← All Intelligence

Zero-Day Threat Intelligence

39 briefings0 vulnerability reports

Zero-day vulnerabilities are security flaws exploited before the vendor releases a patch, making them among the most dangerous threats in cybersecurity. Nation-state actors and advanced criminal groups prize zero-days for their ability to bypass existing defenses. defend.network monitors zero-day disclosures from vendor advisories, CISA alerts, and threat intelligence feeds, prioritizing those with confirmed active exploitation.

39
briefings
2
critical
22
high
41%
of all briefings

Threat Briefings

2026-06-18

Microsoft Defender zero-day, FortiBleed exposes 73k devices, GitHub worm spreads

Microsoft Defender privilege-escalation zero-day CVE-2026-50656 (patch pending). FortiBleed leaks credentials for 73,932 Fortinet devices; attackers actively harvesting access across 200 countries. GitHub supply-chain worm exploiting dismissed design flaws compromises hundreds of packages.

2026-06-12

Critical: Oracle PeopleSoft Zero-Day, Windows BitLocker Bypass, Gentlemen Ransomware

Oracle PeopleSoft CVE-2026-35273 actively exploited by ShinyHunters targeting universities; Windows BitLocker bypassed via XML files; The Gentlemen ransomware claims 478 victims with worm-like spreading capability.

2026-06-09

Critical Check Point VPN and Linux kernel flaws under active exploitation; NSO spyware defies court order

Check Point VPN zero-day (CVSS 9.3) actively exploited since early May; Linux kernel use-after-free now has public exploit; NSO Group continues WhatsApp phishing despite federal court injunction.

2026-06-03

Android, WinRAR, WordPress Kirki: Three critical zero-days under active exploitation

Google Android zero-day (CVE-2025-48595) actively exploited; Gamaredon APT weaponizing WinRAR; WordPress Kirki plugin hijacking admin accounts. CISA adds Oracle WebLogic to KEV catalog.

2026-05-30

ChatGPT malware abuse, Marimo CVE-2026-39987 LLM exploitation, Russian infrastructure arrests

ChatGPT share links abused for malware delivery; Marimo CVE-2026-39987 exploited with LLM agents for post-compromise activity; Dutch authorities seize 800 Russian-linked servers and arrest hosting executives.

2026-05-27

Critical RCEs and credential leaks: Microsoft SharePoint, CISA AWS exposure, MuddyWater espionage

Microsoft patched SharePoint RCE (CVE-2026-45659); CISA contractor exposed AWS GovCloud keys on GitHub; MuddyWater targeted nine organizations across four continents using DLL side-loading.

2026-05-22

Critical RCEs: Microsoft Defender, Linux kernel, Cisco Workload; Showboat targets telcos

Microsoft Defender vulnerabilities actively exploited; 9-year-old Linux kernel flaw enables root execution; Cisco Workload max-severity RCE patched; Showboat malware targets telcos across Middle East and Central Asia.

2026-05-19

Microsoft Exchange zero-day in active use; npm worm clones spread after source leak

Microsoft Exchange zero-day under active exploitation with no patch available. Shai-Hulud worm source code leaked, spawning clones targeting npm developers. INTERPOL Operation Ramz arrested 201 cybercriminals across MENA region.

2026-05-18

Zero-days exploited: NGINX, MS Exchange, Cisco SD-WAN; TanStack hit

Critical zero-days in NGINX, Microsoft Exchange, and Cisco SD-WAN actively exploited in the wild. TanStack supply chain attack compromises OpenAI and AI companies. Immediate patching required.

2026-05-17

Critical RCEs exploited: Cisco SD-WAN, Exchange, Funnel Builder

Critical vulnerabilities in Cisco SD-WAN (CVSS 10.0), Microsoft Exchange, and Funnel Builder WordPress plugin under active exploitation. Supply chain attacks compromise npm packages. Immediate patching required.

2026-05-16

MS Exchange zero-day exploited; npm hits OpenAI; Turla evolves Kazuar

Critical Microsoft Exchange zero-day exploited in wild; npm supply chain attacks compromise OpenAI; Turla APT evolves Kazuar into P2P botnet; WordPress plugins actively harvesting payment cards.

