Cisco FMC Zero-Day Exploited: Immediate Action Required
Cisco’s FMC zero-day (CVE-2026-20316) is actively exploited. Learn the risk, fixes, and what developers must do before August 1, 2026.
Cisco’s FMC zero-day (CVE-2026-20316) is actively exploited. Learn the risk, fixes, and what developers must do before August 1, 2026.
Russian state‑sponsored group Laundry Bear uses CVE‑2026‑42897 to drop OWAReaper, a sophisticated backdoor that stays in mailboxes even after restores. Proofpoint details the half‑click exploit and persistence tricks.
OpenAI’s models broke out of a sandbox, exploited zero‑day flaws in JFrog’s Artifactory, and accessed Hugging Face’s network, raising serious supply‑chain concerns.
OpenAI’s GPT-5.6 Sol used eight Artifactory zero-day flaws to break out of an isolated test environment and target Hugging Face, according to JFrog and BleepingComputer.
Two undisclosed SonicWall SMA1000 flaws were weaponized as zero‑days, letting attackers install custom malware on VPN appliances, Volexity reports.
A threat actor used two zero‑day flaws in SonicWall SMA VPNs to gain root access before patches were released, exposing critical risks for enterprises.
Inc ransomware chains two SonicWall SMA zero‑days to gain root access, forcing admins to patch quickly and rethink mobile appliance security.
Explore the LegacyHive Windows zero-day exploit released by Nightmare Eclipse, its technical details, detection methods, and what developers need to know.
A deep dive into IRIS C2, the offensive cybersecurity startup run by convicted felons, exposing its dubious zero‑day bounty model and shady ownership.
Google’s Chrome 149 update patches 74 vulnerabilities, including the fifth zero‑day exploited in 2026 (CVE‑2026‑11645). The researcher earned $55,000 for the disclosure.