#zeroday — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.
-
Threat campaign Targeting Magento StyleSmuggler Zero-Day RCE Exploitation in the Wild
Pulse ID: 6a9c93480062fd59fc51e7fe
Pulse Link: https://otx.alienvault.com/pulse/6a9c93480062fd59fc51e7fe
Pulse Author: cryptocti
Created: 2026-09-05 22:10:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #cryptocti
-
Threat campaign Targeting Magento StyleSmuggler Zero-Day RCE Exploitation in the Wild
Pulse ID: 6a9c93a4d5f17d95c5d2e9cf
Pulse Link: https://otx.alienvault.com/pulse/6a9c93a4d5f17d95c5d2e9cf
Pulse Author: cryptocti
Created: 2026-09-05 22:11:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #cryptocti
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
StyleSmuggler, a Magento zero-day, gives unauthenticated remote code execution and is exploited in the wild. No patch yet. Mitigate now.
#StyleSmuggler #Magento #AdobeCommerce #ZeroDay #RCE #eCommerceSecurity #Sansec #Infosec
-
Update Chrome to the latest version immediately; the attackers already knew about this before you did.
Reward: You've received a Cracked Piston — cosmetic only, non-functional, much like your unpatched browser was.
#ZeroDay #Chrome #CyberSecurity #V8Engine #Vulnerability #PatchedOrPerish (2/2)
-
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046)
Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité. CVE-2026-85046 (CVSS : 8.8) est une faille de type confusion dans le moteur V8 (JavaScript/WebAssembly de Chrome). Elle permet à…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-google-corrige-le-sixieme-zero-day-chrome-activement-exploite-en-2026-cve-2026-85046/
🌐 source : https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html
🟢 vérification factuelle haute
#Chrome #ZeroDay #Cyberveille -
CrowdStrike Zero-Day Exploit Grants SYSTEM Privileges on Windows Systems
A new zero-day exploit, dubbed FalconFlank, can grant attackers SYSTEM-level access to fully patched Windows machines protected by CrowdStrike Falcon, allowing them to spawn a command prompt with elevated privileges. This alarming vulnerability leverages CrowdStrike's own Office malicious macros remediation feature to perform a…
#Crowdstrike #ZeroDay #Windows #PrivilegeEscalation #FalconSensor
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay
https://cyberworldops.eu/en/chrome-fixes-sixth-zero-day-of-2026-active-attacks-target-v8-engine
-
Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay
https://cyberworldops.eu/en/chrome-fixes-sixth-zero-day-of-2026-active-attacks-target-v8-engine
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google just patched a high-severity Chrome zero-day flaw that's being actively exploited - a type confusion vulnerability in V8 that could let hackers run malicious code inside the browser's sandbox. This critical update brings Chrome's version up to 152.0.7977.82, so make sure you've got the latest version installed!
-
Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances
SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.
-
Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances
SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Security Researcher Exploits CrowdStrike Falcon with New Zero-Day Bug
A security researcher known as Nightmare Eclipse has made a stunning discovery, exploiting a zero-day bug in CrowdStrike's Falcon software and prompting the company to urge customers to disable a key Windows policy setting. This latest finding is part of a string of proof-of-concept exploits released by the…
#ZeroDay #CrowdstrikeFalcon #ProofofconceptExploits #NightmareEclipse #EmergingThreats
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
Pegasus Spyware Targets Serbian Student Activist's iPhone
A Serbian student activist's iPhone was hacked with NSO Group's notorious Pegasus spyware through a clever zero-click exploit targeting Apple iMessage, according to a joint investigation by Citizen Lab and SHARE Foundation. This sneaky attack allowed the spyware to infect the device without the user even clicking on a link.
