#zeroday — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.
-
Threat campaign Targeting Magento StyleSmuggler Zero-Day RCE Exploitation in the Wild
Pulse ID: 6a9c93480062fd59fc51e7fe
Pulse Link: https://otx.alienvault.com/pulse/6a9c93480062fd59fc51e7fe
Pulse Author: cryptocti
Created: 2026-09-05 22:10:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #cryptocti
-
Threat campaign Targeting Magento StyleSmuggler Zero-Day RCE Exploitation in the Wild
Pulse ID: 6a9c93a4d5f17d95c5d2e9cf
Pulse Link: https://otx.alienvault.com/pulse/6a9c93a4d5f17d95c5d2e9cf
Pulse Author: cryptocti
Created: 2026-09-05 22:11:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #cryptocti
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
StyleSmuggler, a Magento zero-day, gives unauthenticated remote code execution and is exploited in the wild. No patch yet. Mitigate now.
#StyleSmuggler #Magento #AdobeCommerce #ZeroDay #RCE #eCommerceSecurity #Sansec #Infosec
-
Trezor Breach Exposes 67,000 US Customers' Data
A data breach at Trezor's shipping provider has compromised the personal info of 67,000 US customers, including names, emails, phone numbers, addresses, and order numbers. The breach, linked to a zero-day SQL injection vulnerability, has raised concerns about customer data security, but Trezor assures that its hardware wallets remain secure.
-
📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity
-
Update Chrome to the latest version immediately; the attackers already knew about this before you did.
Reward: You've received a Cracked Piston — cosmetic only, non-functional, much like your unpatched browser was.
#ZeroDay #Chrome #CyberSecurity #V8Engine #Vulnerability #PatchedOrPerish (2/2)
-
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046)
Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité. CVE-2026-85046 (CVSS : 8.8) est une faille de type confusion dans le moteur V8 (JavaScript/WebAssembly de Chrome). Elle permet à…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-google-corrige-le-sixieme-zero-day-chrome-activement-exploite-en-2026-cve-2026-85046/
🌐 source : https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html
🟢 vérification factuelle haute
#Chrome #ZeroDay #Cyberveille -
CrowdStrike Zero-Day Exploit Grants SYSTEM Privileges on Windows Systems
A new zero-day exploit, dubbed FalconFlank, can grant attackers SYSTEM-level access to fully patched Windows machines protected by CrowdStrike Falcon, allowing them to spawn a command prompt with elevated privileges. This alarming vulnerability leverages CrowdStrike's own Office malicious macros remediation feature to perform a…
#Crowdstrike #ZeroDay #Windows #PrivilegeEscalation #FalconSensor
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay
https://cyberworldops.eu/en/chrome-fixes-sixth-zero-day-of-2026-active-attacks-target-v8-engine
-
Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay
https://cyberworldops.eu/en/chrome-fixes-sixth-zero-day-of-2026-active-attacks-target-v8-engine
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google just patched a high-severity Chrome zero-day flaw that's being actively exploited - a type confusion vulnerability in V8 that could let hackers run malicious code inside the browser's sandbox. This critical update brings Chrome's version up to 152.0.7977.82, so make sure you've got the latest version installed!
-
Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances
SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.
-
Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances
SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Security Researcher Exploits CrowdStrike Falcon with New Zero-Day Bug
A security researcher known as Nightmare Eclipse has made a stunning discovery, exploiting a zero-day bug in CrowdStrike's Falcon software and prompting the company to urge customers to disable a key Windows policy setting. This latest finding is part of a string of proof-of-concept exploits released by the…
#ZeroDay #CrowdstrikeFalcon #ProofofconceptExploits #NightmareEclipse #EmergingThreats
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
Pegasus Spyware Targets Serbian Student Activist's iPhone
A Serbian student activist's iPhone was hacked with NSO Group's notorious Pegasus spyware through a clever zero-click exploit targeting Apple iMessage, according to a joint investigation by Citizen Lab and SHARE Foundation. This sneaky attack allowed the spyware to infect the device without the user even clicking on a link.
-
Storm-1175 is hitting orgs with chained zero-days and dropping Medusa ransomware in under 24 hours.
