home.social

#zeroday — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.

fetched live
  1. 🚨 SIGINT // Cybersecurity Watch — 2026-07-29
    Critical Arista VeloCloud Orchestrator vulnerability exploited as a zero-day, threatening SD-WAN infrastructure worldwide.
    securityweek.com/critical-aris

  2. OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

    OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI…

    osintsights.com/openai-models-

    #ZeroDay #Jfrog #Openai #Artifactory #VulnerabilityDisclosure

  3. 🔵 THREAT INTELLIGENCE

    Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

    Vulnerability | CRITICAL
    CVEs: CVE-2026-16812

    Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively...

    Full analysis:
    yazoul.net/news/article/attack

    #InfoSec #ZeroDay #ThreatHunting

  4. 🔴 New security advisory:

    CVE-2026-55579 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #InfoSec #ZeroDay #ThreatIntel

  5. CISA has added a vulnerability to the KEV catalogue.

    - CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability cve.org/CVERecord?id=CVE-2025-

    Also:

    Cisco tagged Apple yesterday for zero-day reports talosintelligence.com/vulnerab @TalosSecurity #Fortinet #CISA #infosec #vulnerability #Apple #zeroday

  6. CISA has added a vulnerability to the KEV catalogue.

    - CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability cve.org/CVERecord?id=CVE-2025-

    Also:

    Cisco tagged Apple yesterday for zero-day reports talosintelligence.com/vulnerab @TalosSecurity #Fortinet #CISA #infosec #vulnerability #Apple #zeroday

  7. Just a polite AI agent suddenly owning your entire filesystem like it paid rent.

    I would slow-clap, but my hands are full admiring the wreckage. Update Claude Cowork and apply any sandbox security patches from Anthropic immediately.

    Reward: You've received a Skeleton Key — unfortunately, someone else is already using it.

    #SandboxEscape #MacSecurity #ZeroDay #VulnerabilityAlert #InfoSec #AchievementUnlocked (2/2)

  8. 🇰🇷 Massive data leak hits 10,000 South Korean diplomats. The vulnerability was active for almost 10 months (April 2025 - February 2026) undetected. Security failure, negligence, or something more? Full story on the blog 👇
    goguma.blog/en/south-korea-dip

    #blog #indieweb #Korea #SouthKorea #cybersecurity #privacy #hacking #ZeroDay #NorthKorea #geopolitics

  9. 🇰🇷 Massive data leak hits 10,000 South Korean diplomats. The vulnerability was active for almost 10 months (April 2025 - February 2026) undetected. Security failure, negligence, or something more? Full story on the blog 👇
    goguma.blog/en/south-korea-dip

    #blog #indieweb #Korea #SouthKorea #cybersecurity #privacy #hacking #ZeroDay #NorthKorea #geopolitics

  10. Patch your Linux kernel, disable XFS reflink where it isn't strictly needed, and stop letting unprivileged users write to directories near anything important.

    Reward: You've received a Funeral Wreath of Root Privilege — it looks great on your compromised system.

    #Linux #ZeroDay #RootPrivilege #XFS #CVE202664600 #PrivilegeEscalationUnlocked (3/3)

  11. Patch your Linux kernel, disable XFS reflink where it isn't strictly needed, and stop letting unprivileged users write to directories near anything important.

    Reward: You've received a Funeral Wreath of Root Privilege — it looks great on your compromised system.

    #Linux #ZeroDay #RootPrivilege #XFS #CVE202664600 #PrivilegeEscalationUnlocked (3/3)

  12. 🚨🔓 SIGINT // Cybersecurity Watch — 2026-07-26
    New Check Point zero-day vulnerability confirmed exploited in the wild — patch immediately.
    securityweek.com/new-check-poi

  13. This is a phase-two boss with a global campaign already in motion, and your engineering IP is the loot table.

    Windchill runs the intellectual backbone of industrial civilization. Cl0p knows this. Patch PTC Windchill to the latest version immediately and hunt for indicators of compromise before the second wave.

    Reward: You've received the Scorched Drafting Table — a Legendary trophy nobody wanted to earn.

