A sophisticated zero-click attack methodology called RenderShock that exploits passive file preview and indexing behaviors in modern operating systems to execute malicious payloads without requiring any user interaction.
Unlike traditional phishing campaigns that rely on users clicking malicious links or...
A threat actor using the handle “zeroplayer” advertised a previously unknown remote-code-execution (RCE) exploit for WinRAR on an underground forum.
The post, titled “WINRAR RCE 0DAY – 80,000$,” claims the flaw works “fully on the latest version of WinRAR and...
A critical information disclosure vulnerability in Microsoft SQL Server, designated as CVE-2025-49719, allows unauthorized attackers to access sensitive data over network connections.
This vulnerability stems from improper input validation within SQL Server's processing mechanisms, enabling attackers to disclose uninitialized memory...
Nippon Steel Solutions has disclosed a significant data breach affecting customer, partner, and employee personal information following a zero-day cyber attack that exploited a previously unknown software vulnerability in their network infrastructure.
The incident, detected on March 7, 2025,...
CISA has issued an urgent warning about a critical zero-day vulnerability in Google Chrome that attackers are actively exploiting in the wild.
The vulnerability, designated CVE-2025-6554, affects the Chromium V8 JavaScript engine and has been added to CISA's Known Exploited...
Summary
1. A threat actor is selling an unpatched exploit targeting Intelbras routers on hacker forums for 2 BTC, claiming it affects approximately 30,000 devices.
2. The exploit allegedly allows attackers to gain remote access or full control of affected routers...
A sophisticated attack campaign exploiting a Google Chrome zero-day vulnerability tracked as CVE-2025-2783, marking yet another instance of advanced persistent threat (APT) groups leveraging previously unknown security flaws to compromise high-value targets.
The vulnerability, which enables sandbox escape capabilities, has...
A critical zero-day vulnerability affecting Windows systems that allows attackers to achieve privilege escalation through a novel Reflective Kerberos Relay Attack.
The vulnerability, designated CVE-2025-33073, was patched by Microsoft on June 10, 2025, as part of their monthly Patch Tuesday...
A critical zero-day vulnerability discovered in Salesforce's default controller has exposed millions of user records across thousands of deployments worldwide.
The security flaw, found in the built-in aura://CsvDataImportResourceFamilyController/ACTION$getCsvAutoMap controller, allowed attackers to extract sensitive user information and document details through...
Significant vulnerabilities were uncovered in Versa Concerto, a widely deployed SD-WAN orchestration platform used by major enterprises and government entities.
The flaws include authentication bypass vulnerabilities that can be chained to achieve remote code execution and complete system compromise.
Despite responsible...