< ciso
brief />
Tag Banner

All news with #zero day exploitation tag

492 articles · page 3 of 25

Critical GlobalProtect VPN Bug Now Used in Ransomware

🔒 Palo Alto Networks patched a critical PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) on May 13 after Rapid7 observed active exploitation from May 17. Arctic Wolf reports the Qilin ransomware gang is leveraging the flaw to gain unauthorized VPN access and deploy ransomware, with incidents in June resulting in domain-wide encryption. CISA added the vulnerability to its Known Exploited Vulnerability catalog and ordered federal agencies to remediate within three days.
read more →

Unofficial patches available for LegacyHive zero-day

🛡️ Free unofficial micropatches are available for a recently disclosed Windows zero-day, dubbed LegacyHive, which enables non-admin users to escalate privileges by mounting other users' registry hives. The vulnerability was disclosed by researcher Nightmare Eclipse alongside a stripped proof-of-concept after Microsoft's July 2026 updates. ACROS Security (0Patch) offers free micropatches for affected Windows 10 2004+/Windows Server 2022+ systems; Microsoft says it is investigating the claims.
read more →

Weekly cyber recap: critical bugs, active exploits

⚠️ This week saw small inputs produce severe outcomes: unauthenticated RCEs in WordPress Core, SonicWall SMA zero-days exploited in the wild, OpenSSL DoS via an 11-byte payload, and a SharePoint RCE added to CISA's KEV catalog. Other notable items include the OkoBot malware framework targeting crypto wallets, the NadMesh botnet harvesting cloud keys, and a long list of high-priority CVEs that require immediate patching and investigation.
read more →

Critical WordPress REST Batch API RCE Patch Urged

⚠️ Security researchers disclosed a pre-authentication remote code execution flaw in WordPress’ built-in REST Batch API, tracked as wp2shell. The bug allows attackers to execute arbitrary code on default WordPress installs without plugins or authentication by exploiting an indexing mismatch in the batch/v1 endpoint. Affected versions include 6.9.0–6.9.4 and 7.0.0–7.0.1; fixes were released in 6.9.5, 7.0.2 and 6.8.6. Administrators are urged to patch immediately or block the REST Batch endpoints at the web server or WAF and inventory all WordPress instances.
read more →

Critical ServiceNow RCE Flaw Now Observed Exploited

🛡️ Security researchers report active exploitation of a pre-auth sandbox escape and remote code execution bug (CVE-2026-6875) in the ServiceNow AI Platform. The vulnerability, disclosed in early April and patched for hosted and self-hosted instances in mid-July, allows unauthenticated actors to execute code by escaping the platform sandbox. Defused confirmed in-the-wild attacks days after patches were released, though ServiceNow states it is not currently aware of exploitation against instances and urges customers to apply updates immediately.
read more →

Critical WordPress core flaw enables anonymous RCE

🔒 WordPress patches a critical pre-auth remote code execution (RCE) in core that an anonymous HTTP request could exploit on default installs. Researcher Adam Kues of Assetnote reported the issue as wp2shell, and WordPress released versions 6.9.5 and 7.0.2 on July 17, 2026, to remediate affected 6.9.x and 7.0.x releases. Owners should verify their exact version and apply updates; Searchlight offers a checker and temporary mitigations for the REST batch endpoint.
read more →

New LegacyHive Windows zero-day enables privilege escalation

🔒 A researcher known as Nightmare Eclipse published a proof-of-concept named LegacyHive after Microsoft's July 2026 Patch Tuesday, claiming it exploits a vulnerability in the Windows User Profile Service. The PoC has been intentionally modified to require additional credentials, making exploitation harder than earlier releases. Analysts note successful exploitation allows non-admin users to modify the classes registry hive and achieve code execution on admin login. Detection queries for Microsoft Defender for Endpoint were published shortly after.
read more →

Chained Zero-Day Flaws in Siemens ROX II Switches

🛡️ This Unit 42 advisory, developed in partnership with Siemens, describes a chained exploit of three zero-day vulnerabilities in Siemens ROX II OT switches. The chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) enables arbitrary file disclosure, root privilege escalation and persistent root execution, risking full device compromise. Siemens has issued advisories and a firmware update V2.17.1; Palo Alto Networks provides virtual patching and OT device protections.
read more →

Patch surge strains defenders amid AI‑driven finds

🔥 This week’s Threat Source highlights a record Microsoft Patch Tuesday that fixed 622 vulnerabilities, including two zero‑days being actively exploited. Cisco Talos discloses UAT‑11795, a Russian‑speaking group using trojanized installers to deliver the Python-based Starland RAT and an in-memory PowerShell implant called WLDR agent. The newsletter outlines detection guidance and emphasizes the operational stress on IT teams facing accelerated vulnerability discovery driven by frontier AI research.
read more →

CISA orders federal patching for exploited Oracle EBS flaw

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch systems by Saturday to mitigate active exploitation of a critical Oracle E-Business Suite vulnerability, tracked as CVE-2026-46817. The flaw in the Oracle Payments File Transmission component allows unauthenticated HTTP access leading to system takeover in low-complexity attacks. Oracle issued fixes in its May 2026 Critical Security Patch Update and urged immediate patching, while security firms and CISA have observed active exploitation. Shadowserver reports over 1,000 Internet-exposed Oracle EBS instances, many in the U.S., prompting CISA to add the flaw to its list of known exploited vulnerabilities and mandate remediation under BOD 26-04.
read more →

