Latest

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

A compromised version of the Nx Console extension — a popular VS Code plugin with over 2.2 million installations — was published to the Visual Studio Code Marketplace after an attacker leveraged stolen developer credentials to inject a multi-stage credential stealer into the official nrwl/nx GitHub repository. The malicious version

By Zero Day Wire
Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Symantec and Carbon Black have published a definitive analysis confirming that Fast16, a Lua-based malware framework first surfaced by SentinelOne weeks ago, was purpose-built to sabotage nuclear weapons testing simulations. The findings establish Fast16 as the earliest known cyber sabotage tool targeting nuclear weapons research — predating the first known version

By Zero Day Wire
Chaotic Eclipse Releases MiniPlasma — A Five-Year-Old Windows Zero-Day That Still Grants SYSTEM Privileges on Fully Patched Systems

Chaotic Eclipse Releases MiniPlasma — A Five-Year-Old Windows Zero-Day That Still Grants SYSTEM Privileges on Fully Patched Systems

Chaotic Eclipse has released a third wave of Windows zero-day disclosures, publishing a proof-of-concept for a privilege escalation vulnerability codenamed MiniPlasma that grants SYSTEM privileges on fully patched Windows systems — including those running the latest May 2026 updates. The flaw resides in cldflt.sys, the Windows Cloud Files Mini Filter

By Zero Day Wire
FamousSparrow Targets Azerbaijani Oil and Gas Firm in Three-Wave Campaign Using ProxyNotShell, Deed RAT, and Kernel-Level Rootkit

FamousSparrow Targets Azerbaijani Oil and Gas Firm in Three-Wave Campaign Using ProxyNotShell, Deed RAT, and Kernel-Level Rootkit

Bitdefender Labs has documented a sustained espionage campaign by Chinese-aligned APT group FamousSparrow against an oil and gas company in Azerbaijan, carried out across three distinct waves between December 2025 and February 2026. The campaign marks a strategic pivot for the group toward South Caucasus energy infrastructure and demonstrates how

By Zero Day Wire
Chaotic Eclipse Returns With Two More Windows Zero-Days — BitLocker Bypass YellowKey and CTFMON Privilege Escalation GreenPlasma

Chaotic Eclipse Returns With Two More Windows Zero-Days — BitLocker Bypass YellowKey and CTFMON Privilege Escalation GreenPlasma

The anonymous security researcher known as Chaotic Eclipse — responsible for the BlueHammer, RedSun, and UnDefend Microsoft Defender zero-days that ZDW covered last month — has returned with two additional Windows zero-days, escalating an increasingly public confrontation with Microsoft over vulnerability disclosure handling. The first vulnerability, codenamed YellowKey, is a BitLocker bypass

By Zero Day Wire
Microsoft Exposes AiTM Phishing Campaign Targeting 35,000 Users Across 26 Countries With Code of Conduct Lures and Real-Time Token Theft

Microsoft Exposes AiTM Phishing Campaign Targeting 35,000 Users Across 26 Countries With Code of Conduct Lures and Real-Time Token Theft

Microsoft has disclosed a large-scale credential theft campaign that targeted more than 35,000 users across 13,000 organizations in 26 countries over a three-day window between April 14 and 16, 2026. The campaign combined polished enterprise-style lures with adversary-in-the-middle (AiTM) phishing to harvest Microsoft credentials and authentication tokens in

By Zero Day Wire
Critical MetInfo and Weaver E-cology Flaws Under Active Exploitation — Unauthenticated RCE Targeting Chinese Enterprise Infrastructure

Alerts

Critical MetInfo and Weaver E-cology Flaws Under Active Exploitation — Unauthenticated RCE Targeting Chinese Enterprise Infrastructure

Two critical vulnerabilities in widely deployed Chinese enterprise software are under active exploitation, with threat actors leveraging unauthenticated remote code execution flaws in MetInfo CMS and Weaver E-cology to compromise servers without requiring any credentials. CVE-2026-29014 (CVSS 9.8) affects MetInfo, a PHP and MySQL-based enterprise content management system popular

By Zero Day Wire
Critical GitHub RCE Vulnerability Exposed Millions of Public and Private Repositories to Backend Server Compromise (CVE-2026-3854)

Alerts

Critical GitHub RCE Vulnerability Exposed Millions of Public and Private Repositories to Backend Server Compromise (CVE-2026-3854)

Wiz researchers have disclosed a critical remote code execution vulnerability in GitHub's internal Git infrastructure that exposed millions of repositories across both GitHub.com and GitHub Enterprise Server. Tracked as CVE-2026-3854, the flaw allowed any authenticated user to execute arbitrary commands on GitHub's backend servers using

