Articles tagged "Zero-day"

Found 117 articles

A newly discovered zero-day vulnerability in the Gogs self-hosted Git service allows attackers to execute remote code on servers that are exposed to the internet. This flaw poses a significant risk to organizations using Gogs for version control, as malicious actors could potentially gain full control over affected systems. Currently, there are no patches available to fix this issue, leaving users vulnerable until a solution is released. The exploitation of this vulnerability is particularly concerning because it can lead to data breaches or further attacks within an organization's infrastructure. Users and administrators of Gogs should take immediate action to secure their installations and monitor for any unusual activity.

Impact: Gogs self-hosted Git service
Remediation: Users are advised to secure their installations and monitor for unusual activity until a patch is released.
Read Original

A recently discovered zero-day vulnerability in the LiteSpeed cPanel plugin has been exploited by attackers to execute scripts with root privileges. This security flaw poses a significant risk to users of LiteSpeed's web server and cPanel, particularly those who have not yet applied the necessary patches. The Cybersecurity and Infrastructure Security Agency (CISA) has urged immediate action to patch this vulnerability, which had been actively exploited before it was resolved last week. Failure to address this issue could leave systems vulnerable to further attacks, potentially compromising sensitive data and system integrity. Users are strongly advised to prioritize updates to safeguard their environments.

Impact: LiteSpeed cPanel plugin
Remediation: Users should immediately apply the latest patches provided by LiteSpeed to mitigate the vulnerability.
Read Original

Hackers have taken advantage of a zero-day vulnerability in the KnowledgeDeliver learning management system (LMS) to install a malicious web shell known as Godzilla. This security flaw allows attackers to gain unauthorized access to systems running this LMS, potentially compromising sensitive data and disrupting services. Organizations using KnowledgeDeliver should be particularly vigilant, as the exploitation of this vulnerability could lead to significant operational and data security issues. The presence of a web shell means that attackers can execute commands remotely, making it crucial for affected users to take immediate action to secure their systems. Companies must prioritize patching and monitoring their environments to mitigate the risks associated with this exploit.

Impact: KnowledgeDeliver learning management system
Remediation: Users should apply any available patches from KnowledgeDeliver and closely monitor their systems for unauthorized access. Regular security assessments and updates are recommended.
Read Original

A zero-day vulnerability identified as CVE-2026-5426 has been discovered in a Japanese Learning Management System (LMS). This security flaw arises from the use of hard-coded ASP.NET machine keys, which attackers can exploit to deploy Cobalt Strike, a popular penetration testing tool that can also be used for malicious purposes. The exploitation of this vulnerability poses significant risks to educational institutions and organizations using the LMS, potentially allowing unauthorized access to sensitive information and systems. Users of the affected LMS should take immediate steps to secure their systems to prevent potential intrusions.

Impact: Japanese Learning Management System (LMS) using ASP.NET
Remediation: Users should update their LMS to remove hard-coded ASP.NET machine keys and implement secure key management practices. Regularly reviewing and updating security configurations is also recommended.
Read Original

Trend Micro has reported a serious security vulnerability in its Apex One platform, identified as CVE-2026-34926. This flaw allows for a directory path traversal, which means attackers could potentially access files and directories outside the intended scope. The company has confirmed that this vulnerability is being actively exploited in the wild, with at least one confirmed incident. Organizations using the Apex One platform are at risk, which makes it crucial for them to act quickly. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding this vulnerability, urging affected users to take immediate action to protect their systems.

Impact: Trend Micro Apex One platform
Remediation: Organizations should apply the latest security updates provided by Trend Micro to mitigate this vulnerability. Additionally, users are advised to review their system configurations and restrict access to sensitive directories as a precaution.
Read Original

TrendAI has addressed a serious vulnerability in its Apex One security software, identified as CVE-2026-34926. This flaw is a directory traversal issue that could be exploited by attackers to gain unauthorized access to files on the system. The vulnerability specifically affects the on-premise version of Apex One, which is used by various organizations for endpoint security. Given that this vulnerability has been exploited in the wild, it poses a significant risk to users who have not yet applied the necessary updates. Companies using Apex One should prioritize applying the latest patches to safeguard their systems against potential breaches.

