Zero Day Room
Vulnerabilities
Actively exploited CVEs
Critical severity this month
Microsoft
Cisco
Fortinet
Ivanti
VMware
Oracle
SAP
RCE
privilege escalation
auth bypass
deserialisation
Patch Tuesday and vendor patch cycles
End of life and unsupported software
How CVSS and EPSS scoring work
VPN and edge devices
firewalls
file transfer software
hypervisors
mail servers
identity providers
backup software
network management
Zero days confirmed exploited in the wild
Vulnerabilities with no patch available and only vendor mitigations
Additions to the known exploited vulnerabilities catalogue this week
Prioritising with severity, exploitation status and exposure together
Vendor disclosure policies and advisory quality
Bug bounty programme changes
Deprecated protocols and default credentials
Firmware and out of band management exposure
Threats
Ransomware groups and campaigns
Business email compromise
Supply chain attacks
Phishing and credential theft
Info stealers
Cloud account compromise
OT and ICS attacks
Mobile threats
Threat actor tracking and naming conventions
Initial access brokers and how access is resold
Abuse of legitimate administration tools, described defensively
SIM swap and telecommunications fraud
Distributed denial of service and hacktivist campaigns in the region
Cryptocurrency and exchange theft
Third party and software as a service compromise
Insider risk
Deepfake enabled business email compromise
Attacks on managed service providers
Scam compounds and organised online fraud in Southeast Asia
How threat actor names differ between vendors
Defence
Patch management
Multi-factor authentication and phishing resistance
Backup and recovery that survives ransomware
Network segmentation
Endpoint detection and response
Logging and detection engineering
Identity and access management
Incident response planning
Tabletop exercises
Security for small organisations with no security team
Asset inventory and finding shadow IT
Designing a vulnerability management programme
Secure configuration baselines
SPF
DKIM and DMARC
DNS filtering and egress control
Application allowlisting
Secrets management and key rotation
Cloud security posture management
Third party and vendor risk assessment
Security awareness training that measurably works
Recovery testing, recovery point and recovery time objectives
Log retention and what to keep
Regulation & compliance
CERT-In directions
DPDP Act
Cybersecurity Act
PDPA
Japan and Korea: reporting obligations
MLPS
PIPL
data export rules
Indonesia, Philippines, Vietnam: data and cyber laws
Breach notification timelines by country
Critical infrastructure designations
Cross-border data transfer
Incidents
Confirmed breaches
finance
health
telecom
government
Post-incident reports and lessons
Data leak verification
Regulatory penalties issued
Recovery timelines
Supply chain incident timelines
How organisations disclosed and what it cost them
Regulatory enforcement and penalties by market
Class actions and consumer redress
Recovery case studies and what worked
What good disclosure looks like
Incidents where the initial claim turned out to be false
News
Advisories and CERTs
India: CERT-In advisories and directions
Singapore: SingCERT and the Cyber Security Agency
Japan: JPCERT/CC and IPA
South Korea: KrCERT/CC and KISA
Australia: the Australian Cyber Security Centre
Hong Kong: HKCERT
Taiwan: TWCERT/CC
Indonesia: BSSN
Malaysia: MyCERT and NACSA
Philippines: the Department of Information and Communications Technolo
Vietnam: VNCERT
United States: CISA advisories and the known exploited vulnerabilities
ENISA
NCSC UK
BSI CERT-Bund
Industrial control system advisories
Vendor product security incident response teams
Vendors and products
Windows
Windows Server
Exchange
SharePoint
Entra ID
Cisco
Fortinet
Palo Alto Networks
Ivanti
Citrix
SonicWall
Zyxel
F5
Virtualisation and infrastructure: Broadcom VMware, Nutanix, Proxmox
File transfer and collaboration: Progress MOVEit, Atlassian, GitLab, J
Oracle
SAP
Salesforce integrations
Apache projects
Linux kernel
OpenSSL
Kubernetes
container runtimes
Veeam
QNAP
Synology
Commvault
Windows
macOS
Android
iOS
Chrome
Firefox
Edge
Identity providers and single sign on
How to find out what you actually run
Info stealers
Info stealers - reporting from Zero Day Room.
No articles filed here yet. New reporting appears as it is published.