#0days — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #0days, aggregated by home.social.
-
Microsoft Just Patched a Record 570 Flaws in Windows | Lifehacker https://lifehacker.com/tech/microsoft-just-patched-570-flaws-in-windows #cybersecurity #Windows #UpdateNow #0Days
-
Anonymous GitHub account mass-dropping undisclosed 0-days (github.com/bikini)
-
Oh, look! An anonymous hero 🤡 on #GitHub is handing out unreported 0-days like candy, because nothing screams "responsible disclosure" quite like a digital piñata of exploits. 🎉 But hey, don't abuse them, they're just for "alluring" people. Yeah, right. 🙄
https://github.com/bikini/exploitarium #anonymoushero #0days #responsibleDisclosure #cybersecurity #HackerNews #ngated -
Anonymous GitHub account mass-dropping undisclosed 0-days
https://github.com/bikini/exploitarium
#HackerNews #Anonymous #GitHub #0days #security #vulnerabilities #exploit #hacking
-
-
RE: https://infosec.exchange/@jackrhysider/116523222332876813
The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks @jackrhysider for mentioning our work!
@volexity’s detection and response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild.
Read our blog post for the original research mentioned: https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/
-
ZOMG! It's freakin Patch Tuesday again. And Microsoft has patched a staggering 167 security holes (think more people are using AI to find bugs, maybe?)
tl;dr: There's something for everyone today, like an Adobe Reader 0day that's apparently been exploited since at least November 2025; a SharePoint zero-day; and a fix for BlueHammer -- a Windows Defender bug for which there is working exploit code that no longer works if you install today's Windows updates (as per @wdormann).
#patchtuesday, #microsoft #0days
https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/
-
This Week in Security: NPM, Kerbroasting, and The Rest of the Story https://hackaday.com/2025/09/12/this-week-in-security-npm-kerbroasting-and-the-rest-of-the-story/ #ObfuscatedCCodeContest #ThisWeekinSecurity #HackadayColumns #SecurityHacks #0days #NPM
-
Embedded device #hacking 101 💚
#Exploiting #0days in abandoned #hardware by @trailofbits
https://blog.trailofbits.com/2025/07/25/exploiting-zero-days-in-abandoned-hardware/
-
Spent the weekend decompiling and messing with a bunch of windows printer drivers. Was lot of fun and learnt a lot ! Found a few #0days and reported them to NCSC NZ formally known as CERT NZ. Hoping I hear back from them, and these get patched!
-
TOMORROW (4/8) at 6:30 PM EST, legendary @defcon speaker @RenderMan will be talking about his #intetnrtofdongs project finding #vuln #0days & #infosec research into smart sex toys for #DESCI NYC!
RSVP Here: https://lu.ma/descinyc32
-
TOMORROW (4/8) at 6:30 PM EST, legendary @defcon.bsky.social speaker @ihackedwhat.bsky.social will be talking about his #intetnrtofdongs project finding #vuln #0days & #infosec research into smart sex toys for #DESCI NYC! RSVP Here: lu.ma/descinyc32
-
🩹 Microsoft’s February #PatchTuesday addresses 63 security vulnerabilities, including two actively exploited #0days. Update your systems now to protect against these threats. 🔒
Read: https://hackread.com/patch-tuesday-microsoft-fixes-0-day-bugs/
-
@mcc @Infoseepage ah, makes sense. That's why I use Linux personally (for decades now). None of that AI stuff, unless you purposefully install it. IMHO Windows is great for gaming (tho many of my titles run on Linux now. Yay!), and in the enterprise of course (where I get my paycheck lol), and that's it.
Something to keep in mind, W10 hits EOL this October, so it won't be patched further after then. #APT groups will increase attacks using #0days once MSFT ceases official support exponentially.
You can still disable #Copilot in the registry of W11 24H3 (Pro and Enterprise SKUs, not Home as far as I can find). Not sure how long that will last though as #MSFT pushes hard to further integrate AI in everything they offer. At least on the Enterprise side they give us #sysadmins control over a lot of that. Consumers have much less control. It's either you embrace it, or change to a different platform.