Microsoft issues unprecedented July Patch Tuesday updates

🛡️ Microsoft released updates for 570 CVEs on the July 14 Patch Tuesday, prompted by its use of agentic AI to discover flaws. The update batch includes three zero-days (two exploited in the wild) and a large number of elevation-of-privilege, remote code execution and information disclosure bugs. Experts warn this surge is becoming the new normal and urge organizations to adopt risk-based patching, attack-surface reduction and scalable processes.
read more →

SonicWall SMA 1000 Zero‑Days Prompt Urgent Patches

🛡️ SonicWall warned of active exploitation of two zero‑day vulnerabilities affecting Secure Mobile Access (SMA) 1000 series appliances, including an SSRF that scores 10.0 and a post‑auth code injection allowing command execution. Patches are available in platform hotfix builds 12.4.3‑03453, 12.5.0‑02835 and later; customers are urged to apply fixes and perform forensic checks for specific IoCs. CISA added both flaws to its KEV catalog and set a July 17, 2026 deadline for federal agencies.
read more →

SonicWall SMA1000 Zero-Day Flaws Prompt Urgent Patch

🛡️ SonicWall warns customers that two SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being actively exploited and urges immediate installation of hotfixes. CVE-2026-15409 is a critical SSRF (CVSS 10.0) in the Appliance Work Place interface allowing unauthenticated requests, while CVE-2026-15410 is a high-severity post-authentication code injection (CVSS 7.2) enabling OS command execution. Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835 and later; SonicWall provided IOCs and recommends re-imaging compromised devices.
read more →

Microsoft issues record July security update batch

🔒 Microsoft released updates addressing a record 570 security vulnerabilities in July’s Patch Tuesday, attributing the surge to AI-assisted discovery. Nearly 60 of the flaws are rated critical, and three are confirmed zero-days already exploited in the wild. The fixes include numerous elevation-of-privilege bugs and a BitLocker security bypass; vendors warn that AI speeds both discovery and exploit development.
read more →

Progress confirms ShareFile zero‑day behind shutdown

🛡️ Progress Software confirmed a high‑severity zero‑day in ShareFile Storage Zone Controller that prompted an emergency shutdown of customer Windows servers. The flaw is a path traversal impacting all 5.x and 6.x releases, allowing an authenticated admin to read arbitrary files, write attacker‑controlled content, or enumerate the filesystem. Progress released patches (5.12.5 and 6.0.2), reserved a CVE to be published in two weeks, and currently reports no evidence of customer data breaches.
read more →

AI-Driven Breaches Force Rethink of Incident Response

🛡️ Enterprises face a new class of attacks as threat actors leverage AI agents to automate entire intrusion chains, dramatically compressing the time from initial access to deep compromise. Reports from Sygnia and Sysdig document AI-enabled campaigns that harvest credentials, map services, and persist across cloud environments, often exploiting known vulnerabilities rather than zero-days. Experts warn that traditional, human-speed incident response and hunting are often too slow, and emphasize the need for integrated, AI-assisted defenses and rigorous hygiene: fast patching, secrets rotation, least privilege, segmentation, and automated response playbooks.
read more →

Microsoft warns of rising Windows security updates

🛡️ Microsoft says it is deploying AI-driven analysis to uncover more zero-day vulnerabilities across the Windows codebase, warning customers to expect an increased number of security updates. The company described a multi-model agentic scanning harness (MDASH) and a separate prove pipeline to validate findings, aiming to reduce false positives and shorten review windows. Microsoft also plans to update its Secure Development Lifecycle to address AI-enabled attack techniques while retaining human oversight to ensure update quality.
read more →

Microsoft patches Defender RoguePlanet zero‑day

🛡️ Microsoft released a Malware Protection Engine update to fix a Defender zero-day tracked as CVE-2026-50656, dubbed "RoguePlanet." The vulnerability, disclosed by researcher "Nightmare Eclipse," allows spawning a SYSTEM command prompt via a Defender race condition and reportedly works on fully patched Windows 10 and 11 devices. Microsoft shipped version 1.1.26060.3008 to address the issue after confirming work on a patch on June 16.
read more →

Convicted Operators Run Controversial Cybersecurity Startup

🛡️ A cybersecurity startup called IRIS C2, linked to Calvexa Group LLC, is publicly recruiting researchers and offering large payouts for zero-day exploits. The venture is tied to convicted felons and far-right activists Jack Burkman and Jacob Wohl, who have a history of fake intelligence firms, robocall schemes, and legal penalties. IRIS C2 claims to sell offensive capabilities to governments and says it hires junior talent regardless of formal credentials.
read more →

KDDI breach exposes millions of email accounts

📧 KDDI, Japan's second-largest telecom, disclosed a breach of an email platform used by five ISPs that exposed millions of email addresses and passwords. The company detected the incident on June 17 and says attackers exploited a zero-day in third-party software on May 16. KDDI reported up to 14.22 million affected accounts, with 12.23 million email addresses and 7.62 million passwords exposed, and is forcing password changes and deploying EDR.
read more →