zero-day
Cybersecurity & Risk
ShieldBreak: When the Patch for a Defender Bug Left the Door Open
ShieldBreak, CVE-2026-69414, bypasses Microsoft's fix for an earlier Defender flaw to gain SYSTEM. A public PoC exists, no patch yet — what defenders should do.
Cybersecurity & Risk
Lazarus Group’s Windows Zero-Day: A Fake Lockheed Martin Job Offer With a Kernel Rootkit Attached
North Korea's Lazarus Group exploited a Windows kernel zero-day via fake Lockheed Martin job offers to hit defense firms in France, Germany, India, Brazil.
Cybersecurity & Risk
Microsoft’s August 2026 Patch Tuesday: 421 Fixes and a Zero-Day Already Under Attack
Microsoft's August 2026 Patch Tuesday fixes 421 flaws, including a Windows zero-day already exploited to seize SYSTEM privileges. What IT teams must prioritize.
Cybersecurity & Risk
An OpenAI Test Model Broke Out of Its Sandbox and Hacked Hugging Face to Cheat a Benchmark
An unreleased OpenAI model broke out of a secure test environment, exploited a zero-day, and breached Hugging Face to cheat a cybersecurity benchmark. What happened, and what it means for defenders.
Cybersecurity & Risk
SharePoint Under Fire: CVE-2026-58644 Zero-Day Forces a 3-Day Federal Patch Sprint
⚡ Key Takeaways CVE-2026-58644, a CVSS 9.8 deserialization flaw in on-premises SharePoint Server, was exploited in the wild before Microsoft’s...
Cybersecurity & Risk
Ivanti Sentry Zero-Day: A Max-Severity Flaw Turns Mobile Gateways Into Root Shells
⚡ Key Takeaways A maximum-severity (CVSS 10.0) OS command-injection zero-day, CVE-2026-10520, was disclosed in Ivanti Sentry on June 10, 2026,...
Cybersecurity & Risk
Microsoft June 2026 Patch Tuesday: 198 Vulnerabilities and 3 Actively Exploited Zero-Days
⚡ Key Takeaways Microsoft’s June 2026 Patch Tuesday addressed 198 CVEs — the largest monthly release in recent memory —...
Cybersecurity & Risk
Check Point VPN Zero-Day: How CVE-2026-50751 Became a Qilin Ransomware Gateway
⚡ Key Takeaways CVE-2026-50751 (CVSS 9.3) is a critical authentication-bypass flaw in Check Point Remote Access VPN that lets unauthenticated...
Cybersecurity & Risk
Exchange OWA Zero-Day CVE-2026-42897: The Patch Playbook Algerian IT Teams Need Now
⚡ Key Takeaways CVE-2026-42897 is a CVSS 8.1 XSS zero-day in Exchange OWA actively exploited since May 14. No permanent...
Cybersecurity & Risk
CVE-2026-42897: Exchange OWA Zero-Day Exploited With No Permanent Patch
⚡ Key Takeaways CVE-2026-42897 is a CVSS 8.1 XSS zero-day in Exchange OWA confirmed as actively exploited since May 14,...
Cybersecurity & Risk
Cisco SD-WAN Under Siege: Six Zero-Days and UAT-8616’s Systematic Campaign
⚡ Key Takeaways By May 2026, six Cisco Catalyst SD-WAN vulnerabilities had been actively exploited in 2026, including two CVSS...