Tag
A critical PeopleSoft zero-day vulnerability is being actively exploited by the ShinyHunters group, compromising hundreds of organizations and stealing gigabytes of data, including 48GB from a single victim.
Microsoft's June 2026 Patch Tuesday sets a record with nearly 200 security fixes, including three publicly exploited zero-days. AI tools are increasingly used to find bugs, with security researchers like Nightmare Eclipse releasing exploits.
Microsoft fixed a 0-day vulnerability disclosed by researcher Nightmare Eclipse amid a heated rivalry, alongside other vulnerabilities like MiniPlasma, YellowKey, and others. The researcher published exploit code for a new Windows Defender vulnerability.
An autonomous AI agent from depthfirst discovered 21 zero-day vulnerabilities in FFmpeg, including a network-reachable RCE via a single 183-byte packet, for only $1,000 in compute costs; the find highlights the disparity between automated bug finding and patching.
Anthropic has embedded about six engineers inside the NSA to deploy its Mythos cyber model for offensive operations, despite publicly calling the model too dangerous to release and suing the Pentagon over military AI use.
Microsoft is facing backlash for threatening legal action against a security researcher who publicly posted zero-day exploits, with critics highlighting the company's inconsistent history with vulnerability disclosure.
A security researcher published six unpatched Windows zero-day vulnerabilities, including working exploit code, without Microsoft's knowledge. Microsoft threatened legal action and criminal referrals, drawing widespread criticism from the cybersecurity community over its handling of the situation.
A disgruntled security researcher known as Nightmare Eclipse has escalated a feud with Microsoft by threatening to dump more Windows zero-day exploits, after already releasing six. Microsoft has responded with a blog post and legal threats.
Microsoft's GitHub banned security researcher Nightmare-Eclipse after they posted zero-day Windows exploits. The researcher claims retaliation and promises further disclosure.
A security researcher released a zero-day exploit called YellowKey that bypasses Microsoft BitLocker encryption on Windows 11 and Windows Server 2022/2025, allowing full access to locked drives using a USB stick; the exploit appears to operate as a backdoor, with files disappearing after use.
An anonymous researcher released two Microsoft zero-day exploits, YellowKey (BitLocker bypass) and GreenPlasma (privilege escalation), after Patch Tuesday, posing serious security risks for organizations.
Google's Threat Intelligence Group reports that hackers are using AI-generated code to discover and weaponize a zero-day vulnerability that could bypass two-factor authentication, marking a notable escalation in AI-driven cybercrime.
OpenAI launches Daybreak, a cybersecurity initiative for enterprises, as Google reveals the first known case of hackers using AI to develop zero-day exploits.
Google's Threat Intelligence Group reports its first discovery of an AI-generated zero-day exploit intended for mass exploitation, highlighting a growing trend of adversaries using AI for malware development, defense evasion, and autonomous cyberattacks.
CVE-2026-31431 (Copy Fail) is a local privilege escalation vulnerability in the Linux kernel affecting all major distributions since 2017, allowing unprivileged users to gain root shell access through a deterministic 4-byte write to any readable file's page cache via the AF_ALG crypto subsystem.
A report titled 'Dirty Frag' details a universal Linux Local Privilege Escalation (LPE) vulnerability that allows root access on major distributions by chaining two kernel bugs. The disclosure notes that due to a broken embargo, no patches currently exist for this critical security issue.
Mozilla used Anthropic's Claude Mythos Preview AI to find and fix 271 zero-day vulnerabilities in Firefox 150, marking a major shift in cybersecurity where AI enables defenders to decisively outpace attackers.
Online discussion speculates on AI-driven discovery of unpatchable zero-day vulnerabilities and the inadequacy of air-gapped systems for protection.
Microsoft's April 2026 Patch Tuesday fixes a record 167 vulnerabilities, including an actively exploited SharePoint zero-day and a publicly disclosed Windows Defender bug (BlueHammer), while Google Chrome and Adobe Reader also addressed zero-days.