< ciso
brief />
Tag Banner

All news with #zero day exploitation tag

492 articles

PaperCut zero-day actively exploited; emergency patch

🚨 PaperCut warned customers that attackers are actively exploiting a zero-day affecting all versions of PaperCut NG and PaperCut MF. The vendor issued emergency patches for v25 and v26 and confirmed known customer incidents while an investigation continues. Indicators include suspicious post-exploitation activity by "pc-app.exe," missing or truncated server.log files, and specific error entries such as ERROR No suitable driver found for jdbc:no:x. Users with internet-exposed PaperCut servers are urged to immediately restrict access to trusted IPs and apply network controls.
read more →

Critical Avada WordPress Theme Zero-Click RCE

🛡️A chain of six vulnerabilities in the Avada WordPress theme and Fusion Builder plugin allows an unauthenticated attacker to execute arbitrary PHP code via a zero-click exploit. Tracked as CVE-2026-18431 with a 9.8 score, the attack requires a precise sequence of authorization, input-validation, trust-boundary, and file-handling failures. ThemeFusion released patches in Avada 7.16.1 and Fusion Builder 3.16.1 after disclosure by Wordfence, which withheld full details to allow administrators time to update.
read more →

NemoClaw vulnerability lets local AI be poisoned

🛡️ A vulnerability in Nvidia's NemoClaw can let a malicious website trick a browser into reaching a locally running Ollama model server via DNS rebinding, giving unauthenticated API access. Cyera researchers showed an attacker could modify a model's chat template to inject persistent, hidden instructions that survive future sessions. Nvidia has patched macOS and Linux builds in NemoClaw 0.0.35, while Windows/WSL remains unpatched.
read more →

CISA Adds Critical Oracle WebLogic Flaw to KEV

🔒 CISA has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw allows unauthenticated HTTP access to create, modify, or delete critical data and potentially gain full access to affected instances. Oracle released patches in January, but reports from GreyNoise and CloudSEK indicate ongoing exploitation activity. Federal agencies must remediate under BOD 26-04 by August 27, 2026.
read more →

Critical Zimbra RCE Flaw Actively Exploited Now

🛡️ CERT Polska warns that attackers are actively exploiting a critical Zimbra Collaboration Suite vulnerability (CVE-2026-73570). The flaw, patched in Zimbra 10.1.20 on July 20, enables unauthenticated remote code execution via command injection in the SNMP notification processing when SNMP notifications are enabled. Shadowserver reports over 12,100 Zimbra servers exposed online, and administrators are urged to check logs and specific directories for signs of compromise. Zimbra has been a frequent target of APT groups in past campaigns.
read more →

Critical Windows IKE Extension Flaw Actively Exploited

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are exploiting a critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component, tracked as CVE-2026-33824. The vulnerability affects supported Windows 10, Windows 11, and Windows Server versions and can be triggered by unauthenticated attackers sending crafted packets to UDP ports 500 or 4500. Microsoft issued a Patch Tuesday advisory and recommended firewall mitigations for organizations that cannot immediately apply updates.
read more →

CISA Adds Actively Exploited Critical Ray Flaw

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Ray vulnerability (CVE-2025-62593) to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The flaw enables remote code execution via DNS rebinding attacks through browsers like Firefox and Safari and primarily affects developers running Ray in development or testing environments. Ray fixed the issue in version 2.52.0, and agencies are urged to remediate by August 20, 2026.
read more →

Certighost: Privilege Risks in Your Certificate Authority

🔒 Certighost (CVE-2026-54121) demonstrates how a standard domain user can coerce an Enterprise CA to issue a Domain Controller certificate via AD CS "chase" behavior. The flaw allows an attacker to obtain PKINIT authentication as a DC, perform DCSync, and escalate to domain compromise. Microsoft patched the issue on July 14, 2026; mitigate by patching, restricting CA outbound access, and reducing MachineAccountQuota.
read more →

Weekly cyber recap: exploits, ransomware, and browser attacks

⚡ This week’s roundup highlights multiple active exploit chains, supply-chain ripple effects, and opportunistic attacks that abused exposed services and old vulnerabilities. Notable incidents include exploitation of a severe VMware vCenter directory-traversal flaw linked to a suspected China-nexus APT, a macOS Screen Sharing flaw used to drop crypto miners, and a Windows privilege-escalation zero-day deployed by Lazarus. The report emphasizes how access already present and weak assumptions about visibility continue to amplify small gaps into large intrusions.
read more →

Unisoc modem exploit chain risks Android kernel

🔒 SSD Secure Disclosure detailed a two-stage exploit chain that yields full Android kernel access via Unisoc modem firmware when a victim answers a malicious VoLTE video call. The advisory, published August 17, 2026, follows an earlier March 2026 remote code execution disclosure and requires control of a private 4G network plus a modem foothold. Affected chipsets include Unisoc T606, T612, and T7250 in multiple device brands, and no vendor patch is yet available.
read more →

