#0-day — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #0-day, aggregated by home.social.
-
Die allerschlechteste Kombination: Chrome und Windows
Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:
#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
Pulse ID: 6aa3b2954797ae28018be984
Pulse Link: https://otx.alienvault.com/pulse/6aa3b2954797ae28018be984
Pulse Author: Tr1sa111
Created: 2026-09-11 07:49:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #Chinese #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Windows #bot #Tr1sa111
-
⚠️📢 Hackers are using hundreds of AI agents to exploit two PaperCut zero-days at scale, with at least 440 servers compromised across 395 organizations in 48 countries.
Listen/Read: https://hackread.com/hackers-use-ai-agents-exploit-papercut-zero-days/
-
SonicWall VPN-Router (Closed-Source) wird aktiv angegriffen
Appliances der SMA1000 Serie des amerikanischen Herstellers SonicWall stehen gerade unter Beschuss. Die Boxen sollen eigentlich für einen sicheren Fernzugang per VPN ins Intranet sorgen. Ja, es hätte so schön sein können. Die Angreifer verketten zwei unterschiedliche "Sicherheitslücken", um sich unbefugten Zugang in das Unternehmensnetzwerk dahinter zu verschaffen. Weshalb habe ich "Sicherheitslücken" in Anführungszeichen geschrieben? Weil es hier wieder mal streng riecht - nach Hintertür. Die erste Zero-day Schwachstelle CVE-2026-83548 (10 von 10) entsteht durch ... Weiterlesen:
#0day #backdoor #cybercrime #exploits #firewall #hersteller #router #UnplugTrump #vorbeugen #wissen #zeroday
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Microsoft Flickentag 2026-09: Neuer Rekord!
Microsoft (MS) hat seinen eigenen Rekord aus dem Juli schon wieder weit überboten. Bei diesen Zahlen wird mir schwindelig. Je nach Zählung kommt man auf 973 gestopfte Sicherheitslücken, 974 oder "mindestens 974". Fast tausend innerhalb eines Monats neu gefundene Sicherheitslücken! Von denen stuft MS 113 kritisch ein. Zwei der Sicherheitslücken wurden bereits vorab in Angriffen ausgenutzt (Zero-Day), beide stuft MS nur als "wichtig" ein, nicht als "kritisch". Kann mir mal jemand erklären, nach welchen Kriterien MS die Einstufungen vornimmt? Und dann ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/09/09/microsoft-flickentag-2026-09-neuer-rekord/
#0day #closedsource #cloud #cybercrime #exploits #Microsoft #politik #privacy #sicherheit #unplugMicrosoft #UnplugTrump #vorbeugen #zahlen #zeroday
-
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
Pulse ID: 6aa148b07d30652d84e25eaa
Pulse Link: https://otx.alienvault.com/pulse/6aa148b07d30652d84e25eaa
Pulse Author: Tr1sa111
Created: 2026-09-09 11:53:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #Adobe #CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #bot #Tr1sa111
-
🖥️🩹 Microsoft’s September #PatchTuesday is its biggest yet, fixing 966 vulnerabilities, including 2 Windows 0-days already exploited in attacks. Critical RCE flaws also affect Office, networking services and Hyper-V.
Listen/Read: https://hackread.com/microsoft-patch-tuesday-vulnerabilities-windows-0-days/
-
A Windows Defender 0day has public PoC exploit code. ShieldCrash reads files as SYSTEM on all supported Windows versions.
