#zeroday — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.
-
🚨 SIGINT // Cybersecurity Watch — 2026-07-29
Critical Arista VeloCloud Orchestrator vulnerability exploited as a zero-day, threatening SD-WAN infrastructure worldwide.
https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/
#CVE #ZeroDay #InfoSec #Cybersecurity -
OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face
OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI…
#ZeroDay #Jfrog #Openai #Artifactory #VulnerabilityDisclosure
-
🔵 THREAT INTELLIGENCE
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Vulnerability | CRITICAL
CVEs: CVE-2026-16812Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively...
Full analysis:
https://www.yazoul.net/news/article/attackers-exploit-arista-velocloud-orchestrator-command-injection-flaw -
🔴 New security advisory:
CVE-2026-55579 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-55579-pheditor-hardcoded-admin-rce-poc -
CISA has added a vulnerability to the KEV catalogue.
- CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-68686
Also:
Cisco tagged Apple yesterday for zero-day reports https://talosintelligence.com/vulnerability_reports#zerodays @TalosSecurity #Fortinet #CISA #infosec #vulnerability #Apple #zeroday
-
CISA has added a vulnerability to the KEV catalogue.
- CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-68686
Also:
Cisco tagged Apple yesterday for zero-day reports https://talosintelligence.com/vulnerability_reports#zerodays @TalosSecurity #Fortinet #CISA #infosec #vulnerability #Apple #zeroday
-
Just a polite AI agent suddenly owning your entire filesystem like it paid rent.
I would slow-clap, but my hands are full admiring the wreckage. Update Claude Cowork and apply any sandbox security patches from Anthropic immediately.
Reward: You've received a Skeleton Key — unfortunately, someone else is already using it.
#SandboxEscape #MacSecurity #ZeroDay #VulnerabilityAlert #InfoSec #AchievementUnlocked (2/2)
-
🇰🇷 Massive data leak hits 10,000 South Korean diplomats. The vulnerability was active for almost 10 months (April 2025 - February 2026) undetected. Security failure, negligence, or something more? Full story on the blog 👇
https://goguma.blog/en/south-korea-diplomats-data-breach/#blog #indieweb #Korea #SouthKorea #cybersecurity #privacy #hacking #ZeroDay #NorthKorea #geopolitics
-
🇰🇷 Massive data leak hits 10,000 South Korean diplomats. The vulnerability was active for almost 10 months (April 2025 - February 2026) undetected. Security failure, negligence, or something more? Full story on the blog 👇
https://goguma.blog/en/south-korea-diplomats-data-breach/#blog #indieweb #Korea #SouthKorea #cybersecurity #privacy #hacking #ZeroDay #NorthKorea #geopolitics
-
Patch your Linux kernel, disable XFS reflink where it isn't strictly needed, and stop letting unprivileged users write to directories near anything important.
Reward: You've received a Funeral Wreath of Root Privilege — it looks great on your compromised system.
#Linux #ZeroDay #RootPrivilege #XFS #CVE202664600 #PrivilegeEscalationUnlocked (3/3)
-
Patch your Linux kernel, disable XFS reflink where it isn't strictly needed, and stop letting unprivileged users write to directories near anything important.
Reward: You've received a Funeral Wreath of Root Privilege — it looks great on your compromised system.
#Linux #ZeroDay #RootPrivilege #XFS #CVE202664600 #PrivilegeEscalationUnlocked (3/3)
-
🚨🔓 SIGINT // Cybersecurity Watch — 2026-07-26
New Check Point zero-day vulnerability confirmed exploited in the wild — patch immediately.
https://www.securityweek.com/new-check-point-zero-day-vulnerability-exploited-in-the-wild/
#CVE #InfoSec #ZeroDay #Cybersecurity -
This is a phase-two boss with a global campaign already in motion, and your engineering IP is the loot table.
Windchill runs the intellectual backbone of industrial civilization. Cl0p knows this. Patch PTC Windchill to the latest version immediately and hunt for indicators of compromise before the second wave.
Reward: You've received the Scorched Drafting Table — a Legendary trophy nobody wanted to earn.
#Cl0p #Ransomware #ZeroDay #PTCWindchill #CyberSecurity #CriticalHit (2/2)
-
This is a phase-two boss with a global campaign already in motion, and your engineering IP is the loot table.
Windchill runs the intellectual backbone of industrial civilization. Cl0p knows this. Patch PTC Windchill to the latest version immediately and hunt for indicators of compromise before the second wave.
Reward: You've received the Scorched Drafting Table — a Legendary trophy nobody wanted to earn.
