Zero Day Room
Live

Supply chain attacks

Everything filed under threats in our cybersecurity coverage, the 20 reports filed on it so far.

New Ofqual data reveals the proportion of UK schools hit by cyber incidents has fallen to 27%, while two-thirds can now...

Ofqual statistics show school cyber incidents falling to 27%

New Ofqual data reveals the proportion of UK schools hit by cyber incidents has fallen to 27%, while two-thirds can now recover immediately from...

2026-10-05
Microsoft has publicly detailed the NeedyMantis malware framework, discovered during analysis of the May 2026 Daemon...

Microsoft details China-linked NeedyMantis malware framework

Microsoft has publicly detailed the NeedyMantis malware framework, discovered during analysis of the May 2026 Daemon Tools supply chain attack.

2026-09-29
Two critical Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in...

NetScaler CVE-2026-88771 and CVE-2026-88772 Exploited

Two critical Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in zero-day attacks to deploy...

2026-09-28
Check Point has disclosed that a critical zero-day vulnerability in its Security Management Server was exploited in...

Check Point Zero-Day Exploited in Targeted July Attacks

Check Point has disclosed that a critical zero-day vulnerability in its Security Management Server was exploited in targeted attacks in July.

2026-09-22
Microsoft details two campaigns: one blasting CEO-impersonation invoice scams and another using passkey-themed social...

Microsoft Warns of Passkey Phishing Cloud Attacks

Microsoft details two campaigns: one blasting CEO-impersonation invoice scams and another using passkey-themed social engineering to hijack Microsoft...

2026-09-14
Tech: Google's Threat Intelligence Group reports that both criminal and state-backed hackers are using AI to automate attacks

Google Warns AI Gives Lesser Attackers Nation-State Capabilities

Google's Threat Intelligence Group reports that both criminal and state-backed hackers are using AI to automate attacks.

2026-09-09
The China-linked Fire Ant group compromised Cisco IOS XR routers to steal credentials, monitor networks, and launch...

Fire Ant Hackers Breach Cisco Routers

The China-linked Fire Ant group compromised Cisco IOS XR routers to steal credentials, monitor networks, and launch further attacks.

2026-09-02
Tech: Sevii has added an AI security module to its Autonomous Defense & Remediation platform

Sevii Launches AI Module for Autonomous Defense Platform

Sevii has added an AI security module to its Autonomous Defense & Remediation platform. It uses AI agents to analyze threats and execute remediation...

2026-09-01
Threat actors are now conducting hands-on-keyboard intrusions by chaining two critical PaperCut vulnerabilities...

PaperCut Attacks Now Active Intrusions

Threat actors are now conducting hands-on-keyboard intrusions by chaining two critical PaperCut vulnerabilities, CVE-2026-82078 and CVE-2026-81578.

2026-09-01
Aurora ransomware actors used SpaceX's Cursor Agent AI to aid attacks on 10 victims from April to May 2026, says Gambit...

Aurora Ransomware Uses Cursor AI in Attacks

Aurora ransomware actors used SpaceX's Cursor Agent AI to aid attacks on 10 victims from April to May 2026, says Gambit Security.

2026-08-29
Over 100 tech and cybersecurity firms, including OpenAI and Microsoft, warn AI-enabled attacks threaten critical...

Tech Giants Warn of Narrowing Window to Counter AI-Enabled Attacks

Over 100 tech and cybersecurity firms, including OpenAI and Microsoft, warn AI-enabled attacks threaten critical infrastructure.

2026-08-29
Attackers are exploiting two critical PaperCut vulnerabilities, CVE-2026-82078 and CVE-2026-81578, to achieve...

PaperCut Flaws Chained for Unauthenticated Attacks

Attackers are exploiting two critical PaperCut vulnerabilities, CVE-2026-82078 and CVE-2026-81578, to achieve unauthenticated remote code execution.

2026-08-28
The U.S. Department of Justice dismantled the QScan and QTRouter hacking platforms linked to Chinese state-backed attacks...

US DOJ Takedown of Chinese QScan, QTRouter

The U.S. Department of Justice dismantled the QScan and QTRouter hacking platforms linked to Chinese state-backed attacks on federal agencies, citing...

2026-08-26
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery...

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert...

2026-08-21
A supply chain attack on the Rust programming language has compromised three widely used crates, potentially affecting...

Rust Supply Chain Attack Compromises Crates with 245 Million Downloads

A supply chain attack on the Rust programming language has compromised three widely used crates, potentially affecting 245 million downloads. The...

2026-08-21
Tech: Cybersecurity researchers have discovered updates to the ToxicPanda and GoldDigger Android malware

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks

Cybersecurity researchers have discovered updates to the ToxicPanda and GoldDigger Android malware.

2026-08-20
Security researchers have discovered a two-stage exploit chain that achieves full Android kernel access on devices...

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers have discovered a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware...

2026-08-18
A vulnerability in Snowflake's public GitHub repository allowed attackers to inject commands into a workflow containing...

Snowflake GitHub Actions Flaw Exposes Jira Credentials to Workflow Injection Attacks

A vulnerability in Snowflake's public GitHub repository allowed attackers to inject commands into a workflow containing internal Jira credentials...

2026-08-17
Two high-severity vulnerabilities have been discovered in popular WordPress plugins, Forminator Forms and User Profile...

Critical Flaws in WordPress Plugins Expose Sites to Unauthenticated RCE and Auth Bypass Attacks

Two high-severity vulnerabilities have been discovered in popular WordPress plugins, Forminator Forms and User Profile Builder, allowing...

2026-08-17
A recent report by Picus Labs reveals that enterprise defenses have made significant improvements at the perimeter, but...

Enterprise Defenses Recovered at the Edge, Collapsed Inside

A recent report by Picus Labs reveals that enterprise defenses have made significant improvements at the perimeter, but are struggling to prevent...

2026-08-16