Tech News
← Home  ·  All topics

Zero-Day

35 GoKawiil briefs on this topic

Microsoft ships record 974 security fixes in September Patch Tuesday

Microsoft released patches for 974 vulnerabilities across Windows and other products, its largest single update batch ever, surpassing July's record of 570 fixes. The release includes two actively exploited zero-day flaws that let attackers escalate privileges, plus 113 critical-rated bugs including a dangerous DNS weakness and a Windows Shell remote code execution flaw scoring 9.8 out of 10 in severity.

Microsoft's September Patch Tuesday Fixes Record 974 Vulnerabilities

Microsoft's September security update addressed 974 unique CVEs, the largest Patch Tuesday release yet, including two zero-day flaws already being actively exploited. Windows accounted for the vast majority of fixes at 723, with Office, SQL, SharePoint and Azure making up the rest, while 13 issues were rated Critical.

Microsoft's September patch fixes record 972 vulnerabilities, 112 critical

Microsoft released its September security update addressing roughly 972 vulnerabilities, including 112 rated critical, surpassing the previous record of 570 set just two months ago. The company has now fixed 2,760 vulnerabilities in 2024 alone, more than double last year's total and on pace to exceed the combined totals of the past three years.

Microsoft's September 2026 Patch Tuesday sets record with 966 fixes, two exploited zero-days

Microsoft's latest Patch Tuesday release addresses 966 vulnerabilities, its largest batch ever, including 105 rated Critical and two zero-days already being exploited in the wild. The count excludes 204 additional flaws Microsoft patched earlier in the month across products like Azure AI Language, Copilot Studio, and Entra ID.

OpenAI classifies GPT-6 Astra at 'Critical' cybersecurity risk level

OpenAI disclosed that its newly deployed GPT-6 Astra model is the first widely released system to hit the 'Critical' threshold in the company's Preparedness Framework for cybersecurity, meaning it can autonomously find and exploit zero-day vulnerabilities in hardened systems. In testing, Astra reportedly uncovered two previously unknown real-world vulnerabilities, which OpenAI says it is now disclosing to the affected software maintainers. The company added new safeguards including stronger jailbreak resistance and monitoring, and says Astra shows fewer safety violations than its predecessor, GPT-5.6 Sol.

Unpatched Magento flaw 'StyleSmuggler' used to install Linux backdoor on e-commerce sites

Security firm Sansec has detected active exploitation of an unpatched vulnerability, dubbed StyleSmuggler, affecting all versions of Magento and Adobe Commerce. Attackers inject PHP code through the platform's template system by triggering a fake failed-payment email, which then installs a Rust-based backdoor disguised as a legitimate Linux process and sets up a cron job for persistence. Adobe has confirmed it is working on a patch but has not given a release date.

Google patches actively exploited Chrome zero-day in V8 engine

Google released Chrome version 152.0.7977.82/.83 to fix a high-severity zero-day flaw, CVE-2026-85046, a type confusion bug in the V8 JavaScript engine that is already being exploited in the wild. The update also patches 11 other vulnerabilities, including use-after-free and out-of-bounds memory issues across several Chrome components.

SonicWall discloses two zero-day flaws in SMA1000 under active attack

SonicWall has warned that attackers are chaining two newly discovered vulnerabilities in its SMA1000 secure remote access appliances to execute code remotely. One flaw is a maximum-severity command injection issue in the WorkPlace interface caused by an SSRF weakness, while the second lets an authenticated admin run arbitrary OS commands via the Management Console. The bugs affect the SMA1000 6210, 7210, and 8200v models, with over 400 exposed devices currently visible online.

OpenAI to release Astra, its first model to cross cybersecurity 'critical threshold'

OpenAI announced its upcoming Astra model has crossed what the company calls a critical cybersecurity threshold, meaning it can independently discover and exploit unknown software vulnerabilities without human guidance. The model reportedly scored perfectly on ExploitBench and found two zero-day flaws in an internal test, prompting OpenAI to limit access to its most advanced capabilities and add extra monitoring before release.

PaperCut issues second patch after first fix for exploited flaws was bypassed

PaperCut released a follow-up emergency update for PaperCut NG and MF after researchers found ways around its initial patch for actively exploited vulnerabilities. The company disclosed CVE-2026-82078, a critical unsafe dynamic class-loading bug, and CVE-2026-81578, a high-severity authentication bypass, which can be chained to let unauthenticated attackers execute code on vulnerable servers.

PaperCut Confirms Active Zero-Day Attacks on NG and MF Print Software

PaperCut has disclosed that hackers are actively exploiting an unpatched vulnerability affecting every version of its PaperCut NG and PaperCut MF print management software. The company confirmed real customer incidents, discovered the flaw after reproducing it with data from an affected university, and has since issued emergency patches for internet-facing servers.