Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
ZeroDay Bug

ShieldCrash Zero-Day Bypasses Microsoft's ShieldBreak Patch

Security researcher Nightmare Eclipse has released ShieldCrash , a proof-of-concept exploit that, on fully updated Windows machines, reads arbitrary …

WeWorm: Zero-Click WeChat Worm Hijacks iOS and Android

Security firm Calif has disclosed WeWorm , a zero-click worm that hijacks WeChat accounts via a regular voice call on both iOS and Android. The vict…

FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor

A security researcher known as Chaotic Eclipse has released FalconFlank , a proof-of-concept zero-day that escalates privileges on fully patched Wind…

PrettyPrague Zero-Day Exploit Hits Avast Antivirus

A security researcher known as Chaotic Eclipse has released a working proof-of-concept exploit for an unpatched privilege escalation vulnerability i…

ShieldBreak PoC Bypasses Microsoft's RoguePlanet Defender Fix

Security researcher Nightmare Eclipse has released ShieldBreak , a proof-of-concept exploit that defeats the patch Microsoft shipped five weeks ago f…

Windows 11 Kernel 0day PoC Drops Before Patch Tuesday

An anonymous researcher has published proof-of-concept (PoC) code for what they describe as an unpatched local privilege-escalation flaw in Windows 1…

Metabase Zero-Day Exposes Framework, Tally Customer Data

Two companies told customers this week that their personal data had been stolen. Neither was breached directly. The attacker walked in through the an…

Cursor's Unpatched 0-Day Lets a Fake Git Binary Hijack Your Windows PC

A security flaw in Cursor, the AI-powered code editor used by more than 7 million developers, lets attackers run arbitrary code on a victim's Win…

BitLocker Bypass GreatXML: Using Defender Offline Scan Against You

If you have ever run Windows Defender's Offline Scan, your BitLocker encryption may already be compromised — before an attacker even logs in. Sec…

Microsoft Defender Zero-Day PoC Gives SYSTEM Access on Fully Patched Windows

A researcher who has turned Microsoft's vulnerability disclosure process into a public battleground has released another working exploit — this t…

Researcher Drops PoC for 1-Click GitHub Token Theft via VSCode Bug — Skips MSRC Entirely

Security researcher Ammar Askar has publicly released a fully working proof-of-concept (PoC) exploit that can steal a victim's GitHub OAuth token…

Trend Micro's Own Security Tool Turned Against Enterprises — Apex One Zero-Day Actively Exploited

The endpoint security software meant to protect enterprise networks from attackers has itself become a target. Trend Micro has patched a zero-day vul…

Palo Alto PAN-OS Zero-Day Under Active Attack — No Patch Available Yet

Attackers are already exploiting a critical zero-day vulnerability in Palo Alto Networks' PAN-OS, the operating system powering the company's…

Telegram 0-Day: One Sticker Could Hack You — Telegram Calls It Fake

[Updated: March 30, 2026 — Score revised from 9.8 to 7.0. Original story below.] On Sunday, Telegram's official account dismissed a newly disclos…

Apple Rushes Patch for Actively Exploited Zero-Day Linked to Spyware Attacks

Apple has issued emergency security updates to address a critical zero-day vulnerability actively exploited in what the company describes as an "…

Hackers Are Actively Exploiting Critical Microsoft Office Flaw—Patch Now or Risk Takeover

Microsoft has scrambled to release an out-of-band security patch for a high-severity zero-day vulnerability in Office that attackers are actively wea…

Cloudflare's Certificate Path Let Attackers Sidestep Web Application Firewalls for Months

A seemingly innocuous certificate validation path became a hidden gateway past Cloudflare's Web Application Firewall (WAF), security researchers …

New VMware Zero-Day Exploited Chinese Hackers

A critical privilege escalation vulnerability in VMware products was exploited in the wild for nearly a year before being patched, security researche…

Hackers Exploit Cisco Firewall Zero-Days, CISA Issues Emergency Directive

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Emergency Directive, ordering federal agencies to immediately identify an…

Cisco Patches Critical IOS Zero-Day Under Active Attack—Millions of Network Devices at Risk

Cisco has released emergency security patches for a critical zero-day vulnerability in its IOS and IOS XE software that attackers are actively exploi…