Impact: Apex One on-premise version, TrendAI
Remediation: Users should apply the latest patches released by TrendAI to mitigate the vulnerability. Specific patch numbers or versions were not mentioned, but immediate action is advised to secure systems.
Read Original

Microsoft has addressed a significant vulnerability in its BitLocker encryption feature, identified as YellowKey and tracked under the CVE-2026-45585 designation. This security flaw, which has a CVSS score of 6.8, allows attackers to bypass key protections, potentially exposing sensitive data on affected systems. The issue was publicly disclosed last week, prompting Microsoft to issue a mitigation to protect users. This vulnerability primarily affects Windows operating systems that utilize BitLocker for disk encryption. Given that BitLocker is widely used by businesses and individuals to secure data, the implications of this flaw are serious, making it crucial for users to implement the provided mitigation as soon as possible.

Impact: Windows operating systems utilizing BitLocker encryption
Remediation: Microsoft has released a mitigation for the YellowKey vulnerability. Users are advised to apply this mitigation to safeguard their systems.
Read Original

Microsoft has recently disclosed a zero-day vulnerability known as YellowKey that affects Windows BitLocker, which is used for encrypting drives. This vulnerability allows unauthorized access to protected drives, posing a significant risk to users' sensitive data. While Microsoft has not specified which particular versions of Windows are impacted, the potential for exploitation raises concerns for many users and organizations relying on BitLocker for data protection. Microsoft has provided mitigation strategies to help users safeguard their systems until a more permanent fix is available. It is crucial for users to implement these mitigations to prevent unauthorized access to their data.

Impact: Windows BitLocker
Remediation: Microsoft has shared mitigations for the vulnerability, but specific patch numbers or updates have not been detailed.
Read Original

On July 23, 2025, Luxembourg experienced a major telecom outage that lasted over three hours, affecting landline, 4G, 5G, and emergency services. The disruption was reportedly caused by a zero-day vulnerability in Huawei enterprise routers. This flaw allowed attackers to exploit the system, leading to widespread communication failures across the country. The incident raised concerns about the security of telecom infrastructure and the potential risks associated with undisclosed vulnerabilities in widely used equipment. The implications of this outage are significant, as it not only disrupted everyday communications but also emergency services, highlighting the critical need for robust cybersecurity measures in telecommunications.

Impact: Huawei enterprise routers, landline services, 4G networks, 5G networks, emergency communication systems
Remediation: N/A
Read Original
Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts

Hackread – Cybersecurity News, Data Breaches, AI and More

At Pwn2Own Berlin 2026, cybersecurity researchers showcased 47 different zero-day exploits, targeting well-known enterprise software and artificial intelligence platforms. This event, which is part of an ongoing competition to identify security vulnerabilities, underscores the persistent risks facing organizations that rely on these technologies. Major software vendors are particularly affected, as these exploits could potentially allow attackers to gain unauthorized access or control over systems. The findings stress the need for companies to prioritize security updates and vulnerability management to protect sensitive data and maintain system integrity. The significant payout of $1.3 million for these discoveries further emphasizes the financial incentive for researchers to identify and report such vulnerabilities.

Impact: Major enterprise software and AI platforms (specific products not detailed)
Remediation: Organizations should implement regular security updates and patch management practices to address identified vulnerabilities. Continuous monitoring for new exploits and adopting a proactive security posture is recommended.
Read Original

A newly discovered zero-day vulnerability in Microsoft Exchange, tracked as CVE-2026-42897, poses a significant risk as it allows attackers to exploit cross-site scripting (XSS) to compromise Outlook Web Access (OWA) mailboxes. This vulnerability is reportedly under active attack, meaning that malicious actors are currently trying to exploit it in the wild. Organizations using Microsoft Exchange should be particularly vigilant, as the absence of an available patch leaves their systems exposed. Without immediate remediation, users could face unauthorized access to sensitive email communications. Companies are advised to implement security measures, such as input validation and monitoring for suspicious activity, until an official patch is released.

