Skip to content
HiveSecurity
  • Home
  • Blog
  • Tags
  • Vulnerabilities
    • Tools
    • Cheat Sheet
    • Security Guides
  • Contact
  • About
Esc
Type to search...
  • Home
  • Blog
  • Tags
  • Vulnerabilities
  • Resources
  • Tools
  • Cheat Sheet
  • Security Guides
  • Contact
  • About
← All tags Tag

Zero-Day

7 articles

Chrome CVE-2026-85046: Updating Is Easy. Proving Every Browser Updated Is Not

Google says an exploit for CVE-2026-85046 exists in the wild. Defenders need to deploy Chrome 152.0.7977.82 or .83 and verify the running version across managed and unmanaged endpoints.

9 September 2026
Vulnerability Browser Security Zero-Day

SonicWall SMA1000 Zero-Day Chain: Patch It, Then Assume It Was Breached

CVE-2026-83548 and CVE-