CuraSec

tag: Zero-Day · 34 items

2026-09-02 · BleepingComputer · source ↗ #sonicwall#zero-day#rce
  • Engineer — Act: Actively exploited RCE zero-days on an edge appliance demand immediate response: apply SonicWall’s emergency mitigations or patches as soon as available, and treat any internet-exposed SMA1000 as potentially compromised pending confirmation.
  • SOC/IR — Act: Active exploitation of an edge SSL VPN device means compromise may predate any patch; sweep SMA1000 appliances for anomalous outbound connections and lateral movement indicators from the appliance’s IP, and initiate assume-breach review of adjacent segments.
  • Leader — Act: If SonicWall SMA1000 is in the estate, confirm remediation is underway this week and request a vendor statement on exposure scope; actively exploited RCE on a remote-access gateway is the kind of incident that surfaces in board and customer conversations.
2026-09-02 · The Hacker News · source ↗ #sonicwall#zero-day#vpn-appliance
  • Engineer — Act: Pre-authentication SSRF (CVSS 10.0) with a public PoC and confirmed active exploitation on SonicWall SMA 1000 series VPN appliances — patch to the vendor-released update immediately and isolate appliances from untrusted networks while patching proceeds.
  • SOC/IR — Act: Active zero-day exploitation of an edge VPN device means assume-breach posture: sweep SMA 1000 access and authentication logs for anomalous pre-auth requests and unusual outbound SSRF-originated connections since disclosure, and tune detections for chained exploit behavior from the appliance.
  • Leader — Act: Confirm whether the organization runs SonicWall SMA 1000 appliances and, if so, brief leadership this week — a CVSS 10.0 pre-auth zero-day under active exploitation on a perimeter VPN is a material risk event that may generate customer or board questions.
  • Signals: CVE-2026-83548 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
  • Engineer — Act: PaperCut NG/MF was exploited as a zero-day and attacks are ongoing — patch to the latest released version immediately and audit server logs for signs of unauthorized access or data exfiltration.
  • SOC/IR — Act: Active data theft via PaperCut exploitation means assume-breach posture for any organization running PaperCut — hunt for anomalous outbound traffic and lateral movement from PaperCut servers since before the patch date.
  • Leader — Plan: PaperCut is widely used in enterprise and education; confirm whether the organization runs it and verify that engineering has applied the patch — brief leadership only if patch status is unconfirmed or delayed.
2026-08-28 · The Hacker News · source ↗ #zero-day#papercut#active-exploitation
  • Engineer — Act: PaperCut NG and MF print management software is under active zero-day exploitation with confirmed customer incidents; apply PaperCut’s emergency patch for v25/v26 immediately and isolate unpatched instances from the network until patched.
  • SOC/IR — Act: Confirmed active exploitation means assume-breach posture for any PaperCut server in the estate; sweep PaperCut application logs for anomalous requests and lateral movement indicators since PaperCut servers have been used as initial-access footholds in prior ransomware campaigns.
  • Leader — Act: Active zero-day with confirmed customer incidents in widely deployed enterprise print software; this week confirm whether your organization runs PaperCut NG or MF, verify emergency patching is underway, and prepare a brief for leadership if exposure is confirmed.
  • Engineer — Act: Zero-day active exploitation in PaperCut NG and MF means no waiting for a patch window; immediately check whether your organization runs either product, apply any vendor-published mitigations or workarounds, and monitor PaperCut’s advisory page for patch availability.
  • SOC/IR — Act: Active exploitation of PaperCut servers creates an immediate assume-breach window; hunt for anomalous child-process spawning from PaperCut services, unusual outbound connections from print-management hosts, and review authentication logs on those servers going back at least two weeks.
  • Leader — Act: PaperCut NG/MF is broadly deployed in enterprise environments and prior PaperCut vulnerabilities were rapidly weaponized by ransomware actors; confirm with your team this week whether either product is in use and verify that mitigations are being applied before a patch is available.
