Back to Blog

#Zero-Day

16 posts
CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline

CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline

CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline CVE-2026-48172 has escalated from vendor emergency to federal patching priority. On May 26, 2...

May 27, 2026
5 min read
CVE-2026-42897 makes on-prem Exchange an immediate mitigation priority

CVE-2026-42897 makes on-prem Exchange an immediate mitigation priority

CVE-2026-42897 makes on-prem Exchange an immediate mitigation priority CVE-2026-42897 is the kind of [zero-day](https://invaders.ie/resources/glossary/zero-day)...

May 16, 2026
5 min read
Dirty Frag Linux kernel zero-day gives local users a fast path to root

Dirty Frag Linux kernel zero-day gives local users a fast path to root

Dirty Frag Linux kernel zero-day gives local users a fast path to root Dirty Frag is the kind of Linux bug defenders worry about because it turns a limited foot...

May 10, 2026
5 min read
Dirty Frag Linux kernel zero-day gives local users a fast path to root

Dirty Frag Linux kernel zero-day gives local users a fast path to root

Dirty Frag Linux kernel zero-day gives local users a fast path to root Dirty Frag deserves attention because it is not a theoretical Linux bug waiting for slow...

May 8, 2026
5 min read
CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path A critical point in the new PAN-OS warning is that defenders are not looking at a ro...

May 7, 2026
4 min read
Leaked Windows Defender zero-days are already being used to gain SYSTEM access

Leaked Windows Defender zero-days are already being used to gain SYSTEM access

Leaked Windows Defender zero-days are already being used to gain SYSTEM access A fast-moving Windows story matters to defenders this week for a simple reason: p...

April 17, 2026
5 min read
Storm-1175 turns patch gaps into rapid Medusa ransomware intrusions

Storm-1175 turns patch gaps into rapid Medusa ransomware intrusions

Storm-1175 turns patch gaps into rapid Medusa ransomware intrusions Storm-1175 is a financially motivated threat actor that Microsoft says has been using newly...

April 7, 2026
7 min read
CVE-2026-3502 turns TrueConf updates into a KEV-listed malware channel

CVE-2026-3502 turns TrueConf updates into a KEV-listed malware channel

CVE-2026-3502 turns TrueConf updates into a KEV-listed malware channel CVE-2026-3502 is the kind of vulnerability defenders should pay attention to even if True...

April 3, 2026
5 min read
Telegram zero-click flaw ZDI-CAN-30207 raises 9.8 risk

Telegram zero-click flaw ZDI-CAN-30207 raises 9.8 risk

Telegram zero-click flaw ZDI-CAN-30207 raises 9.8 risk | 2026 ZDI-CAN-30207 is now listed on the Zero Day Initiative's upcoming advisory page as a Telegram issu...

March 28, 2026
5 min read
CVE-2026-4681: PTC warns of imminent Windchill and FlexPLM RCE risk

CVE-2026-4681: PTC warns of imminent Windchill and FlexPLM RCE risk

CVE-2026-4681: PTC warns of imminent Windchill and FlexPLM RCE risk CVE-2026-4681 deserves immediate attention because PTC is signaling urgency before full patc...

March 26, 2026
6 min read
DarkSword iOS Exploit Chain Hits Multiple Threat Actors

DarkSword iOS Exploit Chain Hits Multiple Threat Actors

DarkSword iOS Exploit Chain Hits Multiple Threat Actors Executive Summary Google Threat Intelligence Group says DarkSword is a full-chain iOS [exploit](https://...

March 19, 2026
6 min read
DarkSword iOS Exploit Chain Hits Multiple Threat Actors

DarkSword iOS Exploit Chain Hits Multiple Threat Actors

DarkSword shows how iPhone zero-days spread far beyond a single operator Executive Summary Google Threat Intelligence Group says DarkSword is a full-chain iOS [...

March 19, 2026
6 min read