Microsoft works on patch for Defender ShieldBreak zero-day

🛡️ Microsoft confirmed it is developing a security update to address a new Microsoft Defender zero-day called "ShieldBreak," disclosed by researcher "Nightmare Eclipse" after the August 2026 Patch Tuesday. The PoC reportedly allows local attackers with limited permissions to escalate to SYSTEM on patched Windows 10, Windows 11, and Windows Server, and has been tracked as CVE-2026-69414. Microsoft stated it is investigating and will provide a quality security update, while the researcher publicly disclosed the exploit amid a dispute over disclosure and bounties.
read more →

Critical SAP Commerce Cloud RCE Now Being Exploited

🛡️ A maximum-severity remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) patched three days ago is already being targeted in attacks, Defused reports. The flaw, in the core Data Hub Adapter extension, allows unauthenticated actors to exploit improper authorization to execute arbitrary code. SAP warned the issue arises from abuse of a default authentication client and insufficient input validation. Threat researchers observed initial exploitation attempts hitting honeypots despite no public PoC existing.
read more →

Critical GeoServer SQL Injection Now Patched

🛡️ A critical SQL injection zero-day in GeoServer was disclosed on August 12, 2026, and saw active exploitation attempts within hours, according to watchTowr. The flaw, tied to the jsonArrayContains function in PostGIS DataStore, could lead to remote code execution under certain configurations and remained initially unpatched. GeoServer has since released versions 3.0.1, 2.28.5, and 2.27.6 to remediate the issue, which carries a CVSS score of 9.8.
read more →

Microsoft patches LegacyHive Windows zero‑day

🛡️ Microsoft released patches addressing the Windows zero-day dubbed LegacyHive, disclosed after July 2026 Patch Tuesday. The flaw was revealed by a researcher using the "Nightmare Eclipse" handle, who published a proof-of-concept after the updates; the exploit requires additional credentials, limiting easy weaponization. Microsoft tracked the issue as CVE-2026-62832 and describes the bug as improper link resolution in the Windows User Profile Service that can allow local privilege escalation. ACROS Security also issued unofficial mitigations prior to Microsoft's August fixes.
read more →

Trezor reports customer data breach via ShipMonk hack

📢 Trezor disclosed a data breach after its shipping partner ShipMonk was hacked, exposing nearly 14,000 customers' order details. The exposed data includes full names, shipping addresses, email addresses, and phone numbers for customers who received orders between May 10 and August 8, 2026. Trezor confirmed its systems and devices were not compromised but warned affected customers to expect heightened phishing attempts. ShipMonk attributed the intrusion to a Metabase zero-day vulnerability that allowed attackers to access stored customer data.
read more →

New ShieldBreak zero-day elevates Defender privileges

🔒 A new zero-day named ShieldBreak was published by researcher Nightmare Eclipse after Microsoft's August 2026 Patch Tuesday. The exploit is a bypass for the earlier RoguePlanet privilege escalation flaw and can grant SYSTEM privileges on patched Windows 10, Windows 11, and Windows Server installations. The researcher claims a 100% success rate in tested builds and ties the release to an ongoing dispute over Microsoft's disclosure and bug bounty practices.
read more →

Microsoft patches 400 vulnerabilities in August update

🔒 Microsoft released its August Patch Tuesday addressing 400 CVEs, including one actively exploited zero-day and two publicly disclosed zero-days. The exploited flaw, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock that can allow local low-privileged attackers to gain system privileges. Other notable fixes include EoP issues in the User Profile Service (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver tampering flaw (CVE-2026-72971). Organizations without automated, risk-based patching will face challenges prioritizing these updates.
read more →

August 2026 Patch Tuesday: Zero‑Day Winsock and SAP CVE

🛡️ Microsoft’s August Patch Tuesday delivers 398 CVE fixes, highlighted by an actively exploited zero‑day in the Windows Ancillary Function Driver for WinSock (CVE‑2026‑68820). The release includes 42 critical and numerous remote code execution flaws that may be exploitable without authentication, plus two additional publicly disclosed zero‑days. SAP released 29 patches, led by a maximum‑severity improper authorization issue in Commerce Cloud’s Data Hub Adapter (CVE‑2026‑58231).
read more →

Zoom patches zero-click RCE and VDI disclosure flaws

🛡️ Zoom has patched four vulnerabilities across its applications, including two zero-click remote code execution issues that allow a meeting participant to execute malicious code on other attendees' systems without any interaction. Three client vulnerabilities affect Zoom versions before 7.1.5 and 7.0.6 and stem from memory corruption in the text annotation feature; a fourth path traversal flaw impacts Zoom Workplace VDI Client and plugins before 7.0.11 and 6.6.15. The annotation bugs were found by A Security using an AI agent, which built a working exploit in under 24 hours, and Zoom has provided mitigations including server-side filtering and guidance to restrict optional features and enforce client version minimums.
read more →

Microsoft issues massive August security patch bundle

🔒 Microsoft released updates addressing 398 security vulnerabilities across Windows and related software in its August Patch Tuesday, including one actively exploited zero-day and two publicly disclosed flaws. The company rated 42 of the fixes as critical, and attributed the flood of discoveries to AI-assisted vulnerability research. Experts caution that AI may accelerate bug finding but human oversight remains essential for safe, effective patching.
read more →