By Zero Day Wire
Microsoft Defender Zero-Day Exploited in the Wild — BlueHammer Attack Chain Extracts SAM Hashes and Kills Defender via Race Condition

Alerts

Microsoft Defender Zero-Day Exploited in the Wild — BlueHammer Attack Chain Extracts SAM Hashes and Kills Defender via Race Condition

A privilege escalation vulnerability in Microsoft Defender is under active exploitation using publicly available proof-of-concept code, with Huntress confirming attacks began on April 10 — four days before Microsoft released a patch. CISA added the flaw to its Known Exploited Vulnerabilities catalog on Wednesday, setting a May 6 federal patching deadline.

By Zero Day Wire
Microsoft Issues Emergency Patch for Critical ASP.NET Core Flaw Allowing SYSTEM Privilege Escalation via Forged Auth Cookies

Alerts

Microsoft Issues Emergency Patch for Critical ASP.NET Core Flaw Allowing SYSTEM Privilege Escalation via Forged Auth Cookies

Microsoft has pushed an emergency out-of-band security update to address CVE-2026-40372, a critical privilege escalation vulnerability in ASP.NET Core's Data Protection cryptographic APIs that allows unauthenticated attackers to forge authentication cookies and gain SYSTEM-level access on affected systems. The flaw originated from a regression introduced in the

By Zero Day Wire
Mustang Panda Deploys Updated LOTUSLITE Backdoor Against Indian Banking Sector and South Korean Policy Targets

Threats

Mustang Panda Deploys Updated LOTUSLITE Backdoor Against Indian Banking Sector and South Korean Policy Targets

Acronis researchers have identified a new variant of the LOTUSLITE backdoor being deployed by Mustang Panda in campaigns targeting India's banking sector and South Korean policy communities. The updated malware demonstrates incremental refinements over its predecessor, confirming active maintenance by the Chinese nation-state group as it broadens its

By Zero Day Wire
CISA Adds Eight Exploited Vulnerabilities to KEV Catalog Including Three Cisco SD-WAN Manager Flaws and Quest KACE CVSS 10.0

Alerts

CISA Adds Eight Exploited Vulnerabilities to KEV Catalog Including Three Cisco SD-WAN Manager Flaws and Quest KACE CVSS 10.0

CISA added eight new vulnerabilities to its Known Exploited Vulnerabilities catalog on Monday, setting aggressive federal patching deadlines after confirming active exploitation across a range of enterprise products. Three of the flaws target Cisco Catalyst SD-WAN Manager, while the remaining five affect Quest KACE, PaperCut, JetBrains TeamCity, Kentico Xperience, and

By Zero Day Wire
Former Ransomware Negotiators Pleads Guilty to Running BlackCat Attacks Against the Companies They Were Hired to Protect

Breaches

Former Ransomware Negotiators Pleads Guilty to Running BlackCat Attacks Against the Companies They Were Hired to Protect

Angelo Martino, a 41-year-old former ransomware negotiator at cybersecurity incident response firm DigitalMint, has pleaded guilty to targeting U.S. companies with BlackCat (ALPHV) ransomware while simultaneously working as a negotiator supposedly helping victims resolve attacks. Martino is the third defendant to plead guilty in a case that exposes one

By Zero Day Wire
Iranian APT Seedworm Deploys Dindoor Backdoor via Microsoft Teams Social Engineering Using Deno Runtime for In-Memory Execution

Threats

Iranian APT Seedworm Deploys Dindoor Backdoor via Microsoft Teams Social Engineering Using Deno Runtime for In-Memory Execution

CyberProof researchers have uncovered a campaign by Iranian APT group Seedworm that uses Microsoft Teams as an initial access vector, deploying a custom backdoor called Dindoor through social engineering that impersonates IT support personnel. The campaign emerged in early March 2026, coinciding with a surge in Iranian-linked cyber activity following

By Zero Day Wire
Vercel Breached via OAuth Supply Chain Attack — Attacker Bypassed MFA Without Stealing a Single Credential

Breaches

Vercel Breached via OAuth Supply Chain Attack — Attacker Bypassed MFA Without Stealing a Single Credential

A threat actor has breached Vercel's developer infrastructure through an identity supply chain attack that bypassed multi-factor authentication entirely — without stealing a single credential. The compromise, disclosed in April 2026, exploited a breached third-party OAuth integration to inherit valid Google Workspace sessions belonging to Vercel developers, representing a

By Zero Day Wire