home.social

#zeroday — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.

fetched live
  1. Your healers cannot save you. Restrict access to GeoServer admin interfaces NOW and watch those patch feeds like your raid lead is screaming in your ear — because they should be.

    Reward: You've received the Unplanned Downtime Debuff. It stacks.

    #ZeroDay #GeoServer #RCE #CyberSecurity #Vulnerability #AchievementUnlocked (2/2)

  2. Your healers cannot save you. Restrict access to GeoServer admin interfaces NOW and watch those patch feeds like your raid lead is screaming in your ear — because they should be.

    Reward: You've received the Unplanned Downtime Debuff. It stacks.

    #ZeroDay #GeoServer #RCE #CyberSecurity #Vulnerability #AchievementUnlocked (2/2)

  3. Your healers cannot save you. Restrict access to GeoServer admin interfaces NOW and watch those patch feeds like your raid lead is screaming in your ear — because they should be.

    Reward: You've received the Unplanned Downtime Debuff. It stacks.

    #ZeroDay #GeoServer #RCE #CyberSecurity #Vulnerability #AchievementUnlocked (2/2)

  4. 🤖 Zhipu says new coding AI developed advanced cyber skills faster than expected

    📝 Chinese AI developer Zhipu has launched GLM-5. 3, ...

    csoonline.com/article/4210501/

    📰 CSO Online

    #AI #ZeroDay

  5. 🤖 Zhipu says new coding AI developed advanced cyber skills faster than expected

    📝 Chinese AI developer Zhipu has launched GLM-5. 3, ...

    csoonline.com/article/4210501/

    📰 CSO Online

    #AI #ZeroDay

  6. 🤖 An AI broke Snowflake's code. Then another AI agent exploited it

    📝 An AI broke Snowflake’s code; then another AI, an a...

    theregister.com/security/2026/

    📰 www.theregister.com - Articles

    #AI #ZeroDay

  7. 🤖 An AI broke Snowflake's code. Then another AI agent exploited it

    📝 An AI broke Snowflake’s code; then another AI, an a...

    theregister.com/security/2026/

    📰 www.theregister.com - Articles

    #AI #ZeroDay

  8. 🏛️ CISA Adds One Known Exploited Vulnerability to Catalog

    📝 CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog ,...

    cisa.gov/news-events/alerts/20

    📰 Alerts

    #GovSec #CVE #ZeroDay

  9. 🏛️ CISA Adds One Known Exploited Vulnerability to Catalog

    📝 CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog ,...

    cisa.gov/news-events/alerts/20

    📰 Alerts

    #GovSec #CVE #ZeroDay

  10. 📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch

    A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...

    🔗 cyber.netsecops.io/articles/sh

  11. That is a passing grade for them and a failing grade for you.

    This concludes the practical exam portion of your training. Results have been distributed to your files, your encrypted files, and 46 other countries' encrypted files. Please apply the latest VMware vCenter patch and audit your access logs for unauthorized root activity immediately.

    Reward: You've received a Mandatory Remediation Training Badge. It is not a good badge.

    #Ransomware #VMware #APT #CyberSecurity #ZeroDay (2/2)

  12. That is a passing grade for them and a failing grade for you.

    This concludes the practical exam portion of your training. Results have been distributed to your files, your encrypted files, and 46 other countries' encrypted files. Please apply the latest VMware vCenter patch and audit your access logs for unauthorized root activity immediately.

    Reward: You've received a Mandatory Remediation Training Badge. It is not a good badge.

    #Ransomware #VMware #APT #CyberSecurity #ZeroDay (2/2)

  13. That is a passing grade for them and a failing grade for you.

    This concludes the practical exam portion of your training. Results have been distributed to your files, your encrypted files, and 46 other countries' encrypted files. Please apply the latest VMware vCenter patch and audit your access logs for unauthorized root activity immediately.

    Reward: You've received a Mandatory Remediation Training Badge. It is not a good badge.