#WindowsDefender #0day #CVE #ShieldCrash #CyberSecurity #Windows #PoC #Infosec
-
Zero-Day-Lücke #StyleSmuggler in #Magento und #AdobeCommerce wird aktiv ausgenutzt | Security https://www.heise.de/news/Zero-Day-Luecke-StyleSmuggler-in-Magento-und-Adobe-Commerce-wird-aktiv-ausgenutzt-11444217.html #0day #ZeroDay #eCommerce
-
Дайджест ИБ, 1–7 сентября: GPT-6 Astra в проде, зарубежные NGFW теряют долю, утечка 153 млн прав
Двадцать новостных сюжетов по информационной безопасности за неделю 1-7 сентября: yязвимости, искусственный интеллект, атаки и утечки, рынок и сделки, регулирование Дайджест собран по данным автоматического агрегатора новостей из 240 источников: за семь дней прочитано ~11 653 материала, ~1 267 из них от профильных изданий, вендоров и регуляторов. Читать дайджест
https://habr.com/ru/articles/1079912/
#дайджест #информационная_безопасность #уязвимости #0day #MikroTik #SonicWall #NGFW #утечки_данных #ИИагенты #цепочка_поставок
-
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code into Magento's template system using styles properties to evade safeguards, then executing the poisoned code via failed payment emails. Upon successful compromise, attackers deploy a Rust-based backdoor disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to command and control servers. The backdoor uses NTP-shaped UDP traffic for C2 communication to evade detection. A second unrelated attacker has also been observed exploiting the same vulnerability to deploy PHP web shells. Affected merchants should deploy immediate mitigation measures, scan for compromise, and temporarily disable GraphQL until an official patch is released.
Pulse ID: 6a9ef14fbc62257cff38357b
Pulse Link: https://otx.alienvault.com/pulse/6a9ef14fbc62257cff38357b
Pulse Author: AlienVault
Created: 2026-09-07 17:15:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #Adobe #BackDoor #CyberSecurity #Email #InfoSec #Magento #OTX #OpenThreatExchange #PHP #RAT #RCE #RemoteCodeExecution #Rust #UDP #Vulnerability #ZeroDay #bot #AlienVault
-
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Indicators extracted from public reporting. Source: https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html
Pulse ID: 6a9eeca6579a625a9b9a23ed
Pulse Link: https://otx.alienvault.com/pulse/6a9eeca6579a625a9b9a23ed
Pulse Author: CyberHunter_NL
Created: 2026-09-07 16:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #Chrome #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SupplyChain #bot #CyberHunter_NL
-
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
StyleSmuggler is an unpatched zero-day vulnerability affecting all current versions of Magento and Adobe Commerce, including version 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code through the styles properties to evade safeguards, then executing it via failed payment email templates. The vulnerability exploits Magento's GraphQL endpoint and template system. Attackers deploy backdoors disguised as legitimate system processes, establish command and control through multiple domains using WebSocket over TLS and custom NTP-shaped traffic. Affected merchants should deploy protective measures, scan for compromise indicators including suspicious background processes, and consider temporarily disabling GraphQL until an official patch is released.
Pulse ID: 6a9c7c833376c19e92778b46
Pulse Link: https://otx.alienvault.com/pulse/6a9c7c833376c19e92778b46
Pulse Author: AlienVault
Created: 2026-09-05 20:33:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #Adobe #BackDoor #CyberSecurity #Email #Endpoint #InfoSec #Magento #OTX #OpenThreatExchange #PHP #RAT #RCE #RemoteCodeExecution #TLS #Vulnerability #ZeroDay #bot #AlienVault
-
A researcher claims a CrowdStrike Falcon vulnerability enabling privilege escalation and published a PoC. CrowdStrike has not confirmed it; no CVE exists.
