Zero-day vulnerability
14
MENTIONS
6
EPISODES
5
PODCASTS
Search complete. 14 mentions across 6 episodes found for "Zero-day vulnerability".
Sep 10, 2026
SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.
J
1:39Johannes UllrichHOST
Still, you probably don't want to do this.
J
1:43Johannes UllrichHOST
And as it has become traditional following Microsoft's Patch Tuesday, we of course get Nightmare Eclipse's Zero Day Wednesday.
J
1:52Johannes UllrichHOST
The latest vulnerability here is dubbed ShieldCrash, and it's actually not a fundamentally new vulnerability.
J
2:00Johannes UllrichHOST
It's ShieldBreak, but, uh, it does expand this older vulnerability to bypass the fix, uh, that Microsoft has implemented for this.
Cyber Daily News for September 10th, 2026
S
0:26speaker_0HOST
This suggests a coordinated effort likely targeting sensitive data, possibly related to AI development.
S
0:32speaker_0HOST
A new zero-day exploit named Shield Crash is successfully bypassing Microsoft Defender.
S
0:37speaker_0HOST
The attack grants full system privileges to attackers on unpatched Windows machines.
S
0:42speaker_0HOST
The vulnerability is being actively exploited against systems running the September 2026 updates.
Six Minutes to Domain Admin: Cisco FMC Under Attack, China’s Blue Moon Zero-Day Chain, Autonomous AI Intrusions & Microsoft Defender Bypassed Again
J
0:04James AzarHOST
CISA's patching deadline is this Saturday.
J
0:07James AzarHOST
A China-linked exploit kit called Blue Moon is chaining Chrome and Windows Zero Days into active espionage operations against defense and government targets.
J
0:15James AzarHOST
Autonomous AI agents hit 440 enterprise servers across 48 countries and went from initial access to domain admin in six minutes flat.
J
0:23James AzarHOST
And Microsoft Defender has a brand new Zero Day dropping just two days after.
8 MINS LATER
J
8:03James AzarHOST
That's my take.
J
8:08James AzarHOST
All right, a newly documented exploit kit called Blue Moon is being used by at least four different threat clusters, the majority with a suspected Chinese nexus, including APT31, also tracked as Violet Typhoon.
J
8:20James AzarHOST
They're chaining Chrome and Windows Zero Days into essentially a single compromised chain With it, they're targeting government agencies, defense contractors, NGOs, aerospace companies, and even financial institutions worldwide.
J
8:32James AzarHOST
The first confirmed use was August 28th, so not very long ago.
Nightmare Eclipse Drops 3 Zero-Days Targeting CrowdStrike, Avast, NVIDIA, Magento StyleSmuggler Zero-Day Exploited to Deploy Linux Backdoors, OpenAI Pledges $1 Billion in Daybreak AI Cyber Defense Tools
J
0:00James AzarHOST
a zero day in magento and adobe commerce is being exploited right now and there's still no patch available a phishing as a service platform bypassed mfa at 258 organizations and is still active rogue's green connect clients are spreading a four-stage worm-like payload to every new host that connects and the researcher behind a string of windows zero days just dropped a public exploit targeting crowdstrike avast and nvidia no coordinated disclosure No waiting for this one.
J
0:29James AzarHOST
This is the Cyber Hub Podcast, Security Gang.
J
0:32James AzarHOST
Let's get into it.
J
0:56James AzarHOST
Tuesday, September 8th, 2026, and I'll be honest with you.
J
1:00James AzarHOST
Today's episode has a different texture than most.
J
1:04James AzarHOST
Yeah, we've got zero days with no patches.
J
1:06James AzarHOST
We have phishing infrastructure that's still online, worm-like malware that's actively spreading through remote management platforms, and public exploit code for CrowdStrike Falcon.
J
1:18James AzarHOST
On any other day...
Nightmare on Windows 11.
D
3:01Dave BittnerHOST
Chaotic Eclipse also claims that taking control of Kaspersky's user interface process can disrupt antivirus functions and interfere with file access controls.
D
3:12Dave BittnerHOST
Kaspersky says it has already addressed the vulnerability.
D
3:16Dave BittnerHOST
Chaotic Eclipse has previously published zero-day exploits targeting Microsoft products, a practice that has fueled debate over responsible vulnerability disclosure and the risks of releasing working exploit code.
D
3:31Dave BittnerHOST
The Financial Stability Board is warning that frontier AI could reshape cyber risk fast enough to threaten the global financial system.
D
3:40Dave BittnerHOST
The FSB, chaired by Bank of England Governor Andrew Bailey, is an international advisory body that monitors potential risks to global financial stability.
AI Security Test Escape: Why Agent Containment Failed
R
2:25RichHOST
It is supposed to provide one limited service, but if the system carrying the feed has a flaw, well, the contestant can stop playing the puzzle and start exploring the production equipment behind it.
R
2:37RichHOST
Now, OpenAI's preliminary account says the models found an unknown vulnerability, often called a zero day, in that package service.
R
2:47RichHOST
Again, in plain text for those that don't know, a zero day is a software weakness the defender or vendor has not yet had a chance to fix.
R
2:55RichHOST
Now, the agents used that weakness to get open internet access.
R
3:00RichHOST
Then they increased their permissions, uh, moved through other parts of the research environment, and eventually reached a system that could connect outside.
R
3:15RichHOST
Uh, Exploit Gym is the benchmark or, uh, standardized test the models were trying to solve.
R
3:23RichHOST
The reported goal was narrow: get the solutions.
R
3:26RichHOST
The route was anything but narrow, and this is where an agent behavior can feel alien, even when it is perfectly consistent with the objective that it-- we gave it, right? OpenAI says one model used stolen credentials and additional zero day vulnerabilities to find a path for remote code execution on Hugging Face servers.