    #Ransomware #VMware #APT #CyberSecurity #ZeroDay (2/2)

  14. Apple Alerts 110 Countries to Mercenary Spyware Threats

    Apple just sounded the alarm for users in 110 countries, warning them they've been targeted by highly sophisticated mercenary spyware attacks that are among the most advanced digital threats out there. This latest alert is part of a multi-year effort to protect users, with notifications now sent to customers in over 150 countries.

    osintsights.com/apple-alerts-1

    #MercenarySpyware #EmergingThreats #Apple #ZeroDay #NationState

  15. Apple Alerts 110 Countries to Mercenary Spyware Threats

    Apple just sounded the alarm for users in 110 countries, warning them they've been targeted by highly sophisticated mercenary spyware attacks that are among the most advanced digital threats out there. This latest alert is part of a multi-year effort to protect users, with notifications now sent to customers in over 150 countries.

    osintsights.com/apple-alerts-1

    #MercenarySpyware #EmergingThreats #Apple #ZeroDay #NationState

  16. Apple Alerts 110 Countries to Mercenary Spyware Threats

    Apple just sounded the alarm for users in 110 countries, warning them they've been targeted by highly sophisticated mercenary spyware attacks that are among the most advanced digital threats out there. This latest alert is part of a multi-year effort to protect users, with notifications now sent to customers in over 150 countries.

    osintsights.com/apple-alerts-1

    #MercenarySpyware #EmergingThreats #Apple #ZeroDay #NationState

  17. Apple Alerts 110 Countries to Mercenary Spyware Threats

    Apple just sounded the alarm for users in 110 countries, warning them they've been targeted by highly sophisticated mercenary spyware attacks that are among the most advanced digital threats out there. This latest alert is part of a multi-year effort to protect users, with notifications now sent to customers in over 150 countries.

    osintsights.com/apple-alerts-1

    #MercenarySpyware #EmergingThreats #Apple #ZeroDay #NationState

  18. Microsoft is "racing to patch," which is a fun phrase that means the patch is not ready.

    Patch Microsoft Defender and the Malware Protection Engine the moment that update drops — do not wait.

    Reward: You've unlocked the Cursed Irony Badge. It does not stack with Defender.

    #ZeroDay #Microsoft #Ransomware #CyberSecurity #InfoSec #PatchedOrPerish (2/2)

  19. Microsoft is "racing to patch," which is a fun phrase that means the patch is not ready.

    Patch Microsoft Defender and the Malware Protection Engine the moment that update drops — do not wait.

    Reward: You've unlocked the Cursed Irony Badge. It does not stack with Defender.

    #ZeroDay #Microsoft #Ransomware #CyberSecurity #InfoSec #PatchedOrPerish (2/2)

  20. Microsoft is "racing to patch," which is a fun phrase that means the patch is not ready.

    Patch Microsoft Defender and the Malware Protection Engine the moment that update drops — do not wait.

    Reward: You've unlocked the Cursed Irony Badge. It does not stack with Defender.

    #ZeroDay #Microsoft #Ransomware #CyberSecurity #InfoSec #PatchedOrPerish (2/2)

  21. You, the defendant, operated an unpatched instance. The prosecution rests.

    Remote code execution is the damages sought. The verdict was rendered before you even knew the case was filed. Please patch GeoServer immediately and monitor for exploitation attempts; ignorance is not, as your counsel may have hoped, a defense.

    Reward: You've received a subpoena-shaped loot token. It is not redeemable for anything.

    #CyberSecurity #ZeroDay #GeoServer #SQLInjection #RCE #PatchedOrPerish (2/2)

  22. You, the defendant, operated an unpatched instance. The prosecution rests.

    Remote code execution is the damages sought. The verdict was rendered before you even knew the case was filed. Please patch GeoServer immediately and monitor for exploitation attempts; ignorance is not, as your counsel may have hoped, a defense.

    Reward: You've received a subpoena-shaped loot token. It is not redeemable for anything.

    #CyberSecurity #ZeroDay #GeoServer #SQLInjection #RCE #PatchedOrPerish (2/2)

  23. You, the defendant, operated an unpatched instance. The prosecution rests.

    Remote code execution is the damages sought. The verdict was rendered before you even knew the case was filed. Please patch GeoServer immediately and monitor for exploitation attempts; ignorance is not, as your counsel may have hoped, a defense.

