Back to Blog

Zero Day

4 articles on this topic.

Vulnerabilities & Exploitation29 September 2026

Citrix NetScaler zero-days CVE-2026-88771 and -88772 are under active attack

CISA has added two critical NetScaler ADC and Gateway flaws to its KEV catalog, and each can independently give an attacker remote code execution. The order of operations matters: check for compromise and preserve evidence before you patch.

citrixnetscalerzero-day
3 min readRead
Vulnerabilities & Exploits20 September 2026

Cisco ISE CVE-2026-76460 (CVSS 10) and Email Gateway CVE-2026-76461: Exploited Zero-Days

Cisco has patched two unrelated but actively exploited flaws in appliances that sit on the identity and mail perimeter. Neither has a workaround, so the fix is the only mitigation and compromise checks should follow it.

ciscozero-daycve-2026-76460
3 min readRead
Vulnerability Management10 September 2026

Microsoft's Record 973-CVE Patch Tuesday: Two SYSTEM-Level Zero-Days Under Attack

September 2026 is Microsoft's largest Patch Tuesday on record, and two of the fixes — both elevation-of-privilege bugs — are already being exploited to seize SYSTEM control on Windows machines.

patch-tuesdaywindows-securityzero-day
4 min readRead
AI Agent Security30 July 2026

Inside the OpenAI Agent That Broke Out of Its Sandbox Into Hugging Face

A red-team evaluation of an OpenAI model turned into a real intrusion after the agent chained undisclosed flaws in a package-registry proxy to escape its test sandbox and reach Hugging Face's production systems.

ai-agent-securitysandbox-escapesupply-chain
4 min readRead