<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Zero Day Room</title><link>https://zerodayroom.com/</link><description>Cybersecurity, Asia. Organised around the vulnerability or campaign, and the patch or control that stops it.</description><language>en</language><item><title>Microsoft Defender Patch Bypass Exploit Claims SYSTEM Access</title><link>https://zerodayroom.com/news/microsoft-defender-patch-bypass-e95232/</link><guid isPermaLink="true">https://zerodayroom.com/news/microsoft-defender-patch-bypass-e95232/</guid><description>A security researcher has released a proof-of-concept exploit for a Microsoft zero-day vulnerability, claiming it can bypass a previously released patch and grant an attacker SYSTEM-level privileges.</description><pubDate>17 August 2026</pubDate></item><item><title>Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS</title><link>https://zerodayroom.com/news/cisco-asa-ftd-flaw-ede96a/</link><guid isPermaLink="true">https://zerodayroom.com/news/cisco-asa-ftd-flaw-ede96a/</guid><description>A high-severity vulnerability in Cisco's Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild, allowing an unauthenticated attacker to trigger a denial-of-service (DoS) condition.</description><pubDate>17 August 2026</pubDate></item><item><title>SAP Commerce Cloud Vulnerability Allows Unauthenticated Attackers to Execute Arbitrary Code</title><link>https://zerodayroom.com/news/sap-commerce-cloud-vulnerability-9c4fb6/</link><guid isPermaLink="true">https://zerodayroom.com/news/sap-commerce-cloud-vulnerability-9c4fb6/</guid><description>SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.</description><pubDate>17 August 2026</pubDate></item><item><title>Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack</title><link>https://zerodayroom.com/news/microsoft-patches-flaws-including-73b10d/</link><guid isPermaLink="true">https://zerodayroom.com/news/microsoft-patches-flaws-including-73b10d/</guid><description>Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack.</description><pubDate>17 August 2026</pubDate></item><item><title>Enterprise Defenses Recovered at the Edge, Collapsed Inside</title><link>https://zerodayroom.com/news/enterprise-defenses-recovered-edge-2689d1/</link><guid isPermaLink="true">https://zerodayroom.com/news/enterprise-defenses-recovered-edge-2689d1/</guid><description>A recent report by Picus Labs reveals that enterprise defenses have made significant improvements at the perimeter, but are struggling to prevent quiet attacks inside the network.</description><pubDate>16 August 2026</pubDate></item><item><title>Adobe Patches Critical Flaws in ColdFusion, Commerce, and Campaign Classic</title><link>https://zerodayroom.com/news/adobe-patches-critical-flaws-96b5e1/</link><guid isPermaLink="true">https://zerodayroom.com/news/adobe-patches-critical-flaws-96b5e1/</guid><description>Adobe releases updates to address multiple critical security vulnerabilities in ColdFusion, Commerce, and Campaign Classic, with some flaws having a CVSS score of 10.0.</description><pubDate>16 August 2026</pubDate></item><item><title>Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access</title><link>https://zerodayroom.com/news/attackers-exploit-vmware-vcenter-a0ae0c/</link><guid isPermaLink="true">https://zerodayroom.com/news/attackers-exploit-vmware-vcenter-a0ae0c/</guid><description>Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability, CVE-2026-59310, is a directory-traversal vulnerability in the VMware vCenter server that can be exploited to execute arbitrary code.</description><pubDate>16 August 2026</pubDate></item><item><title>Malicious LiteLLM Releases May Have Exposed Thousands of Organizations</title><link>https://zerodayroom.com/news/malicious-litellm-releases-may-1b59d6/</link><guid isPermaLink="true">https://zerodayroom.com/news/malicious-litellm-releases-may-1b59d6/</guid><description>A recent investigation has revealed that two malicious LiteLLM releases were published on PyPI in March, potentially exposing over 2,500 organizations to credential-stealing code.</description><pubDate>16 August 2026</pubDate></item><item><title>SharePoint Authentication Bypass Exploited After PoC Release</title><link>https://zerodayroom.com/news/sharepoint-authentication-bypass-exploited-670241/</link><guid isPermaLink="true">https://zerodayroom.com/news/sharepoint-authentication-bypass-exploited-670241/</guid><description>Threat actors are actively exploiting a critical SharePoint vulnerability (CVE-2026-55040) after a proof-of-concept exploit was publicly released. The flaw allows unauthenticated attackers to bypass authentication and impersonate users, enabling file disclosure and data modification.</description><pubDate>16 August 2026</pubDate></item><item><title>Lazarus Group Exploits Windows Zero-Day Vulnerability to Gain SYSTEM Access and Deploy Backdoor</title><link>https://zerodayroom.com/news/lazarus-group-exploits-windows-a82e1d/</link><guid isPermaLink="true">https://zerodayroom.com/news/lazarus-group-exploits-windows-a82e1d/</guid><description>The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.</description><pubDate>16 August 2026</pubDate></item><item><title>737 Chrome VPN Extensions Caught Routing Traffic Through Proxies</title><link>https://zerodayroom.com/news/chrome-vpn-extensions-caught-af9804/</link><guid isPermaLink="true">https://zerodayroom.com/news/chrome-vpn-extensions-caught-af9804/</guid><description>A set of 737 free VPN and proxy extensions have been found to target Russian-speaking users, intercepting browser traffic and routing it through a proxy infrastructure.</description><pubDate>16 August 2026</pubDate></item><item><title>Flaw in AI Reasoning APIs Exposes Secrets and Private Data</title><link>https://zerodayroom.com/news/flaw-ai-reasoning-apis-aa04ef/</link><guid isPermaLink="true">https://zerodayroom.com/news/flaw-ai-reasoning-apis-aa04ef/</guid><description>Researchers have discovered a vulnerability in the AI reasoning APIs of OpenAI, Anthropic, and Google, allowing them to recover internal reasoning and secrets from session logs, including API keys and passwords.</description><pubDate>16 August 2026</pubDate></item></channel></rss>