Unfortunately (or fortunately), Linux is the only non-AI embedded OS left that I'm aware of. The next release of #macOS has #AppleIntelligence built in, #iOS 18.0 and later has it baked in, the latest release of #ChromeOS for Enterprise has #Gemini baked in, and #Android13 has #Gemini baked in on supported devices. As you know, W10 has Copilot optional with supporting hardware, W11 is baked in but can be toggled off. W12 will be a fully AI-OS.
Even still, if you're running any of the latest #IntelUltra processors, they have AI built-in at the hardware level. The new #AMDRyzen processors are doing the same.
I decided to embrace the AI evolution rather than fight it. I use my knowledge and skills to protect myself, my family, and my company as much as is possible, and keep abreast of developments in the sector...I also use AI for #cyberdefense. Only way to keep up with the threat landscape anymore.
For now, I still have control of my bubble lol, and that's about all I can do anymore, short of going completely dark. Not quite there yet lol.
-
Today's mission: find #0days in #Signet!
No, seriously, I'm writing tools to determine the impacts of a malicious client. What can the firmware defend against & what are its limitations?
Whether the code is vulnerable or secure, we should have proof. Right now the proof is "it's open source, just read the code" and that's not good enough. I want any independent security professional to be able to audit the firmware in a weekend, by themselves.
In summary #PoCorGTFO
-
Multiple #0days dropped in #Copenhagen! That naming craze for bugs & exploits does get a bit out of hand, though…
-
@bsi
Viel Erfolg! 👍
Hoffentlich werden nicht #0days/Sicherheitslücken genutzt/finanziert/offengelassen=unterstützt, sondern stattdessen an Schließung/Bekämpfung davon gearbeitet? Da gibt es ja ggf. einen Zielkonflikt mit anderen "Sicherheit"sbehörden.Ich musste bei hochmoderner Medientechnik i.V.m. Behörde erst denken an einen #tageslichtprojektor. 😉
Hier ein "ki"-generiertes Bild zum textprompt: "eine behörde für cybersicherheit macht mit einem analogen alten tageslichtprojektor eine präsentation"
quelle+3 weitere bilder:
https://www.bing.com/images/create/eine-behc3b6rde-fc3bcr-cybersicherheit-macht-mit-einem-a/1-660e9dd147e84bbab49f529038da7740?FORM=GENCRE
#cybersecurity #bsi #security -
In this blog post, Michael Hale Ligh & Andrew Case (@attrc) break down how @volexity used #memoryforensics to discover two #0days being chained together to achieve unauthenticated remote code execution in Ivanti Connect Secure VPN devices. More details here: https://www.volexity.com/blog/2024/02/01/how-memory-forensics-revealed-exploitation-of-ivanti-connect-secure-vpn-zero-day-vulnerabilities
-
Securityproblemen (0-days, Chinese hackers) met Ivanti-systemen, zie ik voorbijkomen. Ivanti, dat al enige tijd een slechte securityreputatie had en niet reageerde op kritische vragen van de Onderzoeksraad voor Veiligheid (OVV).
Nederland nog steeds kwetsbaar door software, kon ik concluderen:
https://www.agconnect.nl/tech-en-toekomst/security/nederland-nog-steeds-kwetsbaar-door-software
(En natuurlijk niet alleen Nederland. En niet alleen door software van Ivanti.)
-
Cybersecurity guru Mikko Hyppönen’s 5 most fearsome AI threats for 2024 https://thenextweb.com/news/mikko-hypponen-5-biggest-ai-cybersecurity-threats-2024 #cybersecurity #ai #deepfakes #automatedmalware #0days
-
It's the largest #Adobe patch Tuesday in recent memory. #Microsoft has a smaller release, but is addressing three #0days being actively exploited. Join @TheDustinChilds as he looks at the full release - which also includes more #Exchange patches. https://www.zerodayinitiative.com/blog/2023/11/14/the-november-2023-security-update-review
-
Some nice #security #audit work here 👍
#Squid Caching Proxy Security Audit: 55 #vulnerabilities and 35 #0days