Tag
#Zero-Day Exploit
Unpatched Magento Zero-Day Exploited: Understanding the StyleSmuggler Threat
Attackers are exploiting a zero-day remote code execution flaw in Adobe Commerce and Magento Open Source, known as StyleSmuggler, to install persistent backdoors on e-commerce sites. This vulnerability is particularly concerning as it affects a large share of mid-market online retail and has been exploited in the wild since September 4, 2026, with no vendor fix available as of September 6, 2026.
CrowdStrike Privilege Escalation Zero-Day Exploit Published
A security researcher has published a zero-day exploit for CrowdStrike, potentially allowing hackers to escalate privileges. This vulnerability is actively exploited, posing a significant risk to affected systems. Immediate action is required to mitigate this threat.
Attackers Exploit PaperCut Zero-Days to Deploy Remote Access Tools
Threat actors are actively exploiting internet-facing PaperCut Application Servers to covertly install legitimate remote access software. PaperCut NG and MF print management solutions are affected, and customers are urged to restrict web access to trusted IP addresses only. This campaign is rated highly severe due to the potential for remote code execution and lateral movement.
Lazarus APT Group Exploits Windows Zero-Day Using Post-Quantum Key Exchange
The Lazarus APT group has been actively exploiting a Windows zero-day vulnerability using a novel approach involving post-quantum key exchange to deliver the exploit. This campaign is currently being actively exploited in the wild. Security professionals should prioritize patching and implement enhanced monitoring to detect this threat.
Understanding the Oracle EBS Zero-Day Exploit: A Deep Dive
This analysis explores the Oracle EBS zero-day exploit used to exfiltrate sensitive information from Estée Lauder in August 2025. We will delve into the vulnerability, exploitation mechanics, real-world impact, and defensive strategies to mitigate such attacks.