Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Zero-Day
#Zero-Day

Actively Exploited F5 BIG-IP OAuth Zero-Day Enables Unauthenticated RCE

23 September 2026  |  dark6  |  Vulnerability

F5 is warning that attackers are exploiting a critical BIG-IP APM zero-day that can provide unauthenticated remote code execution on certain OAuth authorization-server deployments. Organizations should identify exposed...

>> read more

Check Point Confirms In-the-Wild Attacks on Critical Management Server Zero-Day

23 September 2026  |  dark6  |  Vulnerability

A critical, pre-authentication flaw in Check Point's Management Server software was exploited in the wild weeks before a fix existed, letting attackers upload and run code on systems...

>> read more

Zero-Day in Meta’s Muse AI Assistant Lets Local Malware Hijack Voice Commands and Steal Credentials

22 September 2026  |  dark6  |  Vulnerability

Researcher Patrick Wardle has disclosed an unpatched flaw in Meta's macOS AI agent Muse that lets unprivileged malware quietly redirect dictation traffic and harvest account credentials. The bug...

>> read more

Cisco and Android Zero-Days Lead a Week of Identity and AI Security Failures

21 September 2026  |  dark6  |  Vulnerability

Active exploitation of Cisco ISE and Android modem flaws led a week crowded with critical vulnerabilities, agent hijacking research and identity-driven attacks. Defenders should prioritize exposed control planes,...

>> read more

Steam Windows Zero-Day Turns Local Access Into Full SYSTEM Control

19 September 2026  |  dark6  |  Vulnerability

A newly disclosed weakness in the Steam Client Service reportedly lets a standard Windows user execute code with SYSTEM privileges. With no confirmed vendor fix at publication time,...

>> read more

Cisco Email Gateway Zero-Day Gives Remote Attackers Root Control

15 September 2026  |  dark6  |  Vulnerability

Cisco is warning that attackers are exploiting a critical Secure Email Gateway zero-day to execute commands as root without authentication. Organizations should isolate management interfaces, apply Cisco’s remediation...

>> read more

Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure

14 September 2026  |  dark6  |  Vulnerability

This week’s security picture is dominated by exploited Windows and Chrome zero-days, dangerous flaws in perimeter products and increasingly automated attack operations. Defenders need risk-based patch sequencing, exposure...

>> read more

Claude Misuse Report Shows AI Agents Automating Exploits, Malware Changes and Intrusions

11 September 2026  |  dark6  |  AI

Anthropic says state-backed groups, cybercriminals and hacktivists misused Claude to automate attack chains, develop exploits and adapt malware. The cases show that AI agents can compress specialist work...

>> read more