#CrowdStrike #FalconFlank #0day #PrivilegeEscalation #PoC #EDR #InfoSec #Unverified
-
Das kommt von das: Closed-Source UND dem Internet ausgesetzt
Vermutlich werden Institutionen (Firmen, Verwaltungen), die das kommerzielle und proprietäre Druckmanagement PaperCut einsetzen, hier nicht lesen. Trotzdem schreibe ich darüber, weil zwei wichtige Lehren für uns alle enthalten sind. Zunächst die nackten Fakten: Die Firma PaperCut musste ein Notfall-Update veröffentlichen, weil die Software aus dem Internet angegriffen wird. Weder wird berichtet, worin die Schwachstelle besteht, noch welche Auswirkungen ein erfolgreicher Angriff hat. Sie hat noch keine CVE-Nummer erhalten und nur die Einstufung "kritisch". Das Update ist eine Notmaßnahme, die nicht den üblichen ... Weiterlesen:
-
Attacks on AI Infrastructure: 90-Day Honeypot Telemetry
Wiz Threat Research deployed honeypots across AI and ML services including LiteLLM, Flowise, LangChain, Langflow, ChromaDB, and Ollama, observing sustained attack activity over 90 days. Three distinct attack patterns emerged: exploitation of Internet-facing MCP servers for remote code execution through authentication bypass and command injection vulnerabilities; blind prompt injection attacks against AI agent frameworks using out-of-band DNS callbacks to confirm execution; and AI-native post-exploitation techniques adapted to AI infrastructure internals, including extracting master keys from Python module state and staging cryptominers in framework-specific directories. Attackers demonstrated deep knowledge of AI tooling internals, targeting credential concentration points where proxies hold multiple provider keys, and exploiting agent reachability to execute instructions embedded in requests. The campaigns primarily deployed XMRig cryptominers, leveraging framework-specific paths and processes for camoufl...
Pulse ID: 6a90b73a3cf4e349584c8d6d
Pulse Link: https://otx.alienvault.com/pulse/6a90b73a3cf4e349584c8d6d
Pulse Author: AlienVault
Created: 2026-08-27 22:16:26Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #CryptoMiner #CyberSecurity #DNS #Edge #HoneyPot #InfoSec #OTX #OpenThreatExchange #Python #RAT #RemoteCodeExecution #bot #AlienVault
-
‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out
The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.
Pulse ID: 6a9035ff9a03d932d9008b31
Pulse Link: https://otx.alienvault.com/pulse/6a9035ff9a03d932d9008b31
Pulse Author: AlienVault
Created: 2026-08-27 13:05:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #Asia #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #SMS #Windows #bot #AlienVault
-
Начинаем в багбаунти: что такое уязвимости 1-day
Всем привет! С вами Михаил Ключников. Я работаю в Positive Technologies уже 10 лет, где руковожу группой по анализу защищенности ПО. Мы занимаемся поиском новых уязвимостей ( 0-day ) и воспроизведением уже известных ( 1-day ) для нужд пентестов. Еще я состою в команде PT SWARM: ее участники пишут статьи, делают различные типсы и разборы уязвимостей по горячим следам. У меня довольно большой опыт в багхантинге на различных международных платформах и на российской Standoff Bug Bounty. В этой статье я хочу поделиться своим опытом работы с 1-day уязвимостями — багами, которые могут быть опасны, хотя для них уже вышел патч. Мы разберем жизненный цикл уязвимости, способы их мониторинга, инструменты анализа, методы воспроизведения и правила репортинга. Вы узнаете, как правильно работать с 1-day в рамках багбаунти, чтобы не тратить время впустую и добиваться результата.