Full write-up: https://forum.hashpwn.net/post/12014
#cybersecurity #storm1175 #zeroday #medusa #ransomeware #windows #news #hashpwn
-
@dotcsv.bsky.social #Mythos todavía no será público; el salto en capacidades es muy significativo en #Ciberseguridad #vulnerabilidades #ZeroDay #AI #Antropic #Claude #ProgramacionAgentica www.youtube.com/watch?v=e2M5...
CLAUDE MYTHOS, el modelo MÁS P... -
@dotcsv.bsky.social #Mythos todavía no será público; el salto en capacidades es muy significativo en #Ciberseguridad #vulnerabilidades #ZeroDay #AI #Antropic #Claude #ProgramacionAgentica www.youtube.com/watch?v=e2M5...
CLAUDE MYTHOS, el modelo MÁS P... -
@dotcsv.bsky.social #Mythos todavía no será público; el salto en capacidades es muy significativo en #Ciberseguridad #vulnerabilidades #ZeroDay #AI #Antropic #Claude #ProgramacionAgentica www.youtube.com/watch?v=e2M5...
CLAUDE MYTHOS, el modelo MÁS P... -
@dotcsv.bsky.social #Mythos todavía no será público; el salto en capacidades es muy significativo en #Ciberseguridad #vulnerabilidades #ZeroDay #AI #Antropic #Claude #ProgramacionAgentica www.youtube.com/watch?v=e2M5...
CLAUDE MYTHOS, el modelo MÁS P... -
@dotcsv.bsky.social #Mythos todavía no será público; el salto en capacidades es muy significativo en #Ciberseguridad #vulnerabilidades #ZeroDay #AI #Antropic #Claude #ProgramacionAgentica www.youtube.com/watch?v=e2M5...
CLAUDE MYTHOS, el modelo MÁS P... -
Chrome CSS Zero-Day (CVE-2026-2441)
Google has patched a CVSS 8.8 high-severity use-after-free bug in Chrome’s CSS engine that is being exploited in the wild. This also affects all Chrome-based browsers such as Brave, Edge and Opera.
https://forum.hashpwn.net/post/10273
#google #chrome #brave #edge #opera #browser #cybersecurity #css #zeroday #cve20262441 #news #hashpwn
-
Eine neue #Episode des #Zeroday #Podcast ist #online: 0d131 – Der Wechsel auf Linux statt WIndows als daily driver
Link zur Episode: https://0x0d.de/2026/02/0d131-der-wechsel-auf-linux-statt-windows-als-daily-driver/
@[email protected] (Stefan)
@zeroday (Sven)#Cinnamon #Datenschutz #Informationssicherheit #ITSecurity #ITSicherheit #linux #Opendeck #openrgb #privacy #Privatsphäre #VocasterPro #Windows
-
Former defense contractor exec pleaded guilty to selling 8 zero-day exploits to a Russian broker.
• $1.3M crypto payments
• Access to millions of devices
• DOJ seeking 9-year sentence
• $35M+ corporate losses -
Ivanti has disclosed two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) which allow RCE, tracked as CVE-2026-1281 and CVE-2026-1340. Both flaws are unauthenticated code injection issues that allow remote attackers to achieve arbitrary code execution on affected EPMM appliances. Active exploitation has been confirmed.
https://forum.hashpwn.net/post/9428
#cybersecurity #zeroday #rce #news #ivanti #cve #epmm #hashpwn
-
Apple drängt iPhones zu iOS-26-Update wegen Sicherheitslücken
Apple verteilt derzeit wichtige Sicherheitsaktualisierungen für seine Betriebssysteme – doch bei iPhones sorgt die Verteilung für Kritik. Wer ein aktuelles Gerät nutzt, soll praktisch zu iOS 26.2 wechseln, um geschützt zu sein.
https://www.apfeltalk.de/magazin/news/apple-draengt-iphones-zu-ios-26-update-wegen-sicherheitsluecken/
#iPhone #News #Apple #IOS1873 #IOS26 #iPhone #Sicherheitslcke #Sicherheitsupdate #Webkit #ZeroDay