-
Researcher Exposes Privilege Escalation Flaw in CrowdStrike Falcon
A security researcher, known as Chaotic Eclipse, has uncovered a zero-day privilege escalation flaw in CrowdStrike Falcon, dubbed FalconFlank, which exploits the office malicious macros remediation feature. This vulnerability allows for a potentially devastating escalation of privileges, and a public proof-of-concept has…
#ZeroDay #PrivilegeEscalation #CrowdstrikeFalcon #Proofofconcept #EmergingThreats
-
ShinyHunters e lo zero-day PeopleSoft: il regolatore assicurativo USA tra le 100+ vittime di UNC6240
Sfruttando CVE-2026-35273, una RCE non autenticata in Oracle PeopleSoft, il collettivo ShinyHunters/UNC6240 ha colpito oltre 100 organizzazioni prima ancora del rilascio della patch. Tra le vittime la NAIC, il regolatore assicurativo USA: 3,1 TB di dati esfiltrati e agenzie di rating in stallo. -
Cisco unter Beschuss
Es ist alles nicht so schlimm wie es aussieht, es ist alles viel viel schlimmer. Nicht nur werden in schöner (?) Regelmäßigkeit gefährliche Sicherheitslücken in Cisco-Produkten gefunden, sondern sie werden auch sofort für Angriffe ausgenutzt - manche schon vor der Veröffentlichung (Zero-Day). Eine kleine Historie füge ich unten an. Beginnen wir mit CVE-2026-20230 (8,6 von 10), über die ich noch nicht explizit berichtet hatte. Am Anfang Juni hatte Cisco Flicken gegen diese Sicherheitslücke veröffentlicht. Damals vermeldete die Firma, dass ein PoC Exploit vorläge. Anscheinend haben unbekannte Hacker den PoC gleich in einen
https://www.pc-fluesterer.info/wordpress/2026/06/25/cisco-unter-beschuss/
#0day #backdoor #cybercrime #exploits #hersteller #politik #privacy #sicherheit #spionage #UnplugTrump #wissen #zeroday
-
BlueHammer abuses Windows Defender's update process to gain SYSTEM access
https://hackingpassion.com/bluehammer-windows-defender-zero-day/
#HackerNews #BlueHammer #WindowsDefender #ZeroDay #Cybersecurity #Vulnerability #HackingNews
-
https://winbuzzer.com/2026/03/25/darksword-ios-exploit-leaks-github-threatens-millions-xcxwbn/
DarkSword iOS Exploit Leaks on GitHub, Threatens Millions
#iOS #Apple #Cybersecurity #ZeroDay #Exploits #iPhone #Surveillance #Malware #Spyware #Hackers #Cybercrime #ThreatIntelligence #iOS18 #iPad #iPadOS #Hacking #Russia #Cyberespionage #Darksword #Iverify
-
Ny brist i WinRAR utnyttjas av minst två olika hackergrupper. Läs mer på bloggen:
https://kryptera.se/ny-brist-i-winrar-utnyttjas-av-minst-tva-hotaktorer/
#Cybersecurity #InfoSec #Security #Vulnerability #ZeroDay #PatchNow #WinRAR #CVE20258088 #PathTraversal #ThreatIntel #IncidentResponse #RomCom #PaperWerewolf #PhishingAlert
-
#Qualcomm has released security patches for three #zeroday #vulnerabilities in the #Adreno Graphics Processing Unit (#GPU) driver that impact dozens of chipsets and are actively exploited in targeted attacks.
The company says two critical flaws (tracked as CVE-2025-21479 and CVE-2025-21480) were reported through the #Google #Android #Security team in late January, and a third high-severity vulnerability (CVE-2025-27038) was reported in March.
-
malicious npm packages (again) targeting cryptocurrency projects, CEOs cranky over CVEs, and BlackLock gets pantsed - here's your Friday wrap up in Infosec News 👇
🔗 https://opalsec.io/daily-news-update-friday-march-28-2025-australia-melbourne/
Here's a quick rundown of what's inside:
📦 npm Package Nightmare: 10 packages compromised by an infostealer campaign targeting developer environments. Sensitive data was siphoned off to a remote host. Most of the packages are still available on npm, so be careful!
🦊 Firefox Flaw: A critical sandbox escape vulnerability (CVE-2025-2857) patched in Firefox 136.0.4. Windows users, update ASAP! This one's similar to a Chrome zero-day used in espionage campaigns.