Impact: Microsoft Exchange, Outlook Web Access (OWA)
Remediation: Organizations should implement input validation to mitigate XSS attacks, monitor for unusual access patterns, and restrict OWA access where possible until a patch is released.
Read Original

At the recent Pwn2Own event in Berlin, security researchers identified 47 zero-day vulnerabilities in various software and systems, earning a total of $1.3 million in rewards for their findings. These vulnerabilities could potentially allow attackers to exploit systems and gain unauthorized access to sensitive information. The discoveries underscore the ongoing need for companies to enhance their security measures and patch their systems promptly to mitigate risks. This event serves as a reminder of the vulnerabilities that exist in widely used software and the importance of proactive security research. As these zero-days are disclosed, affected vendors will need to act quickly to protect their users.

Impact: Various software and systems (specific products not mentioned)
Remediation: Vendors should release patches and updates to address the identified vulnerabilities.
Read Original

A security researcher known as Chaotic Eclipse has disclosed a serious zero-day vulnerability in Windows called MiniPlasma, which allows attackers to gain SYSTEM privileges on fully updated Windows 11 systems. This flaw, affecting the 'cldflt.sys' file, was believed to have been patched back in 2020 under the CVE-2020-17103 designation, but it appears that the fix was either incomplete or not properly implemented. The existence of a proof-of-concept exploit for this vulnerability raises significant concerns for users and organizations, as it could allow malicious actors to escalate their privileges and potentially take control of affected systems. This issue affects all patched versions of Windows 11, meaning a wide range of users are at risk. Companies should prioritize reviewing their security protocols and consider additional monitoring to mitigate potential exploitation.

Impact: Windows 11 systems, specifically those using the 'cldflt.sys' driver.
Remediation: Users should install any available security updates from Microsoft and monitor for any new patches addressing CVE-2020-17103. Additional security measures include enhancing system monitoring and access controls to detect potential exploitation attempts.
Read Original

The Pwn2Own Berlin 2026 hacking competition recently wrapped up, with security researchers successfully exploiting 47 zero-day vulnerabilities, earning a total of $1,298,250 in rewards. This event showcases the capabilities of ethical hackers who identify and report security flaws before malicious actors can exploit them. The zero-days affected various software and systems, indicating that numerous products may be at risk if these vulnerabilities are not addressed. This situation emphasizes the ongoing need for companies to remain vigilant and proactive in their cybersecurity efforts to protect users and sensitive data. The findings from this contest could lead to important updates and patches, helping to secure software against potential attacks.

Impact: Various software and systems affected (specific products not mentioned)
Remediation: N/A
Read Original

A cybersecurity researcher has disclosed a serious vulnerability in Windows, known as 'MiniPlasma', which allows attackers to escalate their privileges to SYSTEM level on fully patched systems. This zero-day exploit poses a significant risk because it can enable unauthorized access to sensitive data and system controls. Users of Windows systems, particularly those in corporate environments, should be on high alert as this exploit can potentially be used in cyberattacks. The researcher has also released a proof-of-concept (PoC) for the exploit, which can facilitate its misuse by malicious actors. This situation underscores the need for immediate attention to system security measures and vigilance against potential exploitation.

Impact: Fully patched Windows systems, particularly versions that allow privilege escalation to SYSTEM level.
Remediation: Users should apply the latest security patches from Microsoft as they become available. Additionally, organizations should enhance their monitoring and detection capabilities to identify any suspicious activity that may indicate exploitation of this vulnerability.
Read Original
Page 1 of 8Next