Friday, November 21, 2025
Follow on LinkedIn
US Nuclear Weapons Agency Breached

US Nuclear Weapons Agency Breached by Hackers Using Microsoft SharePoint 0-Day Vulnerability

The National Nuclear Security Administration (NNSA) has fallen victim to a sophisticated cyber attack exploiting a previously unknown vulnerability in Microsoft SharePoint, marking one...
CISA Warns of Chinese Hackers Exploiting SharePoint 0-Day Flaws in Active Exploitation

CISA Warns of Chinese Hackers Exploiting SharePoint 0-Day Flaws in Active Exploitation

CISA has issued an urgent alert regarding active exploitation of critical Microsoft SharePoint vulnerabilities by suspected Chinese threat actors.  The attack campaign, dubbed "ToolShell," leverages...
CISA Warns of Microsoft SharePoint Server 0-Day RCE Vulnerability Exploited in Wild

CISA Warns of Microsoft SharePoint Server 0-Day RCE Vulnerability Exploited in Wild

CISA has issued an urgent warning about a critical zero-day remote code execution vulnerability affecting Microsoft SharePoint Server on-premises installations that threat actors are...
Google's AI Tool Big Sleep Uncovered Critical SQLite 0-Day Vulnerability and Blocks Active Exploitation

Google’s AI Tool Big Sleep Uncovered Critical SQLite 0-Day Vulnerability and Blocks Active Exploitation

Google's revolutionary AI-powered security tool, Big Sleep, has achieved a groundbreaking milestone by discovering and preventing the exploitation of a critical SQLite 0-day vulnerability,...
New RenderShock 0-Click Vulnerability Exploits Background Process

RenderShock 0-Click Vulnerability Executes Payloads via Background Process Without User Interaction

A sophisticated zero-click attack methodology called RenderShock that exploits passive file preview and indexing behaviors in modern operating systems to execute malicious payloads without...
Hackers Allegedly Selling WinRAR 0-day Exploit on Dark Web Forums for $80,000

Hackers Allegedly Selling WinRAR 0-day Exploit on Dark Web Forums for $80,000

A threat actor using the handle “zeroplayer” advertised a previously unknown remote-code-execution (RCE) exploit for WinRAR on an underground forum.  The post, titled “WINRAR RCE...
Microsoft SQL Server 0-Day Vulnerability

Microsoft SQL Server 0-Day Vulnerability Exposes Sensitive Data Over Network

A critical information disclosure vulnerability in Microsoft SQL Server, designated as CVE-2025-49719, allows unauthorized attackers to access sensitive data over network connections.  This vulnerability stems...
Nippon Steel Solutions 0-Day Network Vulnerability

Nippon Steel Solutions 0-Day Network Vulnerability Exposes Users Personal Information

Nippon Steel Solutions has disclosed a significant data breach affecting customer, partner, and employee personal information following a zero-day cyber attack that exploited a...
CISA Warns of Chrome 0-day Vulnerability Exploited in Attacks

CISA Warns of Chrome 0-Day Vulnerability Exploited in Attacks

CISA has issued an urgent warning about a critical zero-day vulnerability in Google Chrome that attackers are actively exploiting in the wild.  The vulnerability, designated...
Intelbras Router 0-Day

Hackers Allegedly Selling Intelbras Router 0-Day Exploit on Hacker Forums

Summary 1. A threat actor is selling an unpatched exploit targeting Intelbras routers on hacker forums for 2 BTC, claiming it affects approximately 30,000 devices. 2....
CSN

Top 10