2026-08-17 · BleepingComputer · source ↗ #vulnerability#endpoint-security#zero-day
  • Engineer — Plan: Defender is nearly universal in enterprise Windows estates and a public PoC is on GitHub, but EPSS 0.00 and no KEV listing suggest low immediate exploitation pressure. Track the patch release and apply it as an out-of-band update as soon as Microsoft ships it; no workaround action to take yet.
  • SOC/IR — Plan: The public PoC describes the bypass technique in enough detail to start building detection logic now, before exploitation picks up. Draft a detection for anomalous Defender behavior or process interactions matching the PoC pattern so it is ready to deploy the moment you see exploitation noise.
  • Leader — Skip
  • Signals: CVE-2026-69414 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
2026-08-14 · BleepingComputer · source ↗ #windows#zero-day#patch-management
  • Engineer — Plan: A Windows zero-day now has a patch, so apply the out-of-band update as soon as your change window allows; no KEV listing or public PoC signals suggest immediate active exploitation pressure, but the zero-day classification warrants prioritizing this above routine patches.
  • SOC/IR — Learn: The zero-day label is worth tracking in case exploitation evidence surfaces, but the item provides no IOCs, TTPs, or affected-behavior details to build or tune detections against right now.
  • Leader — Skip
2026-08-13 · BleepingComputer · source ↗ #apt#windows#zero-day
  • Engineer — Act: CISA KEV-listed Windows zero-day with a public PoC now on GitHub — opportunistic exploitation beyond Lazarus is likely imminent. Apply the Microsoft patch for CVE-2026-68820 immediately and verify patch propagation across all Windows endpoints.
  • SOC/IR — Act: Lazarus Operation Dream Job campaign is actively exploiting this CVE; hunt for Dream Job spearphishing lures (fake job offer documents) and post-exploitation behaviors in Windows event logs and EDR telemetry since the campaign’s known activity window, and load current Lazarus IOCs into your SIEM for retroactive sweep.
  • Leader — Act: A nation-state (North Korea/Lazarus) is actively exploiting a KEV-listed Windows zero-day against defense-sector firms; if your organization is defense or defense-adjacent, brief leadership this week and confirm with IT that emergency patching is underway before the public PoC drives broader exploitation.
  • Signals: CVE-2026-68820 — CISA KEV: listed, EPSS 0.00, public PoC on GitHub, reported by 2 collected sources
  • Engineer — Act: With 62 critical CVEs including remote code execution in QUIC and DNS Server plus one actively exploited privilege escalation zero-day, prioritize patching Windows systems this week — target the exploited zero-day and RCE bugs in DNS Server and QUIC-enabled stacks first.
  • SOC/IR — Act: One vulnerability is confirmed exploited in the wild; hunt for privilege escalation activity on Windows endpoints since August 11 and tune EDR/SIEM detections for post-exploit behavior while engineering patches.
  • Leader — Plan: The scale (418 patches, 62 critical, active exploitation) warrants confirming your patch SLA is on track and reviewing exposure of any internet-facing Windows DNS infrastructure with your team this quarter.
2026-08-12 · BleepingComputer · source ↗ #zero-day#privilege-escalation#windows
  • Engineer — Act: A public LPE exploit targeting Microsoft Defender—present on virtually every Windows endpoint—warrants immediate triage: verify whether August Patch Tuesday covered this CVE, and if not, apply any Microsoft-issued workaround and restrict local execution paths that the exploit chain requires.
  • SOC/IR — Plan: No active campaign IOCs or ATT&CK-mapped TTPs are reported yet, but a publicly available SYSTEM-privilege exploit via Defender will attract rapid weaponization; build and stage a detection for anomalous SYSTEM-level child processes spawning from Defender service components (e.g., MsMpEng.exe) before confirmed in-the-wild use.
  • Leader — Plan: A public unpatched exploit in Microsoft’s own security product is a credible board-question risk; direct the team to confirm patch status and monitor for an out-of-band release, and prepare a brief stakeholder statement in case exploitation at scale is confirmed.
