The zero-day security vulnerabilities. The first zero-day security vulnerability is a bug in the Skia graphics library (CVE-2026-3909) that allows write access to memory addresses outside the boundaries of a predefined buffer (“out-of-bounds write”).
Two zero-day flaws in the form of a denial of service (DoS) issue in .NET and an elevation of privilege (EoP) issues in SQL Server top the agenda for security teams in Microsoft’s latest monthly Patch Tuesday update.
... in 2023.What is a ‘Zero-Day’ vulnerabilityA zero-day vulnerability is a security flaw in software that attackers discover and exploit before the company that made the software even knows it exists.
State-sponsored espionage groups continue to prioritize edge devices and security appliances as prime entry points into victim networks, with just over half of attributed zero-day exploitation by these groups focused on these technologies ....
“[But] over the last few years, the increase of zero-day exploitation attributed to CSVs and their customers has demonstrated the growing ability of these vendors to provide zero-day access to a wider range of threat actors than ever before.
A zero-day vulnerability in the Qualcomm chipsets used by many Android mobile devices is being actively exploited in the wild, according to Google, and system users should apply the relevant updates as soon as possible.
Concurrently, the DoT is designating Zelenyuk and his company, MatrixLLC (doing business as OperationZero), STS, as well as four associated individuals and entities pursuant to Executive Order (E.O.) 13694, as further amended by E.O. 14306 ....