The Pwn2Own Berlin 2026 hacking competition recently wrapped up, with security researchers successfully exploiting 47 zero-day vulnerabilities, earning a total of $1,298,250 in rewards. This event showcases the capabilities of ethical hackers who identify and report security flaws before malicious actors can exploit them. The zero-days affected various software and systems, indicating that numerous products may be at risk if these vulnerabilities are not addressed. This situation emphasizes the ongoing need for companies to remain vigilant and proactive in their cybersecurity efforts to protect users and sensitive data. The findings from this contest could lead to important updates and patches, helping to secure software against potential attacks.
A cybersecurity researcher has disclosed a serious vulnerability in Windows, known as 'MiniPlasma', which allows attackers to escalate their privileges to SYSTEM level on fully patched systems. This zero-day exploit poses a significant risk because it can enable unauthorized access to sensitive data and system controls. Users of Windows systems, particularly those in corporate environments, should be on high alert as this exploit can potentially be used in cyberattacks. The researcher has also released a proof-of-concept (PoC) for the exploit, which can facilitate its misuse by malicious actors. This situation underscores the need for immediate attention to system security measures and vigilance against potential exploitation.
Last week, Cisco released a patch for a zero-day vulnerability affecting its SD-WAN product. This flaw could allow attackers to gain unauthorized access to the network and potentially disrupt services. Meanwhile, a previously unpatched vulnerability in Microsoft Exchange Server has been actively exploited by attackers, putting many organizations at risk. These incidents highlight the ongoing challenges companies face in securing their systems against evolving threats. It’s crucial for affected users to apply the latest patches and take proactive measures to protect their networks.
Pwn2Own Berlin 2026 concluded with DEVCORE emerging as the standout performer, successfully identifying 47 unique zero-day vulnerabilities during the event. Over three days, researchers earned a total of $1.29 million in rewards for their discoveries, showcasing the event's focus on security challenges across various platforms and applications. This year's competition not only highlighted the skills of participants but also underscored the ongoing need for robust cybersecurity measures in software development. With the number of zero-day vulnerabilities found, it emphasizes the vulnerabilities present in widely used systems and applications, prompting companies to reassess their security protocols. The event took place in conjunction with OffensiveCon, further connecting the research community with industry professionals.
CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day
Security Affairs
Actively Exploited
Microsoft has confirmed that a new zero-day vulnerability in Exchange Server, identified as CVE-2026-42897, is being actively exploited by attackers. This vulnerability has a CVSS score of 8.1, indicating a high level of severity. It stems from improper handling of user input during web page generation, which can lead to cross-site scripting (XSS) attacks. Organizations using affected versions of Exchange Server are at risk, as attackers could exploit this flaw to execute malicious scripts in the context of users' browsers. Microsoft urges users to take immediate action to protect their systems and data from potential breaches.
Cisco has released a patch for a serious security vulnerability (CVE-2026-20182) affecting its Catalyst SD-WAN solutions. This flaw allows attackers to bypass authentication in both the Catalyst SD-WAN Controller and the Catalyst SD-WAN Manager, which are critical components for managing SD-WAN deployments. The vulnerability has been actively exploited by a sophisticated cyber threat actor, putting both on-premises and cloud users at risk. Organizations using these Cisco products should prioritize applying the patch to safeguard their networks from potential breaches. Failure to address this vulnerability could lead to unauthorized access and significant security incidents.
Microsoft has issued a warning regarding a zero-day vulnerability in Exchange Server, identified as CVE-2026-42897, which is currently being exploited by attackers. This vulnerability affects various versions of Exchange Server, putting organizations that use this software at risk. Microsoft has not yet released a permanent patch but has provided interim mitigations to help secure affected systems. Users and administrators are urged to implement these mitigations to protect their environments until a comprehensive fix is available. The active exploitation of this vulnerability underscores the urgency for affected organizations to take immediate action.