2026-08-12 · The Hacker News · source ↗ #windows-lpe#patch-tuesday#zero-day
  • Engineer — Act: CVE-2026-68820 is CISA KEV-listed with a public GitHub PoC and confirmed active exploitation — apply August 2026 Patch Tuesday updates immediately, prioritizing this kernel driver fix to close the SYSTEM-level LPE path.
  • SOC/IR — Act: Active in-the-wild exploitation of a SYSTEM-level LPE means attackers may already have escalated on unpatched endpoints — hunt for anomalous SYSTEM-privilege process spawns from unexpected parent processes and tune EDR alerts for T1068 kernel-driver abuse since the public PoC widens attacker access.
  • Leader — Plan: A 398-patch batch with one actively exploited zero-day may strain standard patch SLAs — confirm your teams have triaged CVE-2026-68820 as this week’s priority and verify compliance with your critical-patch SLA before the next board or audit checkpoint.
  • Signals: CVE-2026-68820 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
2026-08-12 · BleepingComputer · source ↗ #patch-tuesday#zero-day#microsoft
  • Engineer — Act: One actively exploited zero-day among 400 CVEs makes this a high-priority patch cycle; apply August 2026 Patch Tuesday updates immediately, focusing first on the in-the-wild zero-day once specific CVE identifiers are confirmed from Microsoft’s advisory.
  • SOC/IR — Plan: The actively exploited zero-day creates a detection obligation; once the specific CVE and affected component are identified from Microsoft’s release notes, build or tune detections for exploitation attempts and sweep endpoints for signs of pre-patch compromise.
  • Leader — Skip
  • Engineer — Plan: An actively exploited zero-day in this cycle demands prioritization over routine patching; read the full CrowdStrike analysis to identify the affected product and fast-track that specific patch ahead of the 62 criticals.
  • SOC/IR — Plan: The exploited zero-day likely carries a detection angle — review the full analysis for associated TTPs or IOCs and build or tune a detection before patch coverage is complete across the estate.
  • Leader — Learn: A 415-CVE patch cycle with one exploited zero-day is operationally significant but below board altitude unless the zero-day proves systemic; no leadership action required until the engineering team surfaces exposure details.
  • Engineer — Act: Actively exploited zero-day in Metabase with a 10.0 CVSS allows unauthenticated SQL injection leading to full admin takeover — apply the vendor patch immediately or take any internet-exposed Metabase instance offline until patched.
  • SOC/IR — Act: Confirmed in-the-wild exploitation means assume-breach posture for any Metabase instance in your estate: hunt for unauthorized admin logins and anomalous SQL activity in application logs since the disclosure date, and sweep for lateral movement from those hosts.
  • Leader — Act: Confirm whether the organization runs Metabase — BI tools commonly hold access to sensitive operational data, and a CVSS 10.0 actively exploited vulnerability elevates this to a same-week check; if exposed, brief leadership on potential data access risk and request remediation status from the engineering team.
2026-08-09 · BleepingComputer · source ↗ #sql-injection#zero-day#data-breach
  • Engineer — Act: Metabase is widely deployed for BI/analytics and this SQLi is confirmed exploited with no patch available at attack time; if you run Metabase, isolate the instance, apply any available patch or vendor mitigation immediately, and audit logs for signs of unauthorized data access.
  • SOC/IR — Act: Active zero-day exploitation with confirmed data theft against named organizations warrants an immediate assume-breach sweep on any Metabase instances in your estate; hunt for anomalous outbound data transfers and unusual SQL query patterns originating from Metabase since the earliest known attack date.
  • Leader — Act: Named companies (Framework and Tally) have had customer data stolen via this zero-day; confirm whether your organization or key SaaS vendors run Metabase and request attestations, and prepare a brief for leadership in case customers surface questions about exposure.
