Zero-Day Security News
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
A zero-day is a vulnerability under active exploitation before the vendor has shipped, or even discovered, a fix, leaving defenders with nothing to patch against yet. Disclosures and in-the-wild exploitation show up here, along with the emergency patches that usually follow. These are the highest-urgency items in the feed: attackers already have working exploits by the time most zero-days go public.
Recent Zero-Day items
Other topics
CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.