Day
security1 month ago

Chrome Patch Fends Off Actively Exploited V8 Zero-Day

Google released a Chrome security update that patches 12 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-85046) that enables remote code execution via a crafted HTML page. An exploit already exists in the wild, and Google urges users to update to Chrome 152.0.7977.82/83 on Windows and macOS, and 152.0.7977.82 on Linux; the update also fixes five other CVEs (CVE-2026-2441, -3909, -3910, -5281, -11645), bringing the total of actively exploited Chrome zero-days addressed this year to six.

PaperCut zero-days hit in the wild again, fueling data theft after patches
technology1 month ago

PaperCut zero-days hit in the wild again, fueling data theft after patches

Two newly patched PaperCut NG/MF flaws (CVE-2026-81578 and CVE-2026-82078) are being exploited to bypass authentication and remotely execute code, with attackers now dumping Derby DB tables to steal data. PaperCut released multiple emergency patches (including Release 3) and urges internet-facing servers to apply them; over 800 PaperCut servers are exposed online per Shadowserver. While attribution is unclear, this follows a history of targeted PaperCut exploits by ransomware and state-backed groups and underscores ongoing risk from misconfigured or exposed deployments.

PaperCut Zero-Day Exploitation Forces Emergency Patch Across NG and MF
technology1 month ago

PaperCut Zero-Day Exploitation Forces Emergency Patch Across NG and MF

PaperCut warns that attackers are actively exploiting a zero-day flaw in all NG and MF versions, prompting an emergency patch for v25/v26 and ongoing investigation; security indicators include suspicious post-exploitation activity (pc-app.exe) and anomalous server.log entries, with guidance to restrict PaperCut access to trusted IPs; no details on the flaw or attackers yet, though a 2023 CVE was previously exploited by known threat actors.