2026-07-29 · BleepingComputer · source ↗ #zero-day#artifactory#ai-security
  • Engineer — Act: Self-hosted Artifactory is widely deployed in enterprise ML and artifact pipelines; JFrog confirmed active zero-day exploitation enabling network escape — immediately restrict Artifactory egress to allowlisted destinations and apply JFrog patches as soon as they are released.
  • SOC/IR — Act: Confirmed active exploitation creates a concrete hunt target: sweep Artifactory server logs for anomalous outbound connections and unusual external DNS resolutions, and verify integrity of any packages or models sourced from Hugging Face, which was a secondary attack target.
  • Leader — Act: This event touches two widely used ML infrastructure components (self-hosted Artifactory and Hugging Face); confirm whether your organization depends on either, request JFrog’s incident disclosure, and brief leadership now — the AI-autonomy angle will generate board and customer questions before the week is out.
2026-07-29 · The Hacker News · source ↗ #zero-day#artifactory#supply-chain
  • Engineer — Act: Artifactory is a near-universal artifact store in enterprise pipelines; the zero-day enabled privilege escalation and lateral movement to an internet-facing node. Apply JFrog’s released patches to all self-hosted Artifactory instances immediately and audit Artifactory access logs for anomalous API calls or privilege changes since the incident window.
  • SOC/IR — Plan: No IOCs are available in this summary, but the attack chain — privilege escalation from an artifact repository to a network-connected host — is a detection gap worth closing. Build or tune detections for anomalous Artifactory process behavior, unexpected outbound connections from artifact-tier hosts, and lateral movement originating from internal repository services.
  • Leader — Act: A confirmed zero-day in widely-deployed Artifactory fed a breach that extended to Hugging Face, a platform many ML-forward organizations depend on. Confirm whether your organization uses Hugging Face or self-hosted Artifactory, request a security attestation or incident scope statement from JFrog and Hugging Face, and brief leadership — the AI-agent-as-attacker angle will generate board-level questions.
2026-07-28 · BleepingComputer · source ↗ #zero-day#rce#java
  • Engineer — Act: FastJson is widely used in Java applications; if your codebase or dependencies include it, audit immediately and apply any available patch or mitigations — if no patch exists, consider disabling unsafe deserialization features or replacing the library.
  • SOC/IR — Act: Active exploitation is underway against US firms; hunt for anomalous outbound connections or process spawning from Java application servers since this week, and tune detections for RCE post-exploitation behavior (e.g., web shells, unexpected child processes).
  • Leader — Plan: Active zero-day targeting US organizations warrants asking your engineering team this week whether FastJson is in use and what the mitigation timeline is — this may generate customer questions if it widens.
  • Engineer — Act: Maximum-severity command injection in VeloCloud Orchestrator is actively exploited — if you run on-premises VeloCloud Orchestrator, patch immediately and audit for signs of compromise.
  • SOC/IR — Act: Active exploitation of a max-severity edge orchestrator means assume-breach posture for any environment running on-prem VeloCloud Orchestrator — hunt for anomalous command execution or lateral movement from those hosts since before the patch date.
  • Leader — Act: A maximum-severity zero-day actively exploited in SD-WAN infrastructure warrants immediate confirmation of whether VeloCloud Orchestrator is in use on-premises, and if so, direct the team to patch and assess exposure before this surfaces as a board-level incident.
2026-07-24 · The Hacker News · source ↗ #zimbra#russian-apt#zero-day
  • Engineer — Act: If you run Zimbra webmail, patch to the latest release immediately — the exploit is zero-click (opening a message triggers it) and a joint NSA/CISA advisory confirms months of active state-actor abuse. Also review Zimbra access logs for bulk email-download activity over the past 90+ days.
  • SOC/IR — Act: Pull the NSA/CISA joint advisory for published IOCs and hunt for bulk email exfiltration patterns and anomalous 2FA-recovery-code access in Zimbra webmail logs; the campaign ran for months, so extend your look-back window accordingly.
