BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
News › Topic

News tagged Zero-day

Every TorPortal story that mentions Zero-day. 60 stories, newest first. Category: topic.

Latest coverage of Zero-day

Click a headline for the full story or jump to the original.

RingCentral data breach exposed info of 1.6 million accounts
BleepingComputer · Aug 14, 2026 · 2 min read

RingCentral data breach exposed info of 1.6 million accounts

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.
Microsoft patches LegacyHive Windows zero-day vulnerability
BleepingComputer · Aug 13, 2026 · 1 min read

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
Lazarus hackers exploited Windows zero-day to target defense firms
BleepingComputer · Aug 12, 2026 · 1 min read

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
The Record · Aug 12, 2026 · 3 min read

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
BleepingComputer · Aug 12, 2026 · 1 min read

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates.
Microsoft Plugs Nearly 400 Security Holes
Krebs on Security · Aug 11, 2026 · 4 min read

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly…
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
BleepingComputer · Aug 11, 2026 · 1 min read

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
BleepingComputer · Aug 11, 2026 · 1 min read

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
New StormEncryptor ransomware used by former Medusa affiliate
BleepingComputer · Aug 10, 2026 · 1 min read

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
BleepingComputer · Aug 10, 2026 · 2 min read

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
The Record · Aug 10, 2026 · 3 min read

China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns

A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.
LexisNexis shuts down services after suspicious activity on servers
BleepingComputer · Aug 10, 2026 · 1 min read

LexisNexis shuts down services after suspicious activity on servers

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor.
Critical Progress LoadMaster flaw now actively exploited in attacks
BleepingComputer · Aug 10, 2026 · 1 min read

Critical Progress LoadMaster flaw now actively exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.
Hackers breach TrueConf to trojanize client installers with backdoors
BleepingComputer · Aug 8, 2026 · 1 min read

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.
Metabase SQLi zero-day exploited in customer data-theft attacks
BleepingComputer · Aug 7, 2026 · 1 min read

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally.
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
BleepingComputer · Aug 4, 2026 · 1 min read

OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people…
New XCSSET variant targets macOS devs via compromised Xcode projects
BleepingComputer · Aug 4, 2026 · 1 min read

New XCSSET variant targets macOS devs via compromised Xcode projects

A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.
N-able warns of N-central auth bypass flaw exploited in attacks
BleepingComputer · Aug 3, 2026 · 1 min read

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.
Anthropic says its AI hacked real-world companies in three incidents
The Record · Jul 31, 2026 · 5 min read

Anthropic says its AI hacked real-world companies in three incidents

Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
BleepingComputer · Jul 29, 2026 · 1 min read

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
Cisco warns of FMC static credential flaw exploited in zero-day attacks
BleepingComputer · Jul 29, 2026 · 1 min read

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices.
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
BleepingComputer · Jul 29, 2026 · 1 min read

OpenAI agent used exposed credentials at 4 services in Hugging Face breach

In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other…
Laundry Bear’s webmail hackers had more in store after February, report says
The Record · Jul 29, 2026 · 2 min read

Laundry Bear’s webmail hackers had more in store after February, report says

Researchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.
OpenAI models used Artifactory zero-days to escape to the internet
BleepingComputer · Jul 28, 2026 · 1 min read

OpenAI models used Artifactory zero-days to escape to the internet

JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face.
Hackers target US firms in FastJson RCE zero-day attacks
BleepingComputer · Jul 27, 2026 · 1 min read

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
BleepingComputer · Jul 27, 2026 · 1 min read

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
Hermes AI agent used to automate attack on Thai Finance Ministry
BleepingComputer · Jul 24, 2026 · 1 min read

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance.
Clop ransomware targets Windchill, FlexPLM in data theft attacks
BleepingComputer · Jul 24, 2026 · 1 min read

Clop ransomware targets Windchill, FlexPLM in data theft attacks

The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Russian hackers exploit Zimbra zero-click flaw for email theft
BleepingComputer · Jul 23, 2026 · 1 min read

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a…
Check Point warns of SmartConsole zero-day exploited in attacks
BleepingComputer · Jul 23, 2026 · 1 min read

Check Point warns of SmartConsole zero-day exploited in attacks

Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
OpenAI models behind breach of Hugging Face systems, companies say
The Record · Jul 22, 2026 · 2 min read

OpenAI models behind breach of Hugging Face systems, companies say

OpenAI announced that its models were behind a breach of the AI platform Hugging Face, which had earlier detected an attack carried out by "by an autonomous AI agent."
OpenAI says its AI models hacked Hugging Face during testing
BleepingComputer · Jul 22, 2026 · 1 min read

OpenAI says its AI models hacked Hugging Face during testing

OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment.
Windows LegacyHive zero-day flaw gets free, unofficial patches
BleepingComputer · Jul 21, 2026 · 1 min read

