BTC$85,190+0.77% LTC$69.87+3.93% XMR$543.25+0.03%
TorPortal TorPortalMarkets, mirrors, dark web news
News › Topic

News tagged Zero-day

Every TorPortal story that mentions Zero-day. 60 stories, newest first. Category: topic.

Latest coverage of Zero-day

Click a headline for the full story or jump to the original.

Dell asks admins to patch max severity CSM flaws as soon as possible
BleepingComputer · Oct 2, 2026 · 2 min read

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
BleepingComputer · Oct 1, 2026 · 4 min read

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
Microsoft says threat actors are ahead in the early AI race
BleepingComputer · Oct 1, 2026 · 3 min read

Microsoft says threat actors are ahead in the early AI race

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams…
Kiteworks patches max severity code injection vulnerability
BleepingComputer · Oct 1, 2026 · 2 min read

Kiteworks patches max severity code injection vulnerability

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution.
Hackers stole Pentagon personnel records of over 3 million people
BleepingComputer · Oct 1, 2026 · 2 min read

Hackers stole Pentagon personnel records of over 3 million people

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025.
DIVD says Zammad zero-days enabled AI-driven network breach
BleepingComputer · Sep 30, 2026 · 2 min read

DIVD says Zammad zero-days enabled AI-driven network breach

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
Cisco warns of new SD-WAN zero-day exploited in attacks
BleepingComputer · Sep 30, 2026 · 2 min read

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
Bitget hacked via zero-day in third-party security products
BleepingComputer · Sep 30, 2026 · 2 min read

Bitget hacked via zero-day in third-party security products

Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products.
FBI tells ShinyHunters members to turn themselves in after recent arrest
BleepingComputer · Sep 29, 2026 · 3 min read

FBI tells ShinyHunters members to turn themselves in after recent arrest

The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders.
Hackers exploit Citrix NetScaler zero-day to deploy web shells
BleepingComputer · Sep 29, 2026 · 5 min read

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
Kiteworks patches critical flaw, brings customer systems online
BleepingComputer · Sep 29, 2026 · 2 min read

Kiteworks patches critical flaw, brings customer systems online

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.
Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer · Sep 29, 2026 · 2 min read

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
The Record · Sep 28, 2026 · 3 min read

ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns

A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
US, UK warn of exploited Citrix NetScaler zero-day bugs
The Record · Sep 28, 2026 · 2 min read

US, UK warn of exploited Citrix NetScaler zero-day bugs

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix…
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Krebs on Security · Sep 28, 2026 · 10 min read

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest…
CISA orders feds to patch exploited Citrix flaws by Wednesday
BleepingComputer · Sep 28, 2026 · 3 min read

CISA orders feds to patch exploited Citrix flaws by Wednesday

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
Citrix confirms two NetScaler RCE zero-days exploited in attacks
BleepingComputer · Sep 27, 2026 · 4 min read

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
BleepingComputer · Sep 26, 2026 · 4 min read

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on…
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
BleepingComputer · Sep 25, 2026 · 3 min read

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
The Record · Sep 25, 2026 · 2 min read

Kiteworks urges customers to stop using platform after warning from federal intelligence agencies

Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for…
Hackers now exploit critical Roundcube flaw in code injection attacks
BleepingComputer · Sep 24, 2026 · 2 min read

Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
ShinyHunters Claims FBI Breach, Data Stolen
DarkDotWeb · Sep 24, 2026 · 5 min read

ShinyHunters Claims FBI Breach, Data Stolen

ShinyHunters claims it breached the FBI and stole sensitive data, while the bureau investigates a confirmed compromise of its jobs portal.
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
BleepingComputer · Sep 23, 2026 · 2 min read

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
Arista patches actively exploited VeloCloud Orchestrator zero-day
BleepingComputer · Sep 23, 2026 · 2 min read

Arista patches actively exploited VeloCloud Orchestrator zero-day

Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
BleepingComputer · Sep 23, 2026 · 2 min read

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks.
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
BleepingComputer · Sep 22, 2026 · 5 min read

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
Check Point warns of Management Server zero-day exploited in attacks
BleepingComputer · Sep 22, 2026 · 2 min read

Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
D-Link warns of max severity zero-day bug in DIR-822A routers
BleepingComputer · Sep 22, 2026 · 2 min read

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
New Windows Defender zero-day blocks Microsoft antivirus updates
BleepingComputer · Sep 22, 2026 · 2 min read

New Windows Defender zero-day blocks Microsoft antivirus updates

Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
CISA orders feds to patch Zyxel flaw exploited for data theft
BleepingComputer · Sep 22, 2026 · 3 min read

