← All articles

zero-day

5 articles

CVEzero-dayremediationinfrastructure

Gogs Has a CVSS 9.4 Zero-Day With No Patch. A Metasploit Module Is Out.

Any user can get remote code execution on a Gogs server through a malicious branch name. The maintainer was told in March. It's still not fixed. There's a public exploit. Self-hosters, good luck.

May 29, 2026
CVEMicrosoftExchangezero-dayCISA KEV

CVE-2026-42897: Microsoft Exchange Zero-Day Is Being Exploited Right Now

A crafted email is all it takes. Open it in Outlook Web Access and an attacker runs JavaScript in your browser. No patch yet. Here's what to do if you run Exchange on-prem.

May 15, 2026
educationsmall businesszero-dayvulnerability management

What Is a Zero-Day? And Why Should Your Business Care?

You've seen the term in headlines. Log4Shell. MOVEit. Exchange. Here's what a zero-day actually is, why it matters even if you're not a tech company, and what you can do about a threat you can't see coming.

Apr 30, 2026
infrastructurenetwork securityzero-day

China Hacked All Four Singapore Telecoms. The Operation Took 11 Months to Clean Up.

UNC3886 used zero-days and rootkits to breach every major telecom provider in Singapore. The government ran an 11-month counteroperation called CYBER GUARDIAN. If state actors can own an entire country's telecom, what chance does your business have without help?

Feb 11, 2026
CVEzero-dayinfrastructureCISA KEV

Ivanti Zero-Days Breached Four Governments Before Anyone Got a Patch

The Dutch data authority. The European Commission. Finland. The Council for the Judiciary. All breached through Ivanti EPMM zero-days. CVSS 9.8. If you manage mobile devices with Ivanti, check your version now.

Feb 3, 2026