// ZERO-DAY

// ZERO-DAY

5 articles
All Zero-Day Ransomware Phishing Supply Chain AI Security Data Breaches Malware Vulnerabilities Attacks Security
Android gets patches for Qualcomm zero-day exploited in attacks

Google released security patches for 129 Android vulnerabilities, including an actively exploited zero-day flaw in a Qualcomm display component. This represents a real vulnerability disclosure and active exploitation incident requiring immediate patching.

APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday

A high-severity vulnerability (CVE-2026-21513) in Microsoft's MSHTML Framework was allegedly exploited by APT28 before Microsoft's patch was released. Akamai researchers discovered evidence that the Russia-linked state-sponsored threat actor actively exploited this 0-day vulnerability affecting a critical Windows component.

CISA warns that RESURGE malware can be dormant on Ivanti devices

CISA disclosed details about RESURGE, a malicious implant exploiting CVE-2025-0282 to compromise Ivanti Connect Secure devices. The malware can remain dormant on affected systems, representing an active threat to organizations using vulnerable Ivanti devices.

US Sanctions Russian Exploit Broker Operation Zero

The US sanctioned a Russian exploit broker operation that acquired eight zero-day exploits from a US defense contractor executive who was jailed for selling them. This represents an actual security incident involving theft and trafficking of zero-day vulnerabilities from a legitimate defense contractor.

Cisco SD-WAN Zero-Day Under Exploitation for 3 Years

A maximum-severity zero-day vulnerability (CVE-2026-20127) in Cisco SD-WAN has been actively exploited for approximately 3 years by a sophisticated threat actor with minimal forensic evidence. This represents an actual vulnerability disclosure with real-world exploitation affecting Cisco customers.