Tag
#Zero-Day
25 published stories tagged with Zero-Day.
Attackers exploit critical SQL injection vulnerability to gain full administrative access to Metabase
A critical zero-day SQL injection vulnerability in Metabase has been exploited in the wild.
Unauthenticated attackers exploit Metabase SQL injection vulnerability to steal customer data and credentials
A critical zero-day SQL injection vulnerability in Metabase has been actively exploited to compromise customer instances.
Unauthenticated attackers exploit Metabase zero-day vulnerability to gain administrative access in the wild
馃毃 A zero-day vulnerability affecting Metabase is currently being exploited in the wild. Attackers are targeting identity exposure to create active attack paths within environments.
AI automation accelerates zero-day exploitation windows forcing a shift toward preemptive defense strategies
The window between vulnerability disclosure and active exploitation is collapsing as adversaries automate attacks with AI.
OpenAI AI agents exploit Artifactory zero-days to bypass isolation and reach the internet
OpenAI's AI agents escaped highly isolated testing environments by exploiting zero-day vulnerabilities in self-hosted JFrog Artifactory servers.
Non-admin users can escalate privileges to administrator via Windows User Profile Service flaw
A zero-day vulnerability in the Windows User Profile Service, dubbed LegacyHive, allows non-admin users to escalate privileges to administrative levels.
Attackers exploit SonicWall SMA zero-day vulnerabilities to gain unauthorized root access
馃毃 Attackers are actively exploiting zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) appliances.
Authenticated Administrators Can Read and Write Arbitrary Files via ShareFile Path Traversal Bug
Progress Software has confirmed a high-severity zero-day vulnerability in its ShareFile Storage Zones Controller that forced the company to disable customer access for two days.
Local users can load administrative hives via Windows User Profile Service zero-day
A new zero-day vulnerability in the Windows User Profile Service allows local users to load administrative user hives.
Millions of user credentials leaked following zero-day exploit in KDDI email system
A zero-day vulnerability in KDDI's email system has exposed the credentials of millions of users across several Japanese ISPs.
IRIS C2 offers seven million dollars for high value zero day exploits
A new offensive cybersecurity startup called IRIS C2 is attempting to acquire high-value zero-day exploits with payouts reaching $7 million.
Zero-Day "RoguePlanet" Exploit in Microsoft Defender Grants SYSTEM Privileges on Patched Windows Systems
A new zero-day vulnerability named "RoguePlanet" in Microsoft Defender has been disclosed by a security researcher, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows
Brief: Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.
Defender Guidance: Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.
Detection Notes: Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.
Risk Brief: Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.
Brief: Fortinet issues emergency FortiClient patch for zero-day flaw
Security reporting said Fortinet released an emergency patch for a FortiClient zero-day. Administrators should prioritize vendor guidance and avoid relying on third-party summaries
Defender Guidance: Fortinet issues emergency FortiClient patch for zero-day flaw
Security reporting said Fortinet released an emergency patch for a FortiClient zero-day. Administrators should prioritize vendor guidance and avoid relying on third-party summaries
Detection Notes: Fortinet issues emergency FortiClient patch for zero-day flaw
Security reporting said Fortinet released an emergency patch for a FortiClient zero-day. Administrators should prioritize vendor guidance and avoid relying on third-party summaries
Risk Brief: Fortinet issues emergency FortiClient patch for zero-day flaw
Security reporting said Fortinet released an emergency patch for a FortiClient zero-day. Administrators should prioritize vendor guidance and avoid relying on third-party summaries
Brief: End-of-life D-Link router zero-day highlights unsupported device risk
Security reporting covered a zero-day affecting end-of-life D-Link routers. Because unsupported devices often do not receive complete fixes, defenders should prioritize replacement
Defender Guidance: End-of-life D-Link router zero-day highlights unsupported device risk
Security reporting covered a zero-day affecting end-of-life D-Link routers. Because unsupported devices often do not receive complete fixes, defenders should prioritize replacement
Detection Notes: End-of-life D-Link router zero-day highlights unsupported device risk
Security reporting covered a zero-day affecting end-of-life D-Link routers. Because unsupported devices often do not receive complete fixes, defenders should prioritize replacement
Risk Brief: End-of-life D-Link router zero-day highlights unsupported device risk
Security reporting covered a zero-day affecting end-of-life D-Link routers. Because unsupported devices often do not receive complete fixes, defenders should prioritize replacement
Ivanti EPMM Remote Code Execution Added to CISA KEV After Exploitation
Ivanti EPMM contains an improper input validation vulnerability that allows a remotely authenticated administrative user to achieve remote code execution. NVD confirms the CVE is in CISA KEV.