Skip to main content
Zero-day vulnerability

Zero-day vulnerability

Search complete. 14 mentions across 6 episodes found for "Zero-day vulnerability".

Sep 10, 2026

Johannes UllrichHOST
1:39
Still, you probably don't want to do this.
Johannes UllrichHOST
1:43
And as it has become traditional following Microsoft's Patch Tuesday, we of course get Nightmare Eclipse's Zero Day Wednesday.
Johannes UllrichHOST
1:52
The latest vulnerability here is dubbed ShieldCrash, and it's actually not a fundamentally new vulnerability.
Johannes UllrichHOST
2:00
It's ShieldBreak, but, uh, it does expand this older vulnerability to bypass the fix, uh, that Microsoft has implemented for this.
speaker_0HOST
0:26
This suggests a coordinated effort likely targeting sensitive data, possibly related to AI development.
speaker_0HOST
0:32
A new zero-day exploit named Shield Crash is successfully bypassing Microsoft Defender.
speaker_0HOST
0:37
The attack grants full system privileges to attackers on unpatched Windows machines.
speaker_0HOST
0:42
The vulnerability is being actively exploited against systems running the September 2026 updates.
James AzarHOST
0:04
CISA's patching deadline is this Saturday.
James AzarHOST
0:07
A China-linked exploit kit called Blue Moon is chaining Chrome and Windows Zero Days into active espionage operations against defense and government targets.
James AzarHOST
0:15
Autonomous AI agents hit 440 enterprise servers across 48 countries and went from initial access to domain admin in six minutes flat.
James AzarHOST
0:23
And Microsoft Defender has a brand new Zero Day dropping just two days after.

8 MINS LATER

James AzarHOST
8:03
That's my take.
James AzarHOST
8:08
All right, a newly documented exploit kit called Blue Moon is being used by at least four different threat clusters, the majority with a suspected Chinese nexus, including APT31, also tracked as Violet Typhoon.
James AzarHOST
8:20
They're chaining Chrome and Windows Zero Days into essentially a single compromised chain With it, they're targeting government agencies, defense contractors, NGOs, aerospace companies, and even financial institutions worldwide.
James AzarHOST
8:32
The first confirmed use was August 28th, so not very long ago.
James AzarHOST
0:00
a zero day in magento and adobe commerce is being exploited right now and there's still no patch available a phishing as a service platform bypassed mfa at 258 organizations and is still active rogue's green connect clients are spreading a four-stage worm-like payload to every new host that connects and the researcher behind a string of windows zero days just dropped a public exploit targeting crowdstrike avast and nvidia no coordinated disclosure No waiting for this one.
James AzarHOST
0:29
This is the Cyber Hub Podcast, Security Gang.
James AzarHOST
0:32
Let's get into it.
James AzarHOST
0:56
Tuesday, September 8th, 2026, and I'll be honest with you.
James AzarHOST
1:00
Today's episode has a different texture than most.
James AzarHOST
1:04
Yeah, we've got zero days with no patches.
James AzarHOST
1:06
We have phishing infrastructure that's still online, worm-like malware that's actively spreading through remote management platforms, and public exploit code for CrowdStrike Falcon.
James AzarHOST
1:18
On any other day...
Dave BittnerHOST
3:01
Chaotic Eclipse also claims that taking control of Kaspersky's user interface process can disrupt antivirus functions and interfere with file access controls.
Dave BittnerHOST
3:12
Kaspersky says it has already addressed the vulnerability.
Dave BittnerHOST
3:16
Chaotic Eclipse has previously published zero-day exploits targeting Microsoft products, a practice that has fueled debate over responsible vulnerability disclosure and the risks of releasing working exploit code.
Dave BittnerHOST
3:31
The Financial Stability Board is warning that frontier AI could reshape cyber risk fast enough to threaten the global financial system.
Dave BittnerHOST
3:40
The FSB, chaired by Bank of England Governor Andrew Bailey, is an international advisory body that monitors potential risks to global financial stability.
RichHOST
2:25
It is supposed to provide one limited service, but if the system carrying the feed has a flaw, well, the contestant can stop playing the puzzle and start exploring the production equipment behind it.
RichHOST
2:37
Now, OpenAI's preliminary account says the models found an unknown vulnerability, often called a zero day, in that package service.
RichHOST
2:47
Again, in plain text for those that don't know, a zero day is a software weakness the defender or vendor has not yet had a chance to fix.
RichHOST
2:55
Now, the agents used that weakness to get open internet access.
RichHOST
3:00
Then they increased their permissions, uh, moved through other parts of the research environment, and eventually reached a system that could connect outside.
RichHOST
3:15
Uh, Exploit Gym is the benchmark or, uh, standardized test the models were trying to solve.
RichHOST
3:23
The reported goal was narrow: get the solutions.
RichHOST
3:26
The route was anything but narrow, and this is where an agent behavior can feel alien, even when it is perfectly consistent with the objective that it-- we gave it, right? OpenAI says one model used stolen credentials and additional zero day vulnerabilities to find a path for remote code execution on Hugging Face servers.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.