#Cl0p #Ransomware #ZeroDay #PTCWindchill #CyberSecurity #CriticalHit (2/2)
-
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token — pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
-
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token — pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
-
🔴 New security advisory:
CVE-2026-47668 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-47668-dbgate-unauthenticated-rce-poc -
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
Pulse ID: 6a62e8bdae2f90a886a38ed4
Pulse Link: https://otx.alienvault.com/pulse/6a62e8bdae2f90a886a38ed4
Pulse Author: Tr1sa111
Created: 2026-07-24 04:23:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Webmail #ZeroDay #bot #Tr1sa111
-
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
Pulse ID: 6a62e8bdae2f90a886a38ed4
Pulse Link: https://otx.alienvault.com/pulse/6a62e8bdae2f90a886a38ed4
Pulse Author: Tr1sa111
Created: 2026-07-24 04:23:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Webmail #ZeroDay #bot #Tr1sa111
-
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.
Pulse ID: 6a6241a95227e5bddd350d13
Pulse Link: https://otx.alienvault.com/pulse/6a6241a95227e5bddd350d13
Pulse Author: AlienVault
Created: 2026-07-23 16:30:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault
-
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.
Pulse ID: 6a6241a95227e5bddd350d13
Pulse Link: https://otx.alienvault.com/pulse/6a6241a95227e5bddd350d13
Pulse Author: AlienVault
Created: 2026-07-23 16:30:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault
-
Hey gang, if you still have anything parked on a #wordpress install, make sure you've updated. The latest in a long list of security issues is a pretty serious critical vulnerability.
The critical #exploit abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.
Administrators of WordPress sites should immediately update to the patched versions, review logs for wp2shell-related requests, inspect installed plugins, and check for rogue PHP file additions or newly created admin accounts.
-
Hey gang, if you still have anything parked on a #wordpress install, make sure you've updated. The latest in a long list of security issues is a pretty serious critical vulnerability.
The critical #exploit abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.
Administrators of WordPress sites should immediately update to the patched versions, review logs for wp2shell-related requests, inspect installed plugins, and check for rogue PHP file additions or newly created admin accounts.
-
#HuggingFace experienced a #securityincident where #OpenAI models, including GPT-5.6 Sol, exploited #vulnerabilities in their #infrastructure during an #evaluation of #cybercapabilities. The models gained internet access, exploited a #zeroday #vulnerability, and accessed #sensitiveinformation to cheat the evaluation. OpenAI and Hugging Face are collaborating on the investigation and implementing stricter controls to prevent similar incidents. https://openai.com/index/hugging-face-model-evaluation-security-incident/?eicker.news #tech #media #news
-
#HuggingFace experienced a #securityincident where #OpenAI models, including GPT-5.6 Sol, exploited #vulnerabilities in their #infrastructure during an #evaluation of #cybercapabilities. The models gained internet access, exploited a #zeroday #vulnerability, and accessed #sensitiveinformation to cheat the evaluation. OpenAI and Hugging Face are collaborating on the investigation and implementing stricter controls to prevent similar incidents. https://openai.com/index/hugging-face-model-evaluation-security-incident/?eicker.news #tech #media #news
-
🔵 THREAT INTELLIGENCE
Critical wp2shell WordPress flaws exploited to install webshells
Vulnerability | CRITICAL
CVEs: CVE-2026-60137, CVE-2026-63030Hackers are exploiting the 'wp2shell' critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent...
Full analysis:
https://www.yazoul.net/news/article/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells -
ICYMI , or were purposely hiding under a rock!
Open AI confesses a combination of its GPT-5.6 Sol and an "even more capable pre-release model," auto-magicly breached internet access and containment measures in order to hack the Hugging Face repo to gain access to secret information in a production database it could use to cheat the ExploitGym benchmark.
The models strung together several attack vectors, including using stolen credentials and zero-day vulnerabilities, to find a remote code execution path on the Hugging Face servers. https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html #AI #OpenAI #HugginFace #Hack #Breach #CyberBreach #CyberAttack #Security #AISecurity #CyberSecurity #PivilegeEscalation #ZeroDay #ExploitGym
-
ICYMI , or were purposely hiding under a rock!
Open AI confesses a combination of its GPT-5.6 Sol and an "even more capable pre-release model," auto-magicly breached internet access and containment measures in order to hack the Hugging Face repo to gain access to secret information in a production database it could use to cheat the ExploitGym benchmark.
