vulnerability Google patches new Chrome zero-day flaw exploited in the wild Google has released a security update to address a newly discovered and actively exploited zero-day vulnerability (CVE-2026-11645) within the Chrome browser. This flaw, originating in the V8 JavaScript engine, allows att… BleepingComputer · Jun 9, 2026 High CVE-2026-11645CVE-2024-0519CVE-2026-2441zero-daychromev8
vulnerability Check Point VPN Flaw Exploited Since Early May A critical zero-day vulnerability (CVE-2026-50751) in Check Point's Security Gateways and Spark Firewalls has been exploited since early May by a Qilin ransomware affiliate. The flaw, involving a logic flaw in certificat… Dark Reading · Jun 8, 2026 Critical CVE-2026-50751CVE-2026-50752zero-dayikev1vpn
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
vulnerability Check Point links VPN zero-day attacks to Qilin ransomware gang Check Point identified a zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments, exploited by the Qilin ransomware gang. The flaw allowed unauthenticated attackers to bypass authen… BleepingComputer · Jun 8, 2026 High CVE-2026-50751CVE-2026-50752ISJAAUzero-dayvpnauthentication
threat-intel AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs This article details a significant surge in vulnerability discovery, driven largely by autonomous AI agents. Depthfirst identified 21 zero-days in FFmpeg using their AI agent, while Google patched 429 bugs in Chrome 149,… The Hacker News · Jun 6, 2026 High CVE-2026-39210CVE-2026-39218CVE-2026-10881USaivulnerabilityzero-day
vulnerability Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available A high-severity vulnerability, CVE-2026-20245, in Cisco Catalyst SD-WAN Manager has been actively exploited by threat actors. The flaw, stemming from insufficient input validation, allows authenticated attackers to execu… The Hacker News · Jun 6, 2026 Critical CVE-2026-20245CVE-2026-20182CVE-2026-20127sd-wancvezero-day
threat-intel Exposed Fuel Tank Gauges Under Attack in the US Internet-exposed fuel tank gauges in the United States are being targeted by cyberattacks, posing a significant risk to gas stations and industrial facilities. The Cybersecurity and Infrastructure Security Agency (CISA)… Dark Reading · Jun 5, 2026 High USCAAUindustrial control systemscybersecuritytank gauges
vulnerability Cisco warns of unpatched SD-WAN zero-day exploited in attacks Cisco has issued a warning about a previously unknown zero-day vulnerability (CVE-2026-20245) in its Cisco Catalyst SD-WAN Manager software, which is being actively exploited to gain root privileges. The flaw, stemming f… BleepingComputer · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daysd-wanroot privilege
vulnerability Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 Cisco has issued a security advisory regarding a newly discovered zero-day vulnerability (CVE-2026-20245) within its SD-WAN Manager product. This vulnerability, exploitable via command injection, has been actively used b… SecurityWeek · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daycommand injectionsd-wan
vulnerability Acer working to patch max severity zero-days in Wave 7 routers Acer has confirmed the existence of two critical zero-day vulnerabilities in its Wave 7 mesh routers, reported by security researcher Gergo Pap. These flaws, CVE-2026-49200 and CVE-2026-49201, allow unauthorized access t… BleepingComputer · Jun 3, 2026 Critical CVE-2026-49200CVE-2026-49201zero-daymesh routercredentials
threat-intel Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash This article reports on a controversy between Microsoft and a security researcher, known as Nightmare Eclipse, regarding the disclosure of several zero-day vulnerabilities affecting Microsoft products. Microsoft initiall… SecurityWeek · Jun 3, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825USzero-dayvulnerability disclosurelegal action
vulnerability VS Code zero-day lets hackers steal GitHub tokens in one click A researcher, Ammar Askar, has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. The vulne… BleepingComputer · Jun 3, 2026 High zero-daygithubvscode
threat-intel The Zero-Knowledge Threat Actor and the End of Responsible Disclosure This article discusses the rise of ‘zero-knowledge’ threat actors, empowered by AI, who pose a significant new challenge to cybersecurity. These actors, lacking deep technical expertise, can rapidly discover and exploit… SecurityWeek · Jun 2, 2026 High aivulnerabilityphishing
vulnerability Google fixes one actively exploited Android zero-day, 124 flaws Google has released a significant security update addressing 124 vulnerabilities in Android, including a previously exploited zero-day vulnerability (CVE-2025-48595). This update focuses on mitigating targeted attacks an… BleepingComputer · Jun 2, 2026 High CVE-2025-48595CVE-2025-48633CVE-2025-48572zero-dayandroidvulnerability
threat-intel Microsoft's Zero-Day Legal Threats Spark Backlash This article reports on Microsoft's controversial response to a security researcher, "Nightmare-Eclipse," who published several zero-day exploits. Microsoft initially threatened criminal charges against the researcher an… Dark Reading · Jun 1, 2026 High CVE-2026-33825zero-dayvulnerabilityresearcher
threat-intel Microsoft says it will not pursue security researchers after zero-day backlash Microsoft retracted a controversial blog post condemning security researchers who disclose zero-day vulnerabilities, stating it has no intention to pursue legal action against them. The initial statement, perceived as a… The Record · Jun 1, 2026 Medium UKzero-dayvulnerabilityresponsible disclosure
threat-intel Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more Microsoft is responding to a weeks-long campaign by a pseudonymous researcher, ‘Nightmare Eclipse,’ who released uncoordinated zero-day vulnerabilities in Windows. The researcher, motivated by grievances against Microsof… The Record · May 29, 2026 High zero-dayvulnerabilitydisclosure
vulnerability Gogs Zero-Day Exposes Servers to Remote Code Execution A critical zero-day vulnerability has been discovered in the open-source self-hosted Git service, Gogs, allowing for remote code execution (RCE) on affected servers. The flaw, identified by Rapid7, stems from an argument… SecurityWeek · May 29, 2026 Critical CVE-2025-8110zero-dayremote code executiongit
threat-intel This month in security with Tony Anscombe – May 2026 edition In May 2026, Poland experienced cyberattacks targeting industrial control systems at water treatment facilities, mirroring attacks against the Polish energy sector. Simultaneously, a previously unknown group conducted a… WeLiveSecurity · May 29, 2026 Medium PLicscyberattacksai