home.social

#zeroday — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.

  1. Threat campaign Targeting Magento StyleSmuggler Zero-Day RCE Exploitation in the Wild

    Pulse ID: 6a9c93480062fd59fc51e7fe
    Pulse Link: otx.alienvault.com/pulse/6a9c9
    Pulse Author: cryptocti
    Created: 2026-09-05 22:10:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #cryptocti

  2. Threat campaign Targeting Magento StyleSmuggler Zero-Day RCE Exploitation in the Wild

    Pulse ID: 6a9c93a4d5f17d95c5d2e9cf
    Pulse Link: otx.alienvault.com/pulse/6a9c9
    Pulse Author: cryptocti
    Created: 2026-09-05 22:11:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #cryptocti

  3. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Indicators extracted from public reporting. Source: sansec.io/research/stylesmuggl

    Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
    Pulse Link: otx.alienvault.com/pulse/6a9c8
    Pulse Author: CyberHunter_NL
    Created: 2026-09-05 20:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL

  4. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Indicators extracted from public reporting. Source: sansec.io/research/stylesmuggl

    Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
    Pulse Link: otx.alienvault.com/pulse/6a9c8
    Pulse Author: CyberHunter_NL
    Created: 2026-09-05 20:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL

  5. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Indicators extracted from public reporting. Source: sansec.io/research/stylesmuggl

    Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
    Pulse Link: otx.alienvault.com/pulse/6a9c8
    Pulse Author: CyberHunter_NL
    Created: 2026-09-05 20:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL

  6. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Indicators extracted from public reporting. Source: sansec.io/research/stylesmuggl

    Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
    Pulse Link: otx.alienvault.com/pulse/6a9c8
    Pulse Author: CyberHunter_NL
    Created: 2026-09-05 20:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL

  7. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Indicators extracted from public reporting. Source: sansec.io/research/stylesmuggl

    Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
    Pulse Link: otx.alienvault.com/pulse/6a9c8
    Pulse Author: CyberHunter_NL
    Created: 2026-09-05 20:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL

  8. Trezor Breach Exposes 67,000 US Customers' Data

    A data breach at Trezor's shipping provider has compromised the personal info of 67,000 US customers, including names, emails, phone numbers, addresses, and order numbers. The breach, linked to a zero-day SQL injection vulnerability, has raised concerns about customer data security, but Trezor assures that its hardware wallets remain secure.

    osintsights.com/trezor-breach-

    #Trezor #DataBreach #ZeroDay #Cve202672898 #Metabase

  9. 📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

    Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity

    🔗 cyber.netsecops.io/articles/go

  10. Update Chrome to the latest version immediately; the attackers already knew about this before you did.

    Reward: You've received a Cracked Piston — cosmetic only, non-functional, much like your unpatched browser was.

    #ZeroDay #Chrome #CyberSecurity #V8Engine #Vulnerability #PatchedOrPerish (2/2)

  11. 🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
    OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
    securityweek.com/openais-astra

  12. 🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
    OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
    securityweek.com/openais-astra
    #AI #CyberSecurity #ZeroDay #InfoSec

  13. 🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
    OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
    securityweek.com/openais-astra
    #AI #CyberSecurity #ZeroDay #InfoSec

  14. 📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046)

    Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité. CVE-2026-85046 (CVSS : 8.8) est une faille de type confusion dans le moteur V8 (JavaScript/WebAssembly de Chrome). Elle permet à…

    📖 cyberveille : cyberveille.ch/posts/2026-09-0
    🌐 source : securityaffairs.com/198405/sec
    🟢 vérification factuelle haute
    #Chrome #ZeroDay #Cyberveille

  15. CrowdStrike Zero-Day Exploit Grants SYSTEM Privileges on Windows Systems

    A new zero-day exploit, dubbed FalconFlank, can grant attackers SYSTEM-level access to fully patched Windows machines protected by CrowdStrike Falcon, allowing them to spawn a command prompt with elevated privileges. This alarming vulnerability leverages CrowdStrike's own Office malicious macros remediation feature to perform a…

    osintsights.com/crowdstrike-ze

    #Crowdstrike #ZeroDay #Windows #PrivilegeEscalation #FalconSensor

  16. This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.

    Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.