https://habr.com/ru/companies/pt/articles/1070316/
#0day #1day #уязвимости #багхантинг #багбаунти #bugbounty #standoff_365
-
Mysterien um Microsofts kritisches Sicherheitsloch in Entra ID
Am vorigen Donnerstag macht Microsoft (MS) ein riesiges Trara um eine höchst gefährliche Sicherheitslücke CVE-2026-69836 (Risiko 10 von 10) in Entra ID*. Ein entfernter, nicht autorisierter Angreifer könne durch Ausnutzung dieser Sicherheitslücke beliebigen Programmcode ausführen (RCE). Und die Lücke würde bereits für Angriffe ausgenutzt. Meldungen beispielsweise hier oder hier. Wie die Ausnutzung entdeckt wurde und wer vielleicht betroffen ist, verlautet MS nicht. Einen Tag später zieht MS die Auskunft "wird bereits ausgenutzt" zurück. Hä? Interessant ist auch, dass ... Weiterlesen:
#0day #backdoor #cloud #exploits #identität #Microsoft #sicherheit #unplugMicrosoft #UnplugTrump
-
Warnung vor Angriffen gegen Fortinet
Diese Meldung wiederholt das Thema der vorigen: Software (oder Firmware) nicht aktuell -> gehackt. Heute geht es um eine konkrete Erpresser-Gang namens Gunra. Die durchsucht das Internet nach erreichbaren Firewalls und Routern von Fortinet und versucht, ältere Sicherheitslücken (CVE-2024-55591 und CVE-2025-24472) auszunutzen. Beide sind längst als bereits ausgenutzt bekannt. Wenn die verfügbaren Updates nicht eingespielt wurden, die Lücken also noch offen sind, ist das angegriffene Netzwerk kompromittiert; Datenlecks, Betriebsunterbrechungen und Erpressung folgen. In den USA hat es bereits viele Institutionen getroffen, vom ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/08/14/warnung-vor-angriffen-gegen-fortinet/
#0day #closedsource #cybercrime #firewall #hersteller #router #sicherheit #vorbeugen
-
Weiteres Zero-Day Sicherheitsloch in Windows Defender
Der Hacker Nightmare Eclipse (oder Chaotic Eclipse), der sich schon seit Anfang April auf einem Rachefeldzug gegen #Microsoft (MS) befindet, hat genau einen Tag nach dem MS-Flickentag die nächste #Zero-Day Sicherheitslücke veröffentlicht. Die steckt wieder mal im Windows Defender*. Die Lücke ist inzwischen die zehnte in seinem Zoo. Einen auf W-X und W-11 funktionierenden Exploit liefert er gleich mit. Da die Lücke bisher nicht bekannt war (auch nicht bei MS), gibt es noch keinen Flicken dagegen. Herzlichen Glückwunsch an alle Windows-Nutzer/innen. Einzig tröstlich ist, dass diese Lücke nur von einem angemeldeten ... Weiterlesen:
#0day #antivirus #exploits #sicherheit #unplugMicrosoft #UnplugTrump #windows
-
Microsoft Flickentag 2026-08: Fast Rekord
Der Allzeit-Rekord vom Juli ist nicht erreicht, aber im August beschert uns #Microsoft (MS) mit Flicken gegen immerhin rund doppelt so viele Sicherheitslücken wie im vorherigen Rekord-Monat Juni. Je nach Zählung sind es "mindestens 398", 418 oder 421 Sicherheitslücken. Von den jetzt geflickten Sicherheitslücken schätzt MS selber 62 kritisch ein, und das will bei MS etwas heißen. Zwei andere Sicherheitslücken (nicht als kritisch eingestuft) waren als #Zero-Day schon vor den jetzt veröffentlichten Updates bekannt, eine weitere (ebenfalls nur als wichtig ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/08/12/microsoft-flickentag-2026-08-fast-rekord/
#0day #cloud #cybercrime #datenschutz #exploits #office #privacy #sicherheit #spionage #unplugMicrosoft #UnplugTrump #vorbeugen #windows #wissen
-
Juridisk software virksomhed tog ned 3 it-systemer, efter at de blev ramt af hackere - en del af Metabase data-base #0day angrebene
https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/ -
Researchers detail 176 patched vulnerabilities in Samsung phone apps that enabled camera recordings, screen capture, DNS hijacking, and theft of sensitive data.
Listen/Read: https://hackread.com/samsung-patched-app-flaws-camera-recording-data-bugs/
-
Framework breach: Modululær laptop maker Framework har underrettet brugerne om et sikkerheds-brud forårsaget af et hack af sin Metabase cloud data-base
Hackere udnytter en #0day i Metabase-databasen til at stjæle kundedata
Metabase har bekræftet angreb mod sine cloud-hostede systemer og servere
..er en SQL-injection, der giver angribere admin adgang over databasen og dens indhold
https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/