CISA orders feds to patch Zyxel flaw exploited for data theft

​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
ShinyHunters Hijacks Clop Dark Web Leak Site
DarkDotWeb · Sep 22, 2026 · 3 min read

ShinyHunters Hijacks Clop Dark Web Leak Site

ShinyHunters defaced Clop's dark web leak site and demanded an eight-figure payment while threatening to expose the ransomware group.
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
BleepingComputer · Sep 19, 2026 · 5 min read

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
New Check Point flaw lets hackers execute code with root privileges
BleepingComputer · Sep 18, 2026 · 2 min read

New Check Point flaw lets hackers execute code with root privileges

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.
Cisco warns of max severity ISE zero-day exploited in attacks
BleepingComputer · Sep 17, 2026 · 1 min read

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild.
Google fixes actively exploited Android zero-day on Pixel devices
BleepingComputer · Sep 16, 2026 · 2 min read

Google fixes actively exploited Android zero-day on Pixel devices

Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.
What Zero-Day Response Should Be in the Post-Mythos Era
BleepingComputer · Sep 15, 2026 · 1 min read

What Zero-Day Response Should Be in the Post-Mythos Era

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous…
China spy chief points at US AI models in cyber threat warning
The Record · Sep 15, 2026 · 3 min read

China spy chief points at US AI models in cyber threat warning

China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and…
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
BleepingComputer · Sep 15, 2026 · 1 min read

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.
Cisco patches Secure Email Gateway zero-day exploited in attacks
BleepingComputer · Sep 15, 2026 · 1 min read

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
BleepingComputer · Sep 14, 2026 · 2 min read

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.
Anthropic caught Russia-linked spies using Claude in hacking operations
The Record · Sep 11, 2026 · 4 min read

Anthropic caught Russia-linked spies using Claude in hacking operations

Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
BleepingComputer · Sep 11, 2026 · 1 min read

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
BleepingComputer · Sep 10, 2026 · 1 min read

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
Trezor warns users of email provider breach, phishing attacks
BleepingComputer · Sep 10, 2026 · 2 min read

Trezor warns users of email provider breach, phishing attacks

Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks.
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
The Record · Sep 9, 2026 · 5 min read

Multiple Chinese hacking groups seen using identical Chrome zero-day exploit

A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.
New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
BleepingComputer · Sep 9, 2026 · 1 min read

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates.
Google warns of new Chrome zero-day bug exploited in attacks
BleepingComputer · Sep 9, 2026 · 1 min read

Google warns of new Chrome zero-day bug exploited in attacks

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
Microsoft Plugs Nearly 1,000 Security Holes
Krebs on Security · Sep 8, 2026 · 3 min read

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the…
Microsoft releases Windows 10 KB5122878 extended security update
BleepingComputer · Sep 8, 2026 · 1 min read

Microsoft releases Windows 10 KB5122878 extended security update

Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes.
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
BleepingComputer · Sep 8, 2026 · 1 min read

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
OpenAI says ChatGPT outage causes image generation errors
BleepingComputer · Sep 8, 2026 · 1 min read

OpenAI says ChatGPT outage causes image generation errors

OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files.
OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor
BleepingComputer · Sep 8, 2026 · 1 min read

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities.
Adobe fixes critical Magento zero-day exploited to backdoor servers
BleepingComputer · Sep 8, 2026 · 1 min read

Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.
Hackers build AI frameworks for widescale credential theft
BleepingComputer · Sep 8, 2026 · 1 min read

Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack.
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
BleepingComputer · Sep 7, 2026 · 2 min read

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
Mathspace discloses data breach affecting over 1 million people
BleepingComputer · Sep 7, 2026 · 3 min read

Mathspace discloses data breach affecting over 1 million people

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system.
Trezor data breach impact now reaches 81,000 customers
BleepingComputer · Sep 7, 2026 · 1 min read

Trezor data breach impact now reaches 81,000 customers

Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.
N-able patches max severity N-central flaw amid ongoing attacks
BleepingComputer · Sep 7, 2026 · 1 min read

N-able patches max severity N-central flaw amid ongoing attacks

N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform.
Attackers Hijack MikroTik Routers Through RouterOS Flaws
DarkDotWeb · Sep 7, 2026 · 3 min read

Attackers Hijack MikroTik Routers Through RouterOS Flaws

Attackers are exploiting MikroTik RouterOS flaws to take full control of internet-exposed routers through SSH without authentication.
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
BleepingComputer · Sep 4, 2026 · 2 min read

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems.

← All news