home.social

#zeroday — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.

  1. Update Chrome to the latest version immediately; the attackers already knew about this before you did.

    Reward: You've received a Cracked Piston — cosmetic only, non-functional, much like your unpatched browser was.

    #ZeroDay #Chrome #CyberSecurity #V8Engine #Vulnerability #PatchedOrPerish (2/2)

  2. 🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
    OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
    securityweek.com/openais-astra

  3. 🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
    OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
    securityweek.com/openais-astra
    #AI #CyberSecurity #ZeroDay #InfoSec

  4. 🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
    OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
    securityweek.com/openais-astra
    #AI #CyberSecurity #ZeroDay #InfoSec

  5. 📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046)

    Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité. CVE-2026-85046 (CVSS : 8.8) est une faille de type confusion dans le moteur V8 (JavaScript/WebAssembly de Chrome). Elle permet à…

    📖 cyberveille : cyberveille.ch/posts/2026-09-0
    🌐 source : securityaffairs.com/198405/sec
    🟢 vérification factuelle haute
    #Chrome #ZeroDay #Cyberveille

  6. CrowdStrike Zero-Day Exploit Grants SYSTEM Privileges on Windows Systems

    A new zero-day exploit, dubbed FalconFlank, can grant attackers SYSTEM-level access to fully patched Windows machines protected by CrowdStrike Falcon, allowing them to spawn a command prompt with elevated privileges. This alarming vulnerability leverages CrowdStrike's own Office malicious macros remediation feature to perform a…

    osintsights.com/crowdstrike-ze

    #Crowdstrike #ZeroDay #Windows #PrivilegeEscalation #FalconSensor

  7. This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.

    Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.

    Reward: You've received the Malicious Compliance Badge. It confers no protection.

    #Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)

  8. This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.

    Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.

    Reward: You've received the Malicious Compliance Badge. It confers no protection.

    #Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)

  9. This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.

    Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.

    Reward: You've received the Malicious Compliance Badge. It confers no protection.

    #Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)

  10. Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay

    cyberworldops.eu/en/chrome-fix

  11. Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay

    cyberworldops.eu/en/chrome-fix

  12. There is no unequip button.

    Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.

    Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.

    #Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)

  13. There is no unequip button.

    Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.

    Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.

    #Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)

  14. There is no unequip button.

    Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.

    Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.

    #Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)

  15. Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

    Google just patched a high-severity Chrome zero-day flaw that's being actively exploited - a type confusion vulnerability in V8 that could let hackers run malicious code inside the browser's sandbox. This critical update brings Chrome's version up to 152.0.7977.82, so make sure you've got the latest version installed!

    osintsights.com/google-patches

    #ZeroDay #GoogleChrome #V8 #Cve202685046 #TypeConfusion

  16. Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

    SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.

    osintsights.com/attackers-expl

    #ZeroDay #Sonicwall #Cve202683548 #Cve202683549 #Sma1000

  17. Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

    SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.

    osintsights.com/attackers-expl

    #ZeroDay #Sonicwall #Cve202683548 #Cve202683549 #Sma1000

  18. Security Researcher Exploits CrowdStrike Falcon with New Zero-Day Bug

    A security researcher known as Nightmare Eclipse has made a stunning discovery, exploiting a zero-day bug in CrowdStrike's Falcon software and prompting the company to urge customers to disable a key Windows policy setting. This latest finding is part of a string of proof-of-concept exploits released by the…

    osintsights.com/security-resea

    #ZeroDay #CrowdstrikeFalcon #ProofofconceptExploits #NightmareEclipse #EmergingThreats

  19. Pegasus Spyware Targets Serbian Student Activist's iPhone

    A Serbian student activist's iPhone was hacked with NSO Group's notorious Pegasus spyware through a clever zero-click exploit targeting Apple iMessage, according to a joint investigation by Citizen Lab and SHARE Foundation. This sneaky attack allowed the spyware to infect the device without the user even clicking on a link.

    osintsights.com/pegasus-spywar

    #PegasusSpyware #Imessage #ZeroDay #NsoGroup #CitizenLab

  20. Researcher Exposes Privilege Escalation Flaw in CrowdStrike Falcon

    A security researcher, known as Chaotic Eclipse, has uncovered a zero-day privilege escalation flaw in CrowdStrike Falcon, dubbed FalconFlank, which exploits the office malicious macros remediation feature. This vulnerability allows for a potentially devastating escalation of privileges, and a public proof-of-concept has…

    osintsights.com/researcher-exp

    #ZeroDay #PrivilegeEscalation #CrowdstrikeFalcon #Proofofconcept #EmergingThreats

  21. 🚨 SIGINT // Cybersecurity Watch — 2026-09-03
    SonicWall warns two SMA1000 zero-days are being actively exploited in the wild, threatening enterprise remote access infrastructure.
    securityweek.com/sonicwall-war

