Friday, August 28, 2026
Follow on LinkedIn

Zero-Day

Hackers Actively Exploiting SonicWall SMA1000 0-Day Vulnerability in the Wild

SonicWall disclosed two vulnerabilities affecting its SMA1000 Series remote access appliances, and threat actors were already exploiting one of them before the advisory even went public. The flaws include a critical server-side request forgery (SSRF) bug, CVE-2026-15409, scoring a perfect...

Microsoft Exchange, Windows 11, and Cursor Zero-Days Exploited on Pwn2Own Day 2

Pwn2Own Berlin 2026 is rapidly escalating into one of the most intense offensive security contests in recent years, with Day Two delivering a fresh wave of critical zero-day exploits targeting enterprise software, AI tools, and operating systems. Security researchers...

Hackers Actively Attacking Adobe Reader Users Using Sophisticated 0-Day Exploit

A highly sophisticated, unpatched zero-day exploit is actively targeting users of Adobe Reader. Detected by the EXPMON threat-hunting system, this malicious PDF file is designed to steal sensitive local data and perform advanced system fingerprinting. The exploit functions flawlessly on...

Desktop Window Manager 0-Day Vulnerability Allows Attacker to Elevate Privileges

Microsoft has released urgent security updates to address a critical zero-day vulnerability in the Windows Desktop Window Manager (DWM). Tracked as CVE-2026-21519, this flaw is currently being exploited in the wild, allowing attackers to gain full control over affected systems. The Desktop...

Windows Remote Access Connection Manager 0-Day Vulnerability Let Attackers Trigger DoS Attack

Microsoft has patched a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service, tracked as CVE-2026-21525, which allowed attackers to trigger denial-of-service (DoS) conditions on unpatched systems. The flaw, stemming from a NULL pointer dereference (CWE-476), was actively...

Windows Shell Security Feature 0-Day Vulnerability Let Attackers Bypass Authentication

Microsoft released Microsoft Patch Tuesday updates to address a critical zero-day vulnerability in Windows Shell that is currently being actively exploited in the wild. Tracked as CVE-2026-21510, this security flaw allows remote attackers to bypass essential protection mechanisms, putting millions of...

Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code

A critical zero‑day vulnerability in Gemini MCP Tool exposes users to remote code execution (RCE) attacks without any authentication. Tracked as ZDI‑26‑021 / ZDI‑CAN‑27783 and assigned CVE‑2026‑0755, the flaw carries a maximum CVSS v3.1 score of 9.8, reflecting its...

Hackers Earned $516,500 for 37 Unique 0-day Vulnerabilities – Pwn2Own Automotive 2026

Day One of Pwn2Own Automotive 2026, which delivered $516,500 USD for 37 zero-days, the event has now accumulated $955,750 USD across 66 unique vulnerabilities, demonstrating the automotive sector's substantial attack surface. The competition showcased exploits targeting multiple vehicle subsystems, including...

Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts

A critical zero-day vulnerability has been discovered in XSpeeder's SXZOS firmware, affecting tens of thousands of SD-WAN appliances, edge routers, and smart TV controllers deployed globally. The vulnerability, designated PWN-25-01, enables unauthenticated remote code execution (RCE) with root-level privileges through...

WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls

An urgent security update has been released to fix a critical zero-day vulnerability in WatchGuard Firebox firewalls. With warnings that hackers are already actively exploiting the flaw in the wild to take control of affected devices. The vulnerability, tracked as CVE-2025-14733,...

Latest News

Latest News