Zero-Day Security News
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
A zero-day is a vulnerability being exploited in the wild before the vendor has shipped — or sometimes even known about — a fix, leaving defenders with no patch to apply. This feed tracks zero-day disclosures and in-the-wild exploitation as they are reported, along with the emergency patches that typically follow. These are the highest-urgency items in the feed: attackers already have working exploits by the time most zero-days go public.
Recent Zero-Day items
Other topics
CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.