Windows LegacyHive zero-day flaw gets free, unofficial patches

Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
Estée Lauder discloses data breach via Oracle E-Business flaw
BleepingComputer · Jul 20, 2026 · 1 min read

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying employees of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations.
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
BleepingComputer · Jul 20, 2026 · 1 min read

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Hackers were inside South Korea's diplomat training system for 9 months
The Record · Jul 20, 2026 · 2 min read

Hackers were inside South Korea's diplomat training system for 9 months

Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs.
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
BleepingComputer · Jul 18, 2026 · 1 min read

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
New Windows LegacyHive zero-day gives hackers admin privileges
BleepingComputer · Jul 17, 2026 · 1 min read

New Windows LegacyHive zero-day gives hackers admin privileges

A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.
We built a vulnerability vending machine: AI tokens in, zero-days out
BleepingComputer · Jul 15, 2026 · 1 min read

We built a vulnerability vending machine: AI tokens in, zero-days out

Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown…
Microsoft smashes Patch Tuesday record for second successive month
The Record · Jul 15, 2026 · 4 min read

Microsoft smashes Patch Tuesday record for second successive month

Vulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months combined.
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
BleepingComputer · Jul 14, 2026 · 1 min read

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates.
Krebs on Security · Jul 14, 2026 · 4 min read

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch…
Microsoft releases Windows 10 KB5099539 extended security update
BleepingComputer · Jul 14, 2026 · 1 min read

Microsoft releases Windows 10 KB5099539 extended security update

Microsoft has released the Windows 10 KB5099539 extended security update, which includes this month's record-breaking July 2026 Patch Tuesday fixes, along with additional security improvements.
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
BleepingComputer · Jul 14, 2026 · 1 min read

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

Today is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed.
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
BleepingComputer · Jul 14, 2026 · 1 min read

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw.
You Don't Have to Run an Exploit to Know If You're Vulnerable
BleepingComputer · Jul 14, 2026 · 1 min read

You Don't Have to Run an Exploit to Know If You're Vulnerable

Many vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by…
Microsoft Details Year-Long ShinyHunters Campaign
DarkDotWeb · Jul 14, 2026 · 2 min read

Microsoft Details Year-Long ShinyHunters Campaign

Microsoft reveals how ShinyHunters spent a year targeting organizations with phishing, social engineering and cloud attacks.
CISA warns of actively exploited RCE flaws in Joomla extensions
BleepingComputer · Jul 13, 2026 · 1 min read

CISA warns of actively exploited RCE flaws in Joomla extensions

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file…
Police suspects Dutch hackers were involved in Odido breach
BleepingComputer · Jul 10, 2026 · 1 min read

Police suspects Dutch hackers were involved in Odido breach

The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido.
Progress urges ShareFile admins to shut down servers over “credible” threat
BleepingComputer · Jul 10, 2026 · 1 min read

Progress urges ShareFile admins to shut down servers over “credible” threat

Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-premises secure…
Zimbra urges customers to patch critical web client XSS flaw
BleepingComputer · Jul 10, 2026 · 1 min read

Zimbra urges customers to patch critical web client XSS flaw

The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite.
Microsoft expects more Windows security updates from AI-discovered flaws
BleepingComputer · Jul 9, 2026 · 1 min read

Microsoft expects more Windows security updates from AI-discovered flaws

Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase.
Microsoft patches RoguePlanet Defender zero-day vulnerability
BleepingComputer · Jul 9, 2026 · 1 min read

Microsoft patches RoguePlanet Defender zero-day vulnerability

Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday.
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Krebs on Security · Jul 8, 2026 · 6 min read

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake…
Telco giant KDDI says data breach affects over 12 million people
BleepingComputer · Jul 8, 2026 · 1 min read

Telco giant KDDI says data breach affects over 12 million people

Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country.
CISA orders feds to patch max severity ColdFusion flaw by Friday
BleepingComputer · Jul 8, 2026 · 1 min read

CISA orders feds to patch max severity ColdFusion flaw by Friday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday.
New Januscape Linux flaw allows VM escape on Intel, AMD devices
BleepingComputer · Jul 7, 2026 · 1 min read

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host.
FortiBleed credential-theft campaign linked to Lynx ransomware
BleepingComputer · Jul 1, 2026 · 3 min read

FortiBleed credential-theft campaign linked to Lynx ransomware

The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions.
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
BleepingComputer · Jun 30, 2026 · 1 min read

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks.
Nissan discloses employee data breach linked to Oracle zero-day attacks
BleepingComputer · Jun 29, 2026 · 1 min read

Nissan discloses employee data breach linked to Oracle zero-day attacks

Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group.

← All news