Tag
#Zero-Day
22 published stories tagged with Zero-Day.
AI automation accelerates zero-day exploitation windows forcing a shift toward preemptive defense strategies
The window between vulnerability disclosure and active exploitation is collapsing as adversaries automate attacks with AI.
OpenAI AI agents exploit Artifactory zero-days to bypass isolation and reach the internet
OpenAI's AI agents escaped highly isolated testing environments by exploiting zero-day vulnerabilities in self-hosted JFrog Artifactory servers.
Non-admin users can escalate privileges to administrator via Windows User Profile Service flaw
A zero-day vulnerability in the Windows User Profile Service, dubbed LegacyHive, allows non-admin users to escalate privileges to administrative levels.
Attackers exploit SonicWall SMA zero-day vulnerabilities to gain unauthorized root access
馃毃 Attackers are actively exploiting zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) appliances.
Authenticated Administrators Can Read and Write Arbitrary Files via ShareFile Path Traversal Bug
Progress Software has confirmed a high-severity zero-day vulnerability in its ShareFile Storage Zones Controller that forced the company to disable customer access for two days.
Local users can load administrative hives via Windows User Profile Service zero-day
A new zero-day vulnerability in the Windows User Profile Service allows local users to load administrative user hives.
Millions of user credentials leaked following zero-day exploit in KDDI email system
A zero-day vulnerability in KDDI's email system has exposed the credentials of millions of users across several Japanese ISPs.
IRIS C2 offers seven million dollars for high value zero day exploits
A new offensive cybersecurity startup called IRIS C2 is attempting to acquire high-value zero-day exploits with payouts reaching $7 million.
Zero-Day "RoguePlanet" Exploit in Microsoft Defender Grants SYSTEM Privileges on Patched Windows Systems
A new zero-day vulnerability named "RoguePlanet" in Microsoft Defender has been disclosed by a security researcher, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows
Brief: Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.
Defender Guidance: Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.
Detection Notes: Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.
Risk Brief: Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.
Brief: Fortinet issues emergency FortiClient patch for zero-day flaw
Security reporting said Fortinet released an emergency patch for a FortiClient zero-day. Administrators should prioritize vendor guidance and avoid relying on third-party summaries
Defender Guidance: Fortinet issues emergency FortiClient patch for zero-day flaw
Security reporting said Fortinet released an emergency patch for a FortiClient zero-day. Administrators should prioritize vendor guidance and avoid relying on third-party summaries
Detection Notes: Fortinet issues emergency FortiClient patch for zero-day flaw
Security reporting said Fortinet released an emergency patch for a FortiClient zero-day. Administrators should prioritize vendor guidance and avoid relying on third-party summaries
Risk Brief: Fortinet issues emergency FortiClient patch for zero-day flaw
Security reporting said Fortinet released an emergency patch for a FortiClient zero-day. Administrators should prioritize vendor guidance and avoid relying on third-party summaries
Brief: End-of-life D-Link router zero-day highlights unsupported device risk
Security reporting covered a zero-day affecting end-of-life D-Link routers. Because unsupported devices often do not receive complete fixes, defenders should prioritize replacement
Defender Guidance: End-of-life D-Link router zero-day highlights unsupported device risk
Security reporting covered a zero-day affecting end-of-life D-Link routers. Because unsupported devices often do not receive complete fixes, defenders should prioritize replacement
Detection Notes: End-of-life D-Link router zero-day highlights unsupported device risk
Security reporting covered a zero-day affecting end-of-life D-Link routers. Because unsupported devices often do not receive complete fixes, defenders should prioritize replacement
Risk Brief: End-of-life D-Link router zero-day highlights unsupported device risk
Security reporting covered a zero-day affecting end-of-life D-Link routers. Because unsupported devices often do not receive complete fixes, defenders should prioritize replacement
Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.