Thursday, October 8, 2026

Zero-Day

Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks

Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, a zero-day vulnerability in CoreGraphics that may have been exploited in sophisticated, targeted attacks against specific individuals. Apple's latest...

Kiteworks Urges Customers to Shut Down Servers Over Potential Zero-Day Threat

Kiteworks has lifted its emergency shutdown recommendation after advising customers to temporarily take their systems offline in response to credible intelligence indicating that a...

China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks

Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel privilege-escalation flaw to...

Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM

A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arbitrary file-read access...

Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks

Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known...

CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems

A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively...

Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities

Rapid7's Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This...

Cursor 0-Day Lets Attackers Execute Malicious Code by Opening a Repository

A recently disclosed security issue in Cursor IDE exposed a serious Windows binary-planting vulnerability that could allow malicious code to execute simply by opening...

OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains

OpenAI has expanded its Daybreak cybersecurity program with the introduction of GPT-5.6-Cyber, a purpose-trained model specifically designed for authorized vulnerability research, exploit validation, and...

Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials

Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58...

Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access

A critical zero-day vulnerability in Check Point SmartConsole, identified as CVE-2026-16232, has been actively exploited, allowing unauthenticated attackers to gain full administrative access to...