    Reward: You've received the Malicious Compliance Badge. It confers no protection.

    #Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)

  17. This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.

    Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.

    Reward: You've received the Malicious Compliance Badge. It confers no protection.

    #Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)

  18. This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.

    Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.

    Reward: You've received the Malicious Compliance Badge. It confers no protection.

    #Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)

  19. Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay

    cyberworldops.eu/en/chrome-fix

  20. Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay

    cyberworldops.eu/en/chrome-fix

  21. There is no unequip button.

    Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.

    Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.

    #Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)

  22. There is no unequip button.

    Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.

    Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.

    #Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)

  23. There is no unequip button.

    Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.

    Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.

    #Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)

  24. Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

    Google just patched a high-severity Chrome zero-day flaw that's being actively exploited - a type confusion vulnerability in V8 that could let hackers run malicious code inside the browser's sandbox. This critical update brings Chrome's version up to 152.0.7977.82, so make sure you've got the latest version installed!

    osintsights.com/google-patches

    #ZeroDay #GoogleChrome #V8 #Cve202685046 #TypeConfusion

  25. Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

    SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.

    osintsights.com/attackers-expl

    #ZeroDay #Sonicwall #Cve202683548 #Cve202683549 #Sma1000

  26. Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

    SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.

    osintsights.com/attackers-expl

    #ZeroDay #Sonicwall #Cve202683548 #Cve202683549 #Sma1000

  27. Security Researcher Exploits CrowdStrike Falcon with New Zero-Day Bug

    A security researcher known as Nightmare Eclipse has made a stunning discovery, exploiting a zero-day bug in CrowdStrike's Falcon software and prompting the company to urge customers to disable a key Windows policy setting. This latest finding is part of a string of proof-of-concept exploits released by the…

    osintsights.com/security-resea

    #ZeroDay #CrowdstrikeFalcon #ProofofconceptExploits #NightmareEclipse #EmergingThreats

  28. Pegasus Spyware Targets Serbian Student Activist's iPhone

    A Serbian student activist's iPhone was hacked with NSO Group's notorious Pegasus spyware through a clever zero-click exploit targeting Apple iMessage, according to a joint investigation by Citizen Lab and SHARE Foundation. This sneaky attack allowed the spyware to infect the device without the user even clicking on a link.

    osintsights.com/pegasus-spywar

    #PegasusSpyware #Imessage #ZeroDay #NsoGroup #CitizenLab

  29. Chrome CSS Zero-Day (CVE-2026-2441)

    Google has patched a CVSS 8.8 high-severity use-after-free bug in Chrome’s CSS engine that is being exploited in the wild. This also affects all Chrome-based browsers such as Brave, Edge and Opera.

    forum.hashpwn.net/post/10273

    #google #chrome #brave #edge #opera #browser #cybersecurity #css #zeroday #cve20262441 #news #hashpwn

  30. Former defense contractor exec pleaded guilty to selling 8 zero-day exploits to a Russian broker.

    • $1.3M crypto payments
    • Access to millions of devices
    • DOJ seeking 9-year sentence
    • $35M+ corporate losses

    Full report:
    technadu.com/trenchant-boss-so

    #ZeroDay #CyberSecurity #InsiderThreat #NationalSecurity

  31. Ivanti has disclosed two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) which allow RCE, tracked as CVE-2026-1281 and CVE-2026-1340. Both flaws are unauthenticated code injection issues that allow remote attackers to achieve arbitrary code execution on affected EPMM appliances. Active exploitation has been confirmed.

    forum.hashpwn.net/post/9428

    #cybersecurity #zeroday #rce #news #ivanti #cve #epmm #hashpwn

  32. Apple drängt iPhones zu iOS-26-Update wegen Sicherheitslücken
    Apple verteilt derzeit wichtige Sicherheitsaktualisierungen für seine Betriebssysteme – doch bei iPhones sorgt die Verteilung für Kritik. Wer ein aktuelles Gerät nutzt, soll praktisch zu iOS 26.2 wechseln, um geschützt zu sein.
    apfeltalk.de/magazin/news/appl
    #iPhone #News #Apple #IOS1873 #IOS26 #iPhone #Sicherheitslcke #Sicherheitsupdate #Webkit #ZeroDay