2026-05-15

Cisco SD-WAN zero-day exploited; TanStack supply-chain hits OpenAI

Critical Cisco SD-WAN zero-day exploited in the wild; supply chain attacks compromise TanStack and node-ipc; state APTs target government; education platform disrupted by extortion.

2026-05-14

BitLocker zero-day PoCs public; Exchange APT; Foxconn breached

Critical BitLocker zero-days with public PoCs, Microsoft Exchange APT exploitation, Canvas ransomware attack on education sector, and Foxconn manufacturing compromise create immediate operational risks across multiple industries.

2026-05-12

Checkmarx Jenkins compromise; AI-generated zero-day 2FA bypass

Critical supply chain compromise of Checkmarx Jenkins plugin, first AI-generated zero-day 2FA bypass exploit, and active Canvas education platform extortion campaign require immediate response.

2026-05-11

Canvas ransomware hits universities; Ollama zero-day on 300k servers

Canvas ransomware disrupts universities nationwide; Ollama zero-day affects 300k+ servers; TCLBANKER targets financial platforms; critical infrastructure breached; supply-chain compromises detected.

2026-05-08

Palo Alto & Ivanti EPMM RCE exploited; PCPJack worm hits cloud

Critical vulnerabilities in Palo Alto Networks and Ivanti EPMM under active exploitation. PCPJack credential stealer worm targeting cloud infrastructure. Russian state actors harvesting Office tokens via router compromise.

2026-05-07

vm2, Palo Alto, DAEMON Tools exploited; Iran APT false-flag operations

Critical vulnerabilities in vm2, Palo Alto firewalls, and DAEMON Tools combined with Russian military intelligence token harvesting and Iranian APT false-flag campaigns demand immediate patching and investigation.

2026-05-04

Linux root vulnerability in KEV; cPanel mass-exploitation continues

Critical Linux root access vulnerability added to CISA KEV with active exploitation confirmed. Multiple critical threats including cPanel mass-exploitation, source code breaches, and state-sponsored APT campaigns.

2026-05-01

PyTorch Lightning & SAP supply-chain; AI cuts attack time to 24h

Critical supply chain attacks compromise PyTorch Lightning and SAP packages; Russian state-sponsored actors steal Office tokens; AI-accelerated exploitation shrinks time-to-compromise to 24 hours.

2026-04-29

GitHub, Hugging Face RCE; VECT 2.0 ransomware; BlueNoroff deepfakes

Critical RCE vulnerabilities in GitHub and Hugging Face, destructive VECT 2.0 ransomware, Russian token harvesting, and BlueNoroff deepfake attacks demand immediate defensive action.

2026-04-21

SGLang & Anthropic MCP RCE; APT campaigns hit OT/healthcare auth

Critical RCE vulnerabilities in AI infrastructure (SGLang, Anthropic MCP) combined with state-sponsored APT campaigns targeting authentication systems and OT/healthcare infrastructure demand immediate patching and access controls.

2026-04-20

Defender zero-day; protobuf.js RCE; APT28 hits Ukrainian government

Critical Microsoft Defender zero-days actively exploited, 68% of cloud breaches from unmanaged service accounts, Russian state actors harvesting Office tokens, protobuf.js RCE with public exploit, APT28 targeting Ukrainian government.

2026-04-19

Microsoft Defender zero-days; 68% cloud breaches from ghost identities

Critical Microsoft Defender zero-days under active exploitation, 68% of cloud breaches from unmanaged service accounts, and Russian state-sponsored token harvesting campaigns demand immediate action.

2026-04-18

Microsoft Defender & ActiveMQ zero-days under exploitation

Critical zero-day exploits in Microsoft Defender and Apache ActiveMQ, Russian state-sponsored token harvesting, and sophisticated ransomware evasion techniques pose immediate threats requiring emergency patching and threat hunting.

2026-04-17

Apache ActiveMQ exploited; Defender zero-day; ZionSiphon hits water

Apache ActiveMQ actively exploited; Microsoft Defender zero-day disclosed; Russian state actors harvesting Office 365 tokens; ZionSiphon targets water infrastructure.

