Saturday, January 17, 2026
HomeZero-day

Zero-day

CISA Alerts Public To Active Exploitation Of Android Zero-Day Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two high-severity Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog on December 2, 2025, signaling active exploitation in the wild. CVE-2025-48572 enables local elevation of privilege, while CVE-2025-48633 allows information disclosure, both affecting core...

Broadcom Reportedly Hit By Clop Ransomware Through Oracle E-Business Suite Zero-Day Vulnerability

The Cl0p ransomware group claimed responsibility for breaching Broadcom, a major semiconductor firm, by exploiting a zero-day flaw in Oracle E-Business Suite. This incident fits into Cl0p's broad campaign targeting enterprise systems since August 2025. Broadcom confirmed targeting but stated it patched the vulnerability...

Oracle Reportedly Hit By Clop Ransomware Using E-Business Suite Zero-Day Vulnerability

The notorious Clop ransomware gang has posted Oracle on its dark web leak site, claiming a significant breach of the tech giant's internal systems. This attack exploits a critical zero-day vulnerability in Oracle E-Business Suite (EBS), tracked as CVE-2025-61882. Known as Graceful Spider, the...

CISA Alerts Users To Active Exploitation Of New Google Chrome Zero-Day

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-13223, a high-severity type confusion vulnerability in Google Chromium's V8 JavaScript engine, to its Known Exploited Vulnerabilities (KEV) catalog. This zero-day flaw allows remote attackers to trigger heap corruption via specially crafted HTML pages,...

FortiWeb Hit By Newly Discovered 0-Day RCE Vulnerability Actively Exploited

Fortinet's popular web application firewall, FortiWeb, faces a serious threat from a newly discovered zero-day vulnerability that enables remote code execution (RCE). This flaw, classified as an OS Command Injection issue under CWE-78, allows authenticated attackers to run unauthorized commands on the device's underlying...

Washington Post Oracle E-Suite Breach Exposes Data Of Over 9,000 Employees and Contractors

The Washington Post has disclosed a significant data breach that compromised sensitive information for 9,720 current and former employees and contractors. This incident, linked to a zero-day vulnerability in Oracle's E-Business Suite software, occurred between July 10 and August 22, 2025, but was only...