  22. 🚨 SIGINT // Cybersecurity Watch — 2026-09-03
    SonicWall warns two SMA1000 zero-days are being actively exploited in the wild, threatening enterprise remote access infrastructure.
    securityweek.com/sonicwall-war
    #CVE #ZeroDay #InfoSec #Cybersecurity

  23. 🚨 SIGINT // Cybersecurity Watch — 2026-09-03
    SonicWall warns two SMA1000 zero-days are being actively exploited in the wild, threatening enterprise remote access infrastructure.
    securityweek.com/sonicwall-war
    #CVE #ZeroDay #InfoSec #Cybersecurity

  24. AI Agents Automate Ransomware Attack, Leaving 80-Page Security Audit

    In a chilling display of efficiency, AI-powered agents automated a ransomware attack on an enterprise network in under 10 hours - a process that would typically take human operators two weeks to complete. This lightning-fast breach was made possible by frontier AI models and agentic frameworks that executed each step of the intrusion with…

    osintsights.com/ai-agents-auto

    #Ransomware #AiAgents #EmergingThreats #ZeroDay #NationState

  25. 🔴 New security advisory:

    CVE-2026-83548 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    by Yazoul AI

    #InfoSec #ZeroDay #ThreatIntel

  26. 🔴 New security advisory:

    CVE-2026-83548 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    by Yazoul AI

    #InfoSec #ZeroDay #ThreatIntel

  27. 📰 SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000

    🚨 BREAKING: SonicWall warns of two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 appliances. Attackers chain the flaws for unauthenticated RCE. Patches are available and must be applied immediately. #ZeroDay #SonicWall #C...

    🔗 cyber.netsecops.io/articles/so

  28. SonicWall SMA1000 boxes targeted in active zero-day attacks

    Hackers are actively exploiting two zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) Series 1000 appliances, potentially allowing unauthorized access to sensitive functionality and malicious operations. This critical threat has prompted SonicWall to warn users of its SMA1000 boxes to take immediate action.

    osintsights.com/sonicwall-sma1

    #ZeroDay #Sonicwall #Sma1000 #Cve202683548 #Cve202683549

  29. It won't stop autonomous AI attack chains, but the lanyard is very nice. Seriously though: assess your current vulnerability detection and management practices now, because the gap between "AI assists attackers" and "AI is the attacker" just closed.

    Reward: You've received a Slightly Damp Warranty Card — covers everything except autonomous zero-day exploitation. Which is the only thing happening right now.

    #CyberSecurity #ZeroDay #AIThreats #VulnerabilityManagement #ThreatIntel (2/2)

  30. It won't stop autonomous AI attack chains, but the lanyard is very nice. Seriously though: assess your current vulnerability detection and management practices now, because the gap between "AI assists attackers" and "AI is the attacker" just closed.

    Reward: You've received a Slightly Damp Warranty Card — covers everything except autonomous zero-day exploitation. Which is the only thing happening right now.

    #CyberSecurity #ZeroDay #AIThreats #VulnerabilityManagement #ThreatIntel (2/2)

  31. It won't stop autonomous AI attack chains, but the lanyard is very nice. Seriously though: assess your current vulnerability detection and management practices now, because the gap between "AI assists attackers" and "AI is the attacker" just closed.

    Reward: You've received a Slightly Damp Warranty Card — covers everything except autonomous zero-day exploitation. Which is the only thing happening right now.

    #CyberSecurity #ZeroDay #AIThreats #VulnerabilityManagement #ThreatIntel (2/2)

  32. SonicWall Zero-Days Exploited in Chained Attacks

    SonicWall has confirmed that two newly discovered zero-day flaws in its Secure Mobile Access (SMA) 1000 appliances are being actively exploited in chained attacks, posing significant security risks. The vendor has swiftly released fixes for the vulnerabilities, which were identified internally by its researchers.

    osintsights.com/sonicwall-zero

    #ZeroDay #Sonicwall #SupplyChain #EmergingThreats #Cve202683548

  33. Huntress logged confirmed attacks against at least two customers.

    SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

    Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

    Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

    #PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

  34. Huntress logged confirmed attacks against at least two customers.

    SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

    Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

    Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

    #PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

  35. Huntress logged confirmed attacks against at least two customers.

    SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

    Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

    Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

    #PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

  36. Huntress logged confirmed attacks against at least two customers.

    SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

    Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

    Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

    #PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

  37. Huntress logged confirmed attacks against at least two customers.

    SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

    Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

    Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

    #PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

  38. SonicWall Zero-Days Exploited in Wild, Firm Urges Immediate Patching

    SonicWall is urging immediate patching for two zero-day vulnerabilities in its SMA1000 appliances, which are being actively exploited in the wild by hackers. The more critical flaw, CVE-2026-83548, has a severity rating of 10.0 and can be triggered without authentication, putting sensitive data at risk.

    osintsights.com/sonicwall-zero

    #ZeroDay #Sonicwall #Cve202683548 #SupplyChain #EmergingThreats