    Reward: You've received a subpoena-shaped loot token. It is not redeemable for anything.

    #CyberSecurity #ZeroDay #GeoServer #SQLInjection #RCE #PatchedOrPerish (2/2)

  24. Outcome: yours.

    This is fine. Everything is fine. Apply the August 2026 Patch Tuesday update to Windows immediately — especially afd.sys — before that exploited privilege escalation becomes your problem personally.

    Reward: You've received 751 To-Do Items and a motivational poster that says "Ship It."

    #PatchTuesday #Windows #CyberSecurity #Ransomware #ZeroDay #PatchedOrPerish (2/2)

  25. Outcome: yours.

    This is fine. Everything is fine. Apply the August 2026 Patch Tuesday update to Windows immediately — especially afd.sys — before that exploited privilege escalation becomes your problem personally.

    Reward: You've received 751 To-Do Items and a motivational poster that says "Ship It."

    #PatchTuesday #Windows #CyberSecurity #Ransomware #ZeroDay #PatchedOrPerish (2/2)

  26. Outcome: yours.

    This is fine. Everything is fine. Apply the August 2026 Patch Tuesday update to Windows immediately — especially afd.sys — before that exploited privilege escalation becomes your problem personally.

    Reward: You've received 751 To-Do Items and a motivational poster that says "Ship It."

    #PatchTuesday #Windows #CyberSecurity #Ransomware #ZeroDay #PatchedOrPerish (2/2)

  27. Multiple confirmed kills already reported.

    The creature had every tool for survival and chose not to use them. Naturalists are baffled, though not surprised.

    To avoid becoming a specimen: disable screen sharing when not in use, and ensure port 5900 is never reachable from the internet.

    Reward: You've received a commemorative Dodo Feather — awarded for preventable extinctions.

    #MacOS #Vulnerability #ZeroDay #RemoteCodeExecution #CyberSecurity #PatchedOrPerish (2/2)

  28. Multiple confirmed kills already reported.

    The creature had every tool for survival and chose not to use them. Naturalists are baffled, though not surprised.

    To avoid becoming a specimen: disable screen sharing when not in use, and ensure port 5900 is never reachable from the internet.

    Reward: You've received a commemorative Dodo Feather — awarded for preventable extinctions.

    #MacOS #Vulnerability #ZeroDay #RemoteCodeExecution #CyberSecurity #PatchedOrPerish (2/2)

  29. Multiple confirmed kills already reported.

    The creature had every tool for survival and chose not to use them. Naturalists are baffled, though not surprised.

    To avoid becoming a specimen: disable screen sharing when not in use, and ensure port 5900 is never reachable from the internet.

    Reward: You've received a commemorative Dodo Feather — awarded for preventable extinctions.

    #MacOS #Vulnerability #ZeroDay #RemoteCodeExecution #CyberSecurity #PatchedOrPerish (2/2)

  30. Reward: You've received the Unpatched Enterprise World First (Fail) title. It does not look good in the achievement showcase.

    #SAP #CyberSecurity #ZeroDay #CodeInjection #CriticalVulnerability #PatchedOrPerish (3/3)

  31. Reward: You've received the Unpatched Enterprise World First (Fail) title. It does not look good in the achievement showcase.

    #SAP #CyberSecurity #ZeroDay #CodeInjection #CriticalVulnerability #PatchedOrPerish (3/3)

  32. Reward: You've received the Unpatched Enterprise World First (Fail) title. It does not look good in the achievement showcase.

    #SAP #CyberSecurity #ZeroDay #CodeInjection #CriticalVulnerability #PatchedOrPerish (3/3)

  33. 🏛️ Autonomous AI attacks pose 'clear and present danger' to critical infrastructure

    📝 In early July, att...

    theregister.com/security/2026/

    📰 www.theregister.com - Articles

    #AI #ZeroDay

  34. watchTowr filed this report; CISA's Known Exploited Vulnerabilities catalog already has prior GeoServer entries, making this less a surprise and more a recurring line item.

    Audit action required: locate exposed GeoServer instances, restrict public access, and watch for a vendor patch before the exploitation scales up.

    Reward: One (1) Cursed Exposure Token. Cannot be discarded. Weight: infinite.

