Posts Tagged ‘zero-day’
CVE-2026-68820 WinSock Zero-Day: Lazarus Deploys Rootkit
The CVE-2026-68820 WinSock zero-day was already being used by North Korea’s Lazarus Group to plant a kernel-mode rootkit weeks before Microsoft shipped a fix in its August 2026 Patch Tuesday. Any Windows endpoint that processes network sockets — which is to say, essentially every Windows machine on your network — was exposed until this month’s…
Read MoreMetabase CVSS 10 SQL Injection Zero-Day Hits Admin Access
The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…
Read MoreMicrosoft July 2026 Patch Tuesday Zero-Day Hits SharePoint
The Microsoft July 2026 Patch Tuesday zero-day count is the largest disclosure on record — trackers put the total at 570 to 622 CVEs depending on methodology — and two of the fixed flaws were already being exploited before the patch shipped: one in Active Directory Federation Services, one in SharePoint Server. A separate, publicly…
Read MoreTop 5 Cybersecurity News Stories April 3, 2026
This week’s Top 5 Cybersecurity News Stories April 3, are not a recap, they’re a strategic read of where risk is concentrating. From exploited zero-days and identity chokepoints to collaboration platforms, executive messaging, and ransomware pressure tactics, these signals show how attackers are gaining leverage faster than patch and governance cycles can keep up. Unifying…
Read MoreTop 5 Cybersecurity News Stories March 06, 2026
Cybersecurity threats evolve rapidly as threat actors target your data and funds. To keep you secure, we’ve scoured the web for the top 5 cybersecurity news stories March 06, 2026, no threat too big or small, from espionage to flaws in everyday devices. Cisco SD-WAN Exploited Silently for Three Years A critical authentication bypass flaw…
Read More
