Cisco warned customers on Monday that a zero-day vulnerability affecting Secure Email Gateway appliances has been exploited in the wild. The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco describes it as an email parsing… Read More "Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation"
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to… Read More "BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days"
N-able Patches Critical Zero-Day in N-central
IT software firm N-able has rolled out an urgent fix for an unauthenticated remote code execution (RCE) vulnerability in its N-central endpoint management platform that has been exploited as a zero-day. Tracked as CVE-2026-86218 (CVSS score of 10/10), the security… Read More "N-able Patches Critical Zero-Day in N-central"
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits… Read More "Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits"
Google Patches 6th Chrome Zero-Day of 2026
https://www.securityweek.com/wp-content/uploads/2024/06/Chrome.jpeg Google on Thursday rolled out fresh Chrome 152 security updates that resolve 12 vulnerabilities, including an exploited zero-day. Tracked as CVE-2026-85046, the high-severity bug is described as a type confusion issue in Chrome’s V8 JavaScript and WebAssembly engine. It… Read More "Google Patches 6th Chrome Zero-Day of 2026"
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
https://www.securityweek.com/wp-content/uploads/2025/08/SonicWall.jpg SonicWall is urging customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance to patch two new zero-day vulnerabilities that have been exploited in the wild. According to an advisory published by SonicWall on Tuesday, the vulnerabilities… Read More "SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks"
PaperCut Exploitation Escalates to Active Intrusions
https://www.securityweek.com/wp-content/uploads/2026/08/PaperCut-print-management.jpeg Attacks exploiting two recently discovered PaperCut NG/MF vulnerabilities have escalated, with threat actors shifting from reconnaissance to hands-on-keyboard activity. PaperCut first warned users of its NG and MF print management solutions about an actively exploited zero-day vulnerability on August… Read More "PaperCut Exploitation Escalates to Active Intrusions"
Hardening Tier-0 Management Planes: Lessons from the Cisco Secure FMC Zero-Day (CVE-2026-20316)
Centralized management consoles serve as the nerve center for enterprise network security. When a management plane is compromised, threat actors gain full visibility into firewall configurations, routing tables, and access control policies across the entire corporate infrastructure. The Cybersecurity and… Read More "Hardening Tier-0 Management Planes: Lessons from the Cisco Secure FMC Zero-Day (CVE-2026-20316)"