Cisco has released a patch for a newly discovered zero-day vulnerability, identified as CVE-2026-20182, which has been actively exploited in targeted attacks. This vulnerability affects Cisco’s SD-WAN products and has been linked to a sophisticated threat actor known as UAT-8616. The exploitation of this flaw marks the sixth zero-day incident involving Cisco in 2026, raising concerns about the security of their products. Companies using Cisco SD-WAN solutions should prioritize applying the latest patches to protect against potential breaches. The ongoing exploitation of this vulnerability highlights the need for vigilance in cybersecurity practices.
On the first day of Pwn2Own Berlin 2026, researchers showcased their skills by identifying 24 zero-day vulnerabilities across various technologies, earning a total of $523,000 in rewards. The entries targeted popular software, including web browsers, operating systems, AI platforms, and NVIDIA infrastructure. This event is significant as it emphasizes the ongoing security challenges faced by widely used technologies, particularly in the realm of AI. The discoveries made during this competition not only highlight the vulnerabilities that could be exploited by attackers but also serve as a wake-up call for developers and organizations to enhance their security measures. As these zero-days are revealed, it’s crucial for affected vendors to respond swiftly to mitigate potential risks to users.
A security researcher has disclosed two serious vulnerabilities in Windows, known as YellowKey and GreenPlasma. YellowKey is a BitLocker bypass that allows unauthorized access to encrypted drives, but it requires physical access to the device. GreenPlasma, on the other hand, enables attackers to elevate their privileges to System level, potentially giving them full control over the affected system. These vulnerabilities pose a significant risk to users and organizations that rely on Windows for sensitive tasks. Companies should assess their physical security measures and apply necessary updates to protect against these risks.
Hackread – Cybersecurity News, Data Breaches, AI and More
Pwn2Own Berlin 2026 has reached full capacity for the first time, leading some researchers who were unable to participate to disclose zero-day exploits publicly. These exploits target widely used software and hardware, specifically Firefox and NVIDIA products, as well as various AI platforms. This situation raises concerns for users and companies relying on these technologies, as zero-day vulnerabilities can be exploited by attackers before patches are released. The public disclosure of these vulnerabilities means that organizations need to act quickly to assess their exposure and implement necessary security measures. This incident emphasizes the ongoing arms race between security researchers and hackers in the cybersecurity landscape.
Google has identified the first zero-day exploit generated by AI, which is capable of bypassing two-factor authentication (2FA). This exploit was developed by a notable cybercrime group, raising concerns about the increasing sophistication of cyber attacks. The implications are significant, as 2FA is widely used to enhance security across various platforms and services. If attackers can bypass this layer of protection, many users could be at risk of unauthorized access to their accounts. This incident underscores the urgent need for companies and individuals to reassess their security measures in light of evolving threats.
The article discusses several cybersecurity topics, including new vulnerabilities and incidents. Notably, it mentions a zero-day exploit affecting Canvas, a learning management system used by educational institutions. This vulnerability could allow attackers to execute unauthorized code, putting sensitive student data at risk. Additionally, it highlights the QuasarRat malware, which has been observed in the wild, targeting various systems. The article also touches on compliance issues faced by companies like Anthropic regarding EU regulations, which can impact their operations. Overall, these developments serve as a reminder for organizations to stay vigilant and update their security measures regularly to protect against evolving threats.
A newly discovered zero-day vulnerability, dubbed 'Dirty Frag', affects most Linux distributions and allows attackers to escalate their privileges to root level. This means that a malicious actor could gain full control over a compromised system, putting sensitive data and operations at risk. The vulnerability is particularly concerning because it impacts a wide range of systems, making it a significant threat for both individual users and organizations that rely on Linux. Researchers are urging users and system administrators to take immediate action to secure their systems. The exact details of how this vulnerability can be exploited are still being analyzed, but the potential for active exploitation is high, prompting a call for swift remediation efforts.
CISA, the U.S. Cybersecurity and Infrastructure Security Agency, has issued an urgent notice to federal agencies to address a serious vulnerability in Ivanti Endpoint Manager Mobile (EPMM). This flaw has been exploited in zero-day attacks, meaning attackers have already taken advantage of it before a fix was available. Federal agencies have just four days to patch their systems to prevent potential breaches. The vulnerability poses a significant risk as it could allow unauthorized access to sensitive information. Agencies using Ivanti EPMM need to act quickly to secure their networks and protect against these exploits.