US sanctions Russian broker for buying stolen zero-day exploits

US sanctions Russian broker for buying stolen zero-day exploits

• US sanctions Russian broker for buying stolen zero-day exploits February 25, 2026 05:31 AM 0 The U.S. • Treasury Department has sanctioned a Russian exploit broker who bought sto

Cybersecurity · February 25, 2026 (updated February 25, 2026) · 2 min · 230 words
ZDI-26-120: GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI-26-120: GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

• Remote attackers can execute arbitrary code via GIMP ICNS file parsing. • Exploit requires user interaction: opening malicious file or visiting malicious page. • Vulnerability du

Threat Intelligence · February 19, 2026 (updated February 24, 2026) · 1 min · 158 words
ZDI-26-107: Autodesk AutoCAD MODEL File Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI-26-107: Autodesk AutoCAD MODEL File Out-Of-Bounds Write Remote Code Execution Vulnerability

• Remote code execution via out-of-bounds write in AutoCAD MODEL file parsing. • Requires user to open malicious file or visit malicious page. • Exploit writes past allocated buffe

Threat Intelligence · February 18, 2026 (updated February 24, 2026) · 3 min · 565 words
Singapore & Its 4 Major Telcos Fend Off Chinese Hackers

Singapore & Its 4 Major Telcos Fend Off Chinese Hackers

• Singapore’s CSA and four telcos launched ‘Cyber Guardian’ to counter China-linked UNC3886.\n• 100+ incident responders coordinated across government and M1, Singtel, StarHub, Sim

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 1 min · 177 words
Update Chrome now: Zero-day bug allows code execution via malicious webpages

Update Chrome now: Zero-day bug allows code execution via malicious webpages

• Update Chrome now: Zero-day bug allows code execution via malicious webpages Google hasissueda patch for a high‑severity Chrome zero‑day, tracked asCVE‑2026‑2441, a memory bug in

Threat Intelligence · February 17, 2026 (updated February 25, 2026) · 2 min · 226 words
New Chrome Zero-Day (CVE-2026-2441) Under Active Attack - Patch Released

New Chrome Zero-Day (CVE-2026-2441) Under Active Attack - Patch Released

• New Chrome Zero-Day (CVE-2026-2441) Under Active Attack - Patch Released Google on Friday released security updates for its Chrome browser to address a security flaw that it said

Cybersecurity · February 16, 2026 (updated February 24, 2026) · 4 min · 709 words
Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again

Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again

• Endpoint Security Cyberattacks & Data Breaches Vulnerabilities & Threats Perimeter News Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again It’s time to phase out the ‘patch a

Cybersecurity · February 12, 2026 (updated February 24, 2026) · 2 min · 399 words
CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

• CVE-2025-6978 exposes command injection in Arista NG Firewall’s diagnostics component. • Remote authenticated attackers can craft HTTP requests to execute arbitrary commands as r

Threat Intelligence · February 5, 2026 (updated February 24, 2026) · 1 min · 164 words
Microsoft releases update to address zero-day vulnerability in Microsoft Office

Microsoft releases update to address zero-day vulnerability in Microsoft Office

• Microsoft releases update to address zero-day vulnerability in Microsoft Office Microsoft has published three out-of-band (OOB) updates so far in January 2026. • One of these upd

Threat Intelligence · January 29, 2026 (updated February 24, 2026) · 2 min · 226 words
Pwn2Own Automotive 2026 - Day One Results

Pwn2Own Automotive 2026 - Day One Results

• 76 unique 0‑day vulnerabilities discovered across three days, totaling $1,047,000 in rewards. • Fuzzware.io clinched Master of Pwn with 28 points, outperforming rivals like Team

Threat Intelligence · January 21, 2026 (updated February 24, 2026) · 3 min · 465 words
Sanctioned but Still Spying: Intellexa's Prolific Zero-Day Exploits Continue

Sanctioned but Still Spying: Intellexa's Prolific Zero-Day Exploits Continue

• Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats tha

Threat Intelligence · December 3, 2025 (updated February 24, 2026) · 1 min · 206 words