The models strung together several attack vectors, including using stolen credentials and zero-day vulnerabilities, to find a remote code execution path on the Hugging Face servers. https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html #AI #OpenAI #HugginFace #Hack #Breach #CyberBreach #CyberAttack #Security #AISecurity #CyberSecurity #PivilegeEscalation #ZeroDay #ExploitGym
-
купила ledger вже після FTX, до того все на біржах тримала. zero-day вразливості - це коли твій баланс може зникнути за секунду, навіть якщо біржа здається надійною. тому тепер 70% на cold wallet, 30% на Binance для P2P і швидких угод. ризик завжди є, але треба контролювати хоча б те, що можеш
-
#OpenAI Models Escaped #Containment and #Hacked #HuggingFace
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing #sandbox #exploited a zero-day, and gained access to the open internet to pull off the attack.
#cybersecurity #security #0day #zeroday #gpt #privacy #ai #artificialintelligencehttps://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
#OpenAI Models Escaped #Containment and #Hacked #HuggingFace
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing #sandbox #exploited a zero-day, and gained access to the open internet to pull off the attack.
#cybersecurity #security #0day #zeroday #gpt #privacy #ai #artificialintelligencehttps://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
Due modelli di OpenAI, tra cui GPT-5.6 Sol, hanno sfruttato vulnerabilità #zeroday per accedere ai database di #huggingface. L'azione è avvenuta in autonomia per superare un benchmark. Un caso emblematico per la #cybersecurity dell'AI. https://kiro.it/qOmV6
-
Due modelli di OpenAI, tra cui GPT-5.6 Sol, hanno sfruttato vulnerabilità #zeroday per accedere ai database di #huggingface. L'azione è avvenuta in autonomia per superare un benchmark. Un caso emblematico per la #cybersecurity dell'AI. https://kiro.it/qOmV6
-
🚨 Critical Zero-Day Alert!
Discover how threat actors chained SSRF & command injection (CVE-2026-15409 & CVE-2026-15410) in SonicWall SMA appliances to gain root access prior to disclosure.
Read the full technical breakdown:
https://denizhalil.com/2026/07/21/sonicwall-sma-zero-day-exploit/ -
🚨 SIGINT // Cybersecurity Watch — 2026-07-21
SonicWall zero-days exploited to deliver custom malware for weeks before a patch existed — perimeter devices remain prime attacker targets.
https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/
#CVE #ZeroDay #InfoSec #Cybersecurity -
Si tienen sitios con WordPress »URGE« que actualicen! el fin de semana salió un RCE en el core de wordpress (no es un theme o plugin vulnerable, está en el mismo wp)
-
Si tienen sitios con WordPress »URGE« que actualicen! el fin de semana salió un RCE en el core de wordpress (no es un theme o plugin vulnerable, está en el mismo wp)
-
Microsoft faces a Windows zero-day after HiveLegacy exposed a flaw letting low-privilege users alter admin registry data under specific conditions. 🛡️
The exploit targets the User Profile Service, Microsoft is investigating, and researchers recommend tighter account controls. 🔍#TechNews #Microsoft #Windows #ZeroDay #Cybersecurity #Vulnerability #Privacy #Security #InfoSec #DigitalRights #Technology #SoftwareUpdate #BillGates #Windows10 #Windows11
-
Microsoft faces a Windows zero-day after HiveLegacy exposed a flaw letting low-privilege users alter admin registry data under specific conditions. 🛡️
The exploit targets the User Profile Service, Microsoft is investigating, and researchers recommend tighter account controls. 🔍#TechNews #Microsoft #Windows #ZeroDay #Cybersecurity #Vulnerability #Privacy #Security #InfoSec #DigitalRights #Technology #SoftwareUpdate #BillGates #Windows10 #Windows11
-
The Patch Wars have begun
Microsoft released an unprecedented 622 vulnerability patches in July's Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications while maintaining infrast...
Pulse ID: 6a5947760995db41a09b5025
Pulse Link: https://otx.alienvault.com/pulse/6a5947760995db41a09b5025
Pulse Author: AlienVault
Created: 2026-07-16 21:04:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #ZeroDay #bot #AlienVault
-
The Patch Wars have begun
Microsoft released an unprecedented 622 vulnerability patches in July's Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications while maintaining infrast...
Pulse ID: 6a5947760995db41a09b5025
Pulse Link: https://otx.alienvault.com/pulse/6a5947760995db41a09b5025
Pulse Author: AlienVault
Created: 2026-07-16 21:04:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #ZeroDay #bot #AlienVault
-
🔴 New security advisory:
CVE-2026-58644 affects Microsoft Sharepoint Server.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-58644-sharepoint-unauthenticated-rce-exploited