  • Leader — Act: If Zimbra is in your webmail stack, confirm patch status with your engineering team this week and assess whether sensitive mailboxes were exposed; a joint NSA/CISA advisory on a months-long Russian espionage campaign stealing credentials and 2FA codes warrants a pre-emptive leadership brief before it surfaces in board news feeds.
2026-07-23 · BleepingComputer · source ↗ #zero-day#check-point#patch
  • Engineer — Act: Actively exploited zero-day in Check Point SmartConsole, the management GUI used to administer Check Point gateways; patch SmartConsole to the fixed version immediately if your organization runs Check Point infrastructure.
  • SOC/IR — Plan: No IOCs or TTPs have been published yet, but active exploitation of a security management console warrants building detections for anomalous SmartConsole admin sessions and unusual policy changes; monitor for updated threat intel and sweep Check Point environments for signs of unauthorized access.
  • Leader — Plan: Confirm whether your organization uses Check Point SmartConsole and direct the engineering team to treat this as a priority patch; actively exploited zero-days in security management tooling carry elevated risk of lateral movement from the management plane.
2026-07-21 · BleepingComputer · source ↗ #windows#privilege-escalation#zero-day
  • Engineer — Plan: A privilege escalation zero-day on fully patched Windows with no official fix warrants tracking; evaluate applying the 0patch micropatch on critical or high-exposure Windows hosts while awaiting Microsoft’s official release, and audit privileged-access paths on Windows servers you own.
  • SOC/IR — Learn: No active exploitation, IOCs, or mapped TTPs are reported, so there is no immediate detection to write; note the vulnerability class for future hunt queries if exploitation evidence emerges.
  • Leader — Skip
2026-07-21 · BleepingComputer · source ↗ #sonicwall#vpn-appliances#zero-day
  • Engineer — Act: SonicWall SMA1000 is widely deployed enterprise VPN/remote-access infrastructure; active zero-day exploitation with custom malware implants is confirmed. Patch SMA1000 appliances to the latest firmware immediately and inspect filesystem and running processes for signs of persistent malware.
  • SOC/IR — Act: Zero-day compromise of edge VPN appliances with custom malware warrants an assume-breach posture for any environment running SMA1000. Hunt for anomalous outbound connections, credential-harvest activity, or lateral movement originating from these appliances, and check for unknown binaries or modified configs on the devices.
  • Leader — Act: Confirmed zero-day exploitation of a common enterprise VPN product deploying custom malware is a board-visible risk. Verify this week whether your organization runs SonicWall SMA1000, and if so direct engineering and SOC to assess exposure and report status before it becomes a customer or leadership question.
2026-07-20 · The Hacker News · source ↗ #sonicwall#vpn-appliance#zero-day
  • Engineer — Act: SonicWall SMA 1000 series VPN appliances were exploited for root access as zero-days since at least June 22, 2026; if this appliance is in your environment, treat it as potentially compromised — isolate it, review for signs of intrusion, and apply any vendor patches immediately.
  • SOC/IR — Act: Threat actor UTA0533 actively exploited SonicWall SMA 1000 appliances before disclosure, meaning some estates may already be rooted; sweep for Volexity-published IOCs and hunt for lateral movement originating from SMA appliance IP addresses since June 22.
  • Leader — Act: A named threat actor achieved root access on widely-deployed SonicWall SMA 1000 VPN appliances before the vulnerability was public — confirm whether your organization uses this product and, if so, direct your team to assess exposure and obtain SonicWall’s official incident guidance this week.
2026-07-17 · BleepingComputer · source ↗ #windows#privilege-escalation#zero-day
  • Engineer — Plan: A public exploit for this Windows local privilege escalation zero-day exists with no patch available; monitor Microsoft advisories closely and apply the fix immediately on release, meanwhile audit privileged-access paths and restrict unnecessary local user capabilities as interim hardening.
  • SOC/IR — Plan: With a public exploit now circulating, build or tune detections for anomalous registry/hive access patterns leading to unexpected privilege escalation on Windows endpoints, and set a hunt for LPE activity on sensitive hosts since exploit release.
