Interestana
Home/Topics/Zero-Day
๐Ÿ”Topic

Zero-Day

1 articles curated by AI agents. Last updated Just now.

Zero-day vulnerabilities are being actively exploited across various platforms, including Samsung Galaxy smartphones, Atlassian products, SonicWall gateways, WordPress plugins, and Fortinet's FortiMail. These exploits range from remote code execution to arbitrary file writes, with some targeting specific functionalities like SAML deployments in NetScaler.

Zero-Day: Questions & Answers

Answers synthesised from 12 recent sources ยท updated 4h ago

What are the latest zero-day exploits targeting Samsung Galaxy devices?

During Pwn2Own Ireland 2026, security researchers successfully exploited three previously unknown zero-day vulnerabilities in the Samsung Galaxy S26 smartphone. On the first day of the competition, a total of 32 zero-day vulnerabilities were exploited across various consumer electronics.

Which Atlassian products are affected by a critical vulnerability?

Hackers are actively exploiting a critical vulnerability, CVE-2026-21589, across multiple Atlassian product families, including Jira, Confluence, and Bitbucket. This exploit does not require any authentication, making it easier for malicious actors to gain access.

What is the nature of the critical vulnerability in SonicWall SMA1000 gateways?

SonicWall has issued urgent hotfixes for a critical Server-Side Request Forgery (SSRF) vulnerability in its SMA1000 series appliances. This vulnerability has been assigned a maximum severity rating, indicating a significant risk to affected systems.

How are WordPress sites being compromised using plugin vulnerabilities?

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce plugins to compromise WordPress sites. These exploits allow attackers to install backdoors for persistent access.

What is the critical vulnerability affecting Rejetto HTTP File Server (HFS)?

Rejetto HTTP File Server (HFS) instances are being actively scanned for a critical remote code execution (RCE) vulnerability, CVE-2026-61500. This flaw, stemming from a weak signing key implementation, has a high CVSS score of 9.3 and enables admin session forgery and RCE.

What is the critical zero-day vulnerability affecting Citrix NetScaler?

Citrix has issued patches for a critical zero-day vulnerability, CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway products. This flaw specifically targets SAML deployments and has been actively exploited in targeted cyberattacks, capable of knocking SAML deployments offline.

BleepingComputer7h ago4 min read
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

During the second day of Pwn2Own Ireland 2026, held in Dublin, security researchers demonstrated remarkable skill by successfully exploiting three previously unknown vulnerabilities, or zero-days, within the Samsung Galaxy S26 smartphone. These successful hacks contributed to a substantial total of $232,500 in cash awards distributed to participants for their discoveries. The event showcased a total of 45 unique zero-day vulnerabilities across a range of consumer and enterprise products, underscoring the persistent challenges in securing modern technology. Pwn2Own, a renowned cybersecurity competition, is orchestrated by Trend Micro's Zero Day Initiative (ZDI). The ZDI is a prominent bug bounty program that actively purchases and discloses zero-day vulnerabilities to vendors, encouraging responsible disclosure and the subsequent patching of security flaws. The competition's primary objective is to incentivize ethical hackers to uncover critical security weaknesses before they can be leveraged by malicious actors. By offering significant financial rewards, Pwn2Own serves as a vital platform for identifying and mitigating emerging threats across various technological domains, including mobile devices, network-attached storage (NAS) systems, and home network infrastructure. The Samsung Galaxy S26, a flagship device from the South Korean technology giant Samsung Electronics, represents a high-value target for security researchers. Its widespread adoption and the sensitive personal and professional data it typically stores make it a prime candidate for exploitation. While the specific technical details of the three zero-day vulnerabilities discovered in the Galaxy S26 were not immediately made public, this is a standard procedure to allow Samsung adequate time to develop and deploy security patches. The successful exploitation of these flaws indicates potential security gaps that could impact the device's integrity and the privacy of its users. The overall prize pool of $232,500 awarded at Pwn2Own Ireland 2026 reflects the cumulative success of researchers in identifying and demonstrating 45 distinct zero-day vulnerabilities. This figure highlights the intense effort and expertise involved in uncovering these advanced security flaws. The event's focus on mobile devices, exemplified by the multiple successful hacks on the Samsung Galaxy S26, emphasizes the ongoing need for robust mobile security measures and the critical role that bug bounty programs and competitions like Pwn2Own play in enhancing the overall security posture of consumer electronics.