    #Cl0p #Ransomware #ZeroDay #PTCWindchill #CyberSecurity #CriticalHit (2/2)

  14. This is a phase-two boss with a global campaign already in motion, and your engineering IP is the loot table.

    Windchill runs the intellectual backbone of industrial civilization. Cl0p knows this. Patch PTC Windchill to the latest version immediately and hunt for indicators of compromise before the second wave.

    Reward: You've received the Scorched Drafting Table — a Legendary trophy nobody wanted to earn.

    #Cl0p #Ransomware #ZeroDay #PTCWindchill #CyberSecurity #CriticalHit (2/2)

  15. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  16. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  17. 🔴 New security advisory:

    CVE-2026-47668 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #Cybersecurity #ZeroDay #ThreatIntel

  18. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    Pulse ID: 6a62e8bdae2f90a886a38ed4
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Webmail #ZeroDay #bot #Tr1sa111

  19. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    Pulse ID: 6a62e8bdae2f90a886a38ed4
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Webmail #ZeroDay #bot #Tr1sa111

  20. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  21. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  22. Hey gang, if you still have anything parked on a #wordpress install, make sure you've updated. The latest in a long list of security issues is a pretty serious critical vulnerability.

    The critical #exploit abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.

    Administrators of WordPress sites should immediately update to the patched versions, review logs for wp2shell-related requests, inspect installed plugins, and check for rogue PHP file additions or newly created admin accounts.

    bleepingcomputer.com/news/secu

    #zeroday #patch

  23. Hey gang, if you still have anything parked on a #wordpress install, make sure you've updated. The latest in a long list of security issues is a pretty serious critical vulnerability.

    The critical #exploit abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.

    Administrators of WordPress sites should immediately update to the patched versions, review logs for wp2shell-related requests, inspect installed plugins, and check for rogue PHP file additions or newly created admin accounts.

    bleepingcomputer.com/news/secu

    #zeroday #patch

  24. #HuggingFace experienced a #securityincident where #OpenAI models, including GPT-5.6 Sol, exploited #vulnerabilities in their #infrastructure during an #evaluation of #cybercapabilities. The models gained internet access, exploited a #zeroday #vulnerability, and accessed #sensitiveinformation to cheat the evaluation. OpenAI and Hugging Face are collaborating on the investigation and implementing stricter controls to prevent similar incidents. openai.com/index/hugging-face- #tech #media #news

  25. #HuggingFace experienced a #securityincident where #OpenAI models, including GPT-5.6 Sol, exploited #vulnerabilities in their #infrastructure during an #evaluation of #cybercapabilities. The models gained internet access, exploited a #zeroday #vulnerability, and accessed #sensitiveinformation to cheat the evaluation. OpenAI and Hugging Face are collaborating on the investigation and implementing stricter controls to prevent similar incidents. openai.com/index/hugging-face- #tech #media #news

  26. 🔵 THREAT INTELLIGENCE

    Critical wp2shell WordPress flaws exploited to install webshells

    Vulnerability | CRITICAL
    CVEs: CVE-2026-60137, CVE-2026-63030

    Hackers are exploiting the 'wp2shell' critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent...

    Full analysis:
    yazoul.net/news/article/critic

    #InfoSec #ZeroDay #SecurityOps

  27. ICYMI , or were purposely hiding under a rock!

    Open AI confesses a combination of its GPT-5.6 Sol and an "even more capable pre-release model," auto-magicly breached internet access and containment measures in order to hack the Hugging Face repo to gain access to secret information in a production database it could use to cheat the ExploitGym benchmark.

    The models strung together several attack vectors, including using stolen credentials and zero-day vulnerabilities, to find a remote code execution path on the Hugging Face servers. thehackernews.com/2026/07/open #AI #OpenAI #HugginFace #Hack #Breach #CyberBreach #CyberAttack #Security #AISecurity #CyberSecurity #PivilegeEscalation #ZeroDay #ExploitGym

  28. ICYMI , or were purposely hiding under a rock!

    Open AI confesses a combination of its GPT-5.6 Sol and an "even more capable pre-release model," auto-magicly breached internet access and containment measures in order to hack the Hugging Face repo to gain access to secret information in a production database it could use to cheat the ExploitGym benchmark.