  • Leader — Learn: An unpatched Windows privilege escalation with a public exploit warrants watching; no confirmed widespread exploitation yet, but be ready to brief leadership if Microsoft delays patching or active campaigns emerge.
  • Engineer — Learn: Siemens ROX II OT switches are niche industrial hardware outside most cloud/AppSec environments, and no enrichment signals confirm active exploitation or available patches; the chained privilege-escalation technique is worth understanding for anyone who architects or audits OT network segments.
  • SOC/IR — Learn: No IOCs, no ATT&CK mappings, and no active campaign detail are present, so there is nothing to hunt or tune detections against; the research is useful context for OT-adjacent threat modeling.
  • Leader — Learn: With no confirmed exploitation and no breach event, this does not require immediate leadership action; leaders accountable for industrial or critical-infrastructure environments should note the research as OT risk awareness for the next risk-register review.
2026-07-15 · BleepingComputer · source ↗ #zero-day#vpn-appliance#cisa-kev
  • Engineer — Act: Both CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation — patch SMA1000 appliances to the latest firmware immediately and audit access logs for signs of pre-patch compromise.
  • SOC/IR — Act: Edge appliance exploitation means assume-breach posture is warranted — sweep for lateral movement or credential harvesting activity originating from SMA1000 IPs since the zero-day window, and hunt for post-exploitation behavior in downstream systems.
  • Leader — Act: Actively exploited VPN appliances are a board-level exposure; confirm whether your organization runs SMA1000, verify patching status with the engineering team, and prepare a brief in case the incident becomes public.
  • Signals: CVE-2026-15409 — CISA KEV: listed, EPSS n/a, public PoC on GitHub, reported by 2 collected sources · CVE-2026-15410 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
2026-07-15 · The Hacker News · source ↗ #sonicwall#zero-day#edge-appliance
  • Engineer — Act: Two actively exploited zero-days in SonicWall SMA 1000 — CISA KEV listed, public PoC on GitHub, CVSS 10.0 SSRF enabling unauthenticated RCE. Apply SonicWall’s emergency patch immediately and restrict management access to SMA 1000 appliances while remediating.
  • SOC/IR — Act: Active exploitation of an edge VPN appliance with unauthenticated RCE — treat as assume-breach: sweep logs for anomalous SMA 1000 admin activity and lateral movement indicators since before the disclosure date, and escalate any SMA 1000 in the estate to incident response review.
  • Leader — Act: A CVSS 10.0 zero-day pair on a widely deployed enterprise VPN appliance is being actively exploited — confirm whether SonicWall SMA 1000 is in your environment, and if so brief leadership and prepare customer communications in case compromise is discovered during the sweep.
  • Signals: CVE-2026-15409 — CISA KEV: listed, EPSS n/a, public PoC on GitHub, reported by 2 collected sources
2026-07-15 · BleepingComputer · source ↗ #zero-day#sharefile#file-sharing
  • Engineer — Act: If you run ShareFile Storage Zone Controllers on-premises, apply the released security updates immediately — Progress shutting down the hosted service is a strong implicit signal of active exploitation risk, mirroring their MOVEit pattern.
  • SOC/IR — Plan: No IOCs or TTPs are available yet, but queue a hunt workflow for once Progress or third-party researchers publish exploitation indicators; given Progress’s MOVEit history, details will likely emerge quickly.
  • Leader — Act: Confirm whether your organization runs ShareFile Storage Zone Controllers on-prem, then check with Progress for breach attestations this week — an emergency service shutdown from this vendor warrants a fast exposure check before board or customer questions arrive.
2026-07-15 · The Hacker News · source ↗ #patch-tuesday#zero-day#microsoft
  • Engineer — Act: Two vulnerabilities are under active exploitation with incident responders credited, making them immediate priorities — apply the July 2026 Microsoft updates now, targeting the two exploited CVEs first, then work through the remaining 620 on your normal risk-ranked cadence.