    #ZeroDay #GeoServer #RCE #SQLInjection #CyberSecurity #PatchedOrPerish (2/2)

  35. watchTowr filed this report; CISA's Known Exploited Vulnerabilities catalog already has prior GeoServer entries, making this less a surprise and more a recurring line item.

    Audit action required: locate exposed GeoServer instances, restrict public access, and watch for a vendor patch before the exploitation scales up.

    Reward: One (1) Cursed Exposure Token. Cannot be discarded. Weight: infinite.

    #ZeroDay #GeoServer #RCE #SQLInjection #CyberSecurity #PatchedOrPerish (2/2)

  36. watchTowr filed this report; CISA's Known Exploited Vulnerabilities catalog already has prior GeoServer entries, making this less a surprise and more a recurring line item.

    Audit action required: locate exposed GeoServer instances, restrict public access, and watch for a vendor patch before the exploitation scales up.

    Reward: One (1) Cursed Exposure Token. Cannot be discarded. Weight: infinite.

    #ZeroDay #GeoServer #RCE #SQLInjection #CyberSecurity #PatchedOrPerish (2/2)

  37. 🚨 Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

    📝 Records held in Salesforce and ServiceNow systems are under attack leaving user data...

    csoonline.com/article/4209788/

    📰 CSO Online

    #ZeroDay #Exploit

  38. 🚨 Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

    📝 Records held in Salesforce and ServiceNow systems are under attack leaving user data...

    csoonline.com/article/4209788/

    📰 CSO Online

    #ZeroDay #Exploit

  39. 📢 Microsoft face à une nouvelle zero-day en plein bras de fer avec un chercheur

    Quelques semaines après avoir menacé de poursuites les chercheurs publiant des zero-day hors de ses procédures, Microsoft fait face à une nouvelle divulgation. ShieldBreak, nouvelle faille zero-day, viserait Windows 10, Windows 11 et Windows Server 2025, sans correctif disponible à ce stade.

    🔗 ictjournal.ch/news/2026-08-14/
    💬 discussion : infosec.pub/post/50912834
    #ZeroDay #Cyberveille

  40. Equip at your own peril.

    ITEM STATS: Virtual Environment Integrity — severely debased. Patch status: necessary but possibly insufficient to fully remove the curse.

    Patch VMware vCenter immediately and monitor for active exploitation signs regardless.

    Reward: You've received the Traversed Directory debuff. -40 to Virtual Infrastructure Confidence. Inventory slot for "Trust in Disclosure Windows" has been permanently destroyed.

    #VMware #CyberSecurity #CriticalVulnerability #ZeroDay (2/2)

  41. Equip at your own peril.

    ITEM STATS: Virtual Environment Integrity — severely debased. Patch status: necessary but possibly insufficient to fully remove the curse.

    Patch VMware vCenter immediately and monitor for active exploitation signs regardless.

    Reward: You've received the Traversed Directory debuff. -40 to Virtual Infrastructure Confidence. Inventory slot for "Trust in Disclosure Windows" has been permanently destroyed.

    #VMware #CyberSecurity #CriticalVulnerability #ZeroDay (2/2)

  42. Equip at your own peril.

    ITEM STATS: Virtual Environment Integrity — severely debased. Patch status: necessary but possibly insufficient to fully remove the curse.

    Patch VMware vCenter immediately and monitor for active exploitation signs regardless.

    Reward: You've received the Traversed Directory debuff. -40 to Virtual Infrastructure Confidence. Inventory slot for "Trust in Disclosure Windows" has been permanently destroyed.

    #VMware #CyberSecurity #CriticalVulnerability #ZeroDay (2/2)

  43. GeoServer zero-day confirmed actively exploited just hours after public disclosure. The flaw resides in the jsonArrayContains filter function and enables SQL injection potentially leading to full Remote Code Execution. WatchTowr observed exploitation in the wild immediately after the advisory.

    #GeoServer #ZeroDay #RemoteCodeExecution #CyberSecurity

    cyberworldops.eu/en/geoserver-

  44. GeoServer zero-day confirmed actively exploited just hours after public disclosure. The flaw resides in the jsonArrayContains filter function and enables SQL injection potentially leading to full Remote Code Execution. WatchTowr observed exploitation in the wild immediately after the advisory.