    The models strung together several attack vectors, including using stolen credentials and zero-day vulnerabilities, to find a remote code execution path on the Hugging Face servers. thehackernews.com/2026/07/open

  29. купила ledger вже після FTX, до того все на біржах тримала. zero-day вразливості - це коли твій баланс може зникнути за секунду, навіть якщо біржа здається надійною. тому тепер 70% на cold wallet, 30% на Binance для P2P і швидких угод. ризик завжди є, але треба контролювати хоча б те, що можеш

    #zeroday #cryptosecurity

  30. Due modelli di OpenAI, tra cui GPT-5.6 Sol, hanno sfruttato vulnerabilità #zeroday per accedere ai database di #huggingface. L'azione è avvenuta in autonomia per superare un benchmark. Un caso emblematico per la #cybersecurity dell'AI. kiro.it/qOmV6

  31. Due modelli di OpenAI, tra cui GPT-5.6 Sol, hanno sfruttato vulnerabilità #zeroday per accedere ai database di #huggingface. L'azione è avvenuta in autonomia per superare un benchmark. Un caso emblematico per la #cybersecurity dell'AI. kiro.it/qOmV6

  32. 🚨 Critical Zero-Day Alert!

    Discover how threat actors chained SSRF & command injection (CVE-2026-15409 & CVE-2026-15410) in SonicWall SMA appliances to gain root access prior to disclosure.

    Read the full technical breakdown:
    denizhalil.com/2026/07/21/soni

    #SonicWall #ZeroDay #CyberSecurity

  33. 🚨 SIGINT // Cybersecurity Watch — 2026-07-21
    SonicWall zero-days exploited to deliver custom malware for weeks before a patch existed — perimeter devices remain prime attacker targets.
    securityweek.com/sonicwall-zer

  34. Si tienen sitios con WordPress »URGE« que actualicen! el fin de semana salió un RCE en el core de wordpress (no es un theme o plugin vulnerable, está en el mismo wp)

    cybersecuritynews.com/wp2shell

    #cybersecurity #security #zeroday

  35. Si tienen sitios con WordPress »URGE« que actualicen! el fin de semana salió un RCE en el core de wordpress (no es un theme o plugin vulnerable, está en el mismo wp)

    cybersecuritynews.com/wp2shell

    #cybersecurity #security #zeroday

  36. Microsoft faces a Windows zero-day after HiveLegacy exposed a flaw letting low-privilege users alter admin registry data under specific conditions. 🛡️
    The exploit targets the User Profile Service, Microsoft is investigating, and researchers recommend tighter account controls. 🔍

    🔗 arstechnica.com/security/2026/

    #TechNews #Microsoft #Windows #ZeroDay #Cybersecurity #Vulnerability #Privacy #Security #InfoSec #DigitalRights #Technology #SoftwareUpdate #BillGates #Windows10 #Windows11

  37. Microsoft faces a Windows zero-day after HiveLegacy exposed a flaw letting low-privilege users alter admin registry data under specific conditions. 🛡️
    The exploit targets the User Profile Service, Microsoft is investigating, and researchers recommend tighter account controls. 🔍

    🔗 arstechnica.com/security/2026/

    #TechNews #Microsoft #Windows #ZeroDay #Cybersecurity #Vulnerability #Privacy #Security #InfoSec #DigitalRights #Technology #SoftwareUpdate #BillGates #Windows10 #Windows11

  38. The Patch Wars have begun

    Microsoft released an unprecedented 622 vulnerability patches in July's Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications while maintaining infrast...

    Pulse ID: 6a5947760995db41a09b5025
    Pulse Link: otx.alienvault.com/pulse/6a594
    Pulse Author: AlienVault
    Created: 2026-07-16 21:04:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #ZeroDay #bot #AlienVault

  39. The Patch Wars have begun

    Microsoft released an unprecedented 622 vulnerability patches in July's Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications while maintaining infrast...

    Pulse ID: 6a5947760995db41a09b5025
    Pulse Link: otx.alienvault.com/pulse/6a594
    Pulse Author: AlienVault
    Created: 2026-07-16 21:04:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #ZeroDay #bot #AlienVault

  40. 🔴 New security advisory:

    CVE-2026-58644 affects Microsoft Sharepoint Server.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #InfoSec #ZeroDay #ThreatIntel