  • SOC/IR — Act: Active exploitation of both zero-days (with IR team involvement confirmed) means assume some estates are already hit — hunt for post-exploitation indicators on Windows systems that lag the July patch cycle and tune detections for lateral movement or privilege escalation patterns consistent with Microsoft kernel/privilege bugs.
  • Leader — Plan: A record 622-CVE release with two actively exploited flaws is likely to surface in board or customer conversations this week — confirm your patch team is triaging the exploited CVEs on an expedited timeline and prepare a brief status for leadership in case questions arise.
2026-07-15 · CrowdStrike Blog · source ↗ #patch-tuesday#microsoft#zero-day
  • Engineer — Act: Two actively exploited zero-days in Microsoft products warrant immediate prioritization of July Patch Tuesday; apply updates now, focusing on the exploited CVEs first — check the full advisory to identify affected components (Windows, Edge, Office, etc.) and patch to current versions within your critical SLA.
  • SOC/IR — Plan: Active exploitation of two zero-days means adversaries may already be in unpatched estates; review the CrowdStrike analysis for TTPs and any IOCs tied to those exploits, then build or tune detections targeting post-exploitation behaviors for the affected components before the broader threat actor ecosystem adopts these.
  • Leader — Plan: Two actively exploited zero-days in this cycle elevate urgency beyond routine patch cadence — confirm with your engineering team this week that the exploited CVEs are being fast-tracked, and assess whether affected components touch regulated systems or customer-facing infrastructure that could trigger disclosure obligations.
2026-07-15 · BleepingComputer · source ↗ #patch-tuesday#zero-day#microsoft
  • Engineer — Act: Two zero-days actively exploited in the wild against Microsoft products demand immediate patching priority this cycle; apply July 2026 Patch Tuesday updates now, triaging the exploited CVEs before the routine 570-flaw backlog.
  • SOC/IR — Plan: The summary confirms active exploitation but provides no IOCs, TTPs, or ATT&CK mappings yet — monitor vendor and threat-intel feeds for those details, then build or tune detections targeting the specific zero-day exploit behaviors once published.
  • Leader — Plan: Record patch volume plus two actively exploited zero-days warrants confirming with engineering that patch management is accelerated this cycle; brief leadership if customer security questionnaires or board inquiries arrive about the record-breaking release.
2026-07-13 · The Hacker News · source ↗ #joomla#zero-day#cisa-kev
  • Engineer — Act: CISA KEV-listed, CVSS 10.0, actively exploited as zero-days with a public PoC on GitHub — patch iCagenda and Balbooa Forms Joomla extensions to the latest fixed versions immediately if these are in your stack.
  • SOC/IR — Act: In-the-wild zero-day exploitation of web-facing Joomla components means you should assume compromise may predate patching — sweep web access logs for anomalous requests targeting these extension endpoints and confirm whether any estate assets run Joomla with either plugin.
  • Leader — Plan: CISA KEV listing at CVSS 10.0 warrants a same-week inventory check of web properties for Joomla usage with these extensions; if confirmed in use, escalate to engineering for urgent remediation before this surfaces in a customer questionnaire or audit.
  • Signals: CVE-2026-48939 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
2026-07-12 · HN (cve) · source ↗ #browser-security#zero-day#cve
  • Engineer — Act: KEV-listed zero-day actively exploited in Chrome’s CSS engine; update Chrome/Chromium to the patched stable release immediately and verify managed browsers in your fleet are on the latest version.
  • SOC/IR — Act: Active in-the-wild exploitation means assume-breach posture for any endpoint running unpatched Chrome; hunt for suspicious child processes or unusual network connections from Chrome since the February 2026 stable release date, and check EDR telemetry for exploitation indicators.
  • Leader — Plan: CISA KEV listing confirms active exploitation of a Chrome browser zero-day; validate that your IT/engineering teams have a forced browser-update mechanism and confirm rollout completion — this is routine but warrants a status check given KEV designation.
  • Signals: CVE-2026-2441 — CISA KEV: listed, EPSS 0.22, public PoC on GitHub