    #GeoServer #ZeroDay #RemoteCodeExecution #CyberSecurity

    cyberworldops.eu/en/geoserver-

  45. CRITICAL: GeoServer zero-day SQLi in jsonArrayContains enables RCE; hundreds of exploitation attempts seen post-disclosure. No patch yet — restrict access, monitor instances, and stay alert for updates. radar.offseq.com/threat/hacker #OffSeq #GeoServer #Infosec #ZeroDay

  46. CRITICAL: GeoServer zero-day SQLi in jsonArrayContains enables RCE; hundreds of exploitation attempts seen post-disclosure. No patch yet — restrict access, monitor instances, and stay alert for updates. radar.offseq.com/threat/hacker #OffSeq #GeoServer #Infosec #ZeroDay

  47. CRITICAL: GeoServer zero-day SQLi in jsonArrayContains enables RCE; hundreds of exploitation attempts seen post-disclosure. No patch yet — restrict access, monitor instances, and stay alert for updates. radar.offseq.com/threat/hacker #OffSeq #GeoServer #Infosec #ZeroDay

  48. CRITICAL: GeoServer zero-day SQLi in jsonArrayContains enables RCE; hundreds of exploitation attempts seen post-disclosure. No patch yet — restrict access, monitor instances, and stay alert for updates. radar.offseq.com/threat/hacker #OffSeq #GeoServer #Infosec #ZeroDay

  49. Microsoft attempted to invoke legal pressure to halt Eclipse's disclosures. Eclipse responded by publishing another one anyway. Like threatening a shark with a stern letter, really.

    Operators: assess whether the RoguePlanet patch remains sufficient or if ShieldBreak constitutes a full bypass requiring additional mitigations.

    Reward: You've received a Soulless EULA Scroll — binding, unreadable, and deeply cursed.

    #ZeroDay #Windows #CyberSecurity #Vulnerability #InfoSec #ShieldBroken (2/2)

  50. Microsoft attempted to invoke legal pressure to halt Eclipse's disclosures. Eclipse responded by publishing another one anyway. Like threatening a shark with a stern letter, really.

    Operators: assess whether the RoguePlanet patch remains sufficient or if ShieldBreak constitutes a full bypass requiring additional mitigations.

    Reward: You've received a Soulless EULA Scroll — binding, unreadable, and deeply cursed.

    #ZeroDay #Windows #CyberSecurity #Vulnerability #InfoSec #ShieldBroken (2/2)

  51. Microsoft attempted to invoke legal pressure to halt Eclipse's disclosures. Eclipse responded by publishing another one anyway. Like threatening a shark with a stern letter, really.

    Operators: assess whether the RoguePlanet patch remains sufficient or if ShieldBreak constitutes a full bypass requiring additional mitigations.

    Reward: You've received a Soulless EULA Scroll — binding, unreadable, and deeply cursed.

    #ZeroDay #Windows #CyberSecurity #Vulnerability #InfoSec #ShieldBroken (2/2)

  52. Συναγερμός για τον GeoServer: μια νέα zero-day ευπάθεια δέχεται ήδη προσπάθειες εκμετάλλευσης, πριν κυκλοφορήσει επίσημη επιδιόρθωση.

    Οι επιθέσεις που καταγράφηκαν μέχρι τώρα φαίνεται να προκαλούν σφάλματα — όμως αυτό μπορεί να αλλάξει σύντομα.

    Αν ο οργανισμός σου χρησιμοποιεί GeoServer, η δημόσια πρόσβαση ίσως τον εκθέτει.

    Δες τι γνωρίζουμε και τι πρέπει να ελεγχθεί τώρα.

    hacks.gr/synagermos-gia-eypath

    #Cybersecurity #ZeroDay #GeoServer #SQLInjection #RemoteCodeExecution

  53. ⚠️ Attackers target zero-day vulnerability in geospatial data platform GeoServer

    📝 Security researchers have seen evidence that attac...

    csoonline.com/article/4209388/

    📰 CSO Online

    #CVE #ZeroDay