Zero-Day Security News

Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.

A zero-day is a vulnerability being exploited in the wild before the vendor has shipped — or sometimes even known about — a fix, leaving defenders with no patch to apply. This feed tracks zero-day disclosures and in-the-wild exploitation as they are reported, along with the emergency patches that typically follow. These are the highest-urgency items in the feed: attackers already have working exploits by the time most zero-days go public.

Recent Zero-Day items

GeoServer Zero-Day SQL Injection Vulnerability Actively Exploited to Gain RCEhttps://gbhackers.com/geoserver-zero-day-sql-injection-vulnerability/
@PentestingNews · Aug 14, 2026
Hackers Exploiting Unpatched GeoServer Zero-Dayhttps://ift.tt/MajvHtg
@ctinow · Aug 14, 2026
Attackers are already probing an unpatched GeoServer zero-day.The SQL injection flaw drew hundreds of attempts within hours of disclosure and, under certain configurations, can lead to remote code exe…
@thehackernews · Aug 13, 2026
Microsoft patches LegacyHive Windows zero-day vulnerabilityhttps://ift.tt/t5CoRbA
@ctinow · Aug 13, 2026
CISA Adds Actively Exploited Windows WinSock Vulnerability to KEV Cataloghttps://gbhackers.com/cisa-adds-actively-exploited-windows-winsock-vulnerability/
@PentestingNews · Aug 13, 2026
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’https://ift.tt/OrwVhxB
@ctinow · Aug 13, 2026
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Jobhttps://ift.tt/9oD5fhS
@ctinow · Aug 13, 2026
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoorhttps://ift.tt/uMAjlCN
@ctinow · Aug 12, 2026
Lazarus-linked attacks exploit a Windows zero-day for SYSTEM access.Dream Job lures defense and aerospace targets with fake recruiter messages. One chain exploits CVE-2026-68820 for privilege escalati…
@thehackernews · Aug 12, 2026
ShieldBreak Windows Defender 0-Day Lets Attackers Bypass Microsoft Patch and Gain SYSTEM Privilegeshttps://gbhackers.com/shieldbreak-windows-defender-0-day/
@PentestingNews · Aug 12, 2026
Lazarus hackers exploited Windows zero-day to target defense firmshttps://ift.tt/StrUP6V
@ctinow · Aug 12, 2026
Three Adobe flaws hit CVSS 10.0 and could enable code execution.Adobe patched the maximum-severity bugs in ColdFusion and Campaign Classic, plus a CVSS 9.1 Commerce flaw that could allow privilege esc…
@thehackernews · Aug 12, 2026
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privilegeshttps://ift.tt/3DkZJFI
@ctinow · Aug 12, 2026
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patchhttps://securityaffairs.com/197063/hacking/shieldbreak-new-windows-zero-day-bypasses-microsofts-rogueplanet-patch.html
@PentestingNews · Aug 12, 2026
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patchhttps://ift.tt/3ZrSUMy
@ctinow · Aug 12, 2026
Fresh Windows Zero-Day Exploited in North Korean Cyberattackshttps://ift.tt/6pgh9Nr
@ctinow · Aug 12, 2026
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCEhttps://securityaffairs.com/197048/security/microsoft-patch-tuesday-for-august-2026-fixed-a-zero-day-and-wormable-rce.html
@PentestingNews · Aug 12, 2026
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCEhttps://ift.tt/AxyO2nV
@ctinow · Aug 12, 2026
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Accesshttps://ift.tt/vAFLfzS
@ctinow · Aug 12, 2026
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoShttps://ift.tt/nq4Uxm9
@ctinow · Aug 12, 2026
Microsoft Patch Tuesday Update August 2026 Fixes Actively Exploited Windows Zero-Dayhttps://gbhackers.com/microsoft-patch-tuesday-update-august-2026/
@PentestingNews · Aug 12, 2026
Microsoft patched RoguePlanet. Now the researcher has dropped another zero-day that claims to bypass the fix.ShieldBreak is said to fully bypass Defender’s CVE-2026-50656 patch. The underlying flaw ca…
@thehackernews · Aug 12, 2026
Cisco Patches Firewall Zero-Day Exploited for DoS Attackshttps://ift.tt/WgJzPT6
@ctinow · Aug 12, 2026
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attackhttps://ift.tt/Cvf0YVl
@ctinow · Aug 11, 2026
398 fixes. One exploited Windows zero-day. Four unauthenticated 9.8 RCEs.Microsoft’s August Patch Tuesday fixes CVE-2026-68820, which can elevate an attacker with existing code execution to SYSTEM.It…
@thehackernews · Aug 11, 2026
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Dayhttps://ift.tt/y6NRi04
@ctinow · Aug 11, 2026
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attackhttps://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/🎖@malwr
@malwr · Aug 11, 2026
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attackhttps://ift.tt/i4cAv0D
@ctinow · Aug 11, 2026
AI Genie in the Wildhttps://ift.tt/SDVAhke
@ctinow · Aug 11, 2026
OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chainshttps://gbhackers.com/openai-launches-gpt-5-6-cyber-to-find-zero-day-vulnerabilities/
@PentestingNews · Aug 11, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.