🏥 Ransomware Reckoning: Advanced, a UK healthcare IT provider, slapped with a £3.1 million fine after a LockBit ransomware attack. Lack of vulnerability scanning and poor patch management were key factors.
🌐 Extension Exploitation: Browser extensions can be bought and repurposed, posing a sneaky threat to enterprises. An extension was bought for $50 and was quickly repurposed to redirect traffic.
⚡ Solar Scare: Dozens of vulnerabilities in solar inverters could let attackers disrupt power grids. Remote code execution, device takeover, and more are possible.
😠 CrushFTP Clash: CEO responds aggressively to VulnCheck after critical unauthenticated access vulnerability (CVE-2025-2825) is released. Vulnerability disclosure and patching processes need to be improved!
🕵️♀️ Pegasus in Serbia: Journalists targeted with Pegasus spyware, marking the third time in two years that Amnesty has found Pegasus deployed against Serbian civil society.
🤖 Mamont Malware: Russian authorities arrest three for developing the Mamont Android banking trojan. This malware steals financial data and spreads through Telegram.
🦹 Ransomware Reverse: Resecurity infiltrates the BlackLock ransomware gang, gathering intel to help victims. LFI vulnerability exploited, and data shared with authorities.Stay vigilant out there, folks! 🛡️
#Cybersecurity #InfoSec #Vulnerability #Ransomware #Malware #npm #Firefox #Pegasus #SolarInverters #DataBreach #ThreatIntel #CyberThreats #SecurityNews #WebAppSec #ZeroDay #PatchManagement #infostealer #blacklock #crushftp #mamont
-
Hey #CyberSecurity pros! 👋 Ready to dive into the latest threats and breaches making headlines?
Our latest blog post is packed with need-to-know info to keep you ahead of the curve.
🗞️ https://opalsec.io/daily-news-update-thursday-march-27-2025-australia-melbourne/
Here's a quick rundown of what's inside:
🕵️♂️ FamousSparrow's Return: The Chinese government-backed hacking group is back, targeting organizations in North America. Important distinction: ESET insists on tracking them separately from Salt Typhoon. Remember to prioritize TTPs and IOCs/IOAs accordingly!
🗄️ RedCurl's Ransomware Twist: This corporate espionage group is now deploying "QWCrypt" ransomware, targeting Hyper-V servers. Phishing emails with malicious IMG attachments are the initial attack vector.
😬 StreamElements Data Breach: A third-party service provider suffered a breach, exposing data of 210,000 customers.!
🏛️ NSW Court System Data Theft: Sensitive documents, including AVOs, were stolen from the NSW Online Registry website. This could have serious consequences for victims of domestic violence.
👨🎓 NYU Website Defacement: A hacker compromised NYU's website, leaking personal data of over 1 million students. Even with good intentions, the collateral damage is unacceptable.
💰 Defense Contractor Fined: MORSE Corp will pay millions for failing to meet federal cybersecurity requirements. Third-party risk management is crucial!
🤖 Atlantis AIO Automates Credential Stuffing: This new platform automates credential stuffing attacks against 140 online services. Stay vigilant against brute force attacks!
🚨 Chrome Zero-Day Exploited: Google patched a zero-day vulnerability exploited in espionage campaigns targeting Russian organizations. Keep your browsers updated!
👦 UK Warns of 'Com Networks': The UK's NCA is warning of a growing threat from online networks of teenage boys who are "dedicated to inflicting harm and committing a range of criminality." A very worrying trend that we need to be aware of.
Ready for the full scoop? Read the full blog post here 👉 https://opalsec.io/daily-news-update-thursday-march-27-2025-australia-melbourne/
#Cybersecurity #InfoSec #DataBreach #Ransomware #ThreatIntelligence #DataPrivacy #ZeroDay #FamousSparrow #RedCurl #StreamElements #NSWCourts #NYU #MORSECorp #AtlantisAIO #Chrome #ComNetworks #SecurityNews #CybersecurityThreats #InfoSecurity #CyberAttack #DataSecurity #PrivacyMatters #Vulnerability #Cybercrime #ThreatActor #ESET #SaltTyphoon #NIST #ZeroTrust #SaltTyphoon #CriticalInfrastructure