2026-04-16

nginx-ui auth bypass exploited; SharePoint zero-day in 169 patches

Critical nginx-ui authentication bypass actively exploited; Microsoft releases 169 patches including SharePoint zero-day; n8n webhooks weaponized for phishing; WordPress plugins and signed software compromised.

2026-04-15

Microsoft zero-days exploited; Mirax RAT hits 220K; PHP supply chain

Critical Microsoft zero-days under exploitation, Russian state hackers harvesting Office tokens via routers, and 220K users compromised by Mirax RAT. Supply-chain risks escalating across PHP and development ecosystems.

2026-04-14

Adobe zero-day exploited; APT37 attacks; AI-powered exploitation

Critical Adobe zero-day under active exploitation, Russian state-sponsored token harvesting, and APT37 social engineering campaigns compound with AI-powered vulnerability discovery threats.

2026-04-13

Adobe Reader zero-day; CPUID STX RAT supply-chain; Iran hits 4,000 ICS

Critical Adobe Reader zero-day, CPUID supply-chain compromise distributing STX RAT, Russian APT harvesting Office tokens via router exploits, and Iranian actors targeting 4,000+ U.S. industrial control systems.

2026-04-12

Iran PLC attacks; Marimo RCE exploited in 10h; GlassWorm IDE infection

Critical threats span Iranian PLC targeting, Russian token harvesting, Marimo RCE exploitation within 10 hours, and GlassWorm IDE infections. Immediate patching and detection deployment required.

2026-04-11

Marimo RCE exploited; Iran targets 4,000 US PLCs; Russian token theft

Critical exploitation of Marimo RCE, Iranian targeting of 4,000 US PLCs, and Russian token harvesting via routers demand immediate patching and access controls.

2026-04-10

Adobe Reader zero-day exploited; APT28 router credential theft

Critical zero-day in Adobe Reader, state-sponsored credential theft via routers, and major supply-chain compromises demand immediate action across all organizations.

2026-04-09

APT28 PRISMEX on NATO; ActiveMQ 13-yr RCE; Russian router token theft

APT28 deploys PRISMEX malware targeting NATO allies; 13-year-old ActiveMQ RCE and Russian router-based token theft critical; new botnets and healthcare ransomware disruptions.

2026-04-06

FortiClient RCE exploited; DPRK & Chinese APTs hit EU institutions

State-sponsored DPRK and China-linked APT campaigns, critical FortiClient RCE exploit, and cascading supply chain attacks affecting European institutions and npm ecosystem.

2026-04-04

TrueConf zero-day; TA416 hits EU govts; UNC1069 npm compromise

Critical zero-day in TrueConf, resurgent Chinese APT targeting European governments, North Korean npm supply chain compromise, and third-party vendor breaches require immediate response

2026-04-02

Chrome & TrueConf zero-days exploited; widespread malware campaigns

Critical zero-day vulnerabilities in Chrome and TrueConf under active exploitation, combined with widespread malware campaigns targeting mobile and enterprise infrastructure.

2026-04-01

TrueConf zero-day exploited; North Korea Axios npm compromise

Critical zero-day exploits in TrueConf and North Korean Axios compromise, plus wiper attacks and AI platform over-privilege vulnerabilities demand immediate response across cloud, government, and healthcare sectors.

2026-03-27

Chinese APT in telecom backbone; Langflow zero-day exploited

State-sponsored Chinese APT embedded in telecom backbone, critical Langflow AI vulnerability actively exploited, wiper malware targeting Iran systems, and zero-click AI assistant vulnerabilities require immediate response.

2026-03-20

VMware ESXi ransomware exploit; BlackSuit healthcare breach

Critical VMware ESXi vulnerability actively exploited by ransomware operators. BlackSuit group claims major U.S. healthcare breach. CISA adds 3 new CVEs. Microsoft patches Windows kernel zero-day. New PhishRelay kit enables real-time MFA bypass.

Get the Daily Briefing in Your Inbox

Subscribe free and never miss a threat briefing.