SonicWall disclosed two vulnerabilities affecting its SMA1000 Series remote access appliances, and threat actors were already exploiting one of them before the advisory even went public.
The flaws include a critical server-side request forgery (SSRF) bug, CVE-2026-15409, scoring a perfect...
Pwn2Own Berlin 2026 is rapidly escalating into one of the most intense offensive security contests in recent years, with Day Two delivering a fresh wave of critical zero-day exploits targeting enterprise software, AI tools, and operating systems.
Security researchers...
A highly sophisticated, unpatched zero-day exploit is actively targeting users of Adobe Reader. Detected by the EXPMON threat-hunting system, this malicious PDF file is designed to steal sensitive local data and perform advanced system fingerprinting.
The exploit functions flawlessly on...
Microsoft has released urgent security updates to address a critical zero-day vulnerability in the Windows Desktop Window Manager (DWM).
Tracked as CVE-2026-21519, this flaw is currently being exploited in the wild, allowing attackers to gain full control over affected systems.
The Desktop...
Microsoft has patched a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service, tracked as CVE-2026-21525, which allowed attackers to trigger denial-of-service (DoS) conditions on unpatched systems.
The flaw, stemming from a NULL pointer dereference (CWE-476), was actively...
Microsoft released Microsoft Patch Tuesday updates to address a critical zero-day vulnerability in Windows Shell that is currently being actively exploited in the wild.
Tracked as CVE-2026-21510, this security flaw allows remote attackers to bypass essential protection mechanisms, putting millions of...
A critical zero‑day vulnerability in Gemini MCP Tool exposes users to remote code execution (RCE) attacks without any authentication.
Tracked as ZDI‑26‑021 / ZDI‑CAN‑27783 and assigned CVE‑2026‑0755, the flaw carries a maximum CVSS v3.1 score of 9.8, reflecting its...
Day One of Pwn2Own Automotive 2026, which delivered $516,500 USD for 37 zero-days, the event has now accumulated $955,750 USD across 66 unique vulnerabilities, demonstrating the automotive sector's substantial attack surface.
The competition showcased exploits targeting multiple vehicle subsystems, including...
A critical zero-day vulnerability has been discovered in XSpeeder's SXZOS firmware, affecting tens of thousands of SD-WAN appliances, edge routers, and smart TV controllers deployed globally.
The vulnerability, designated PWN-25-01, enables unauthenticated remote code execution (RCE) with root-level privileges through...
An urgent security update has been released to fix a critical zero-day vulnerability in WatchGuard Firebox firewalls. With warnings that hackers are already actively exploiting the flaw in the wild to take control of affected devices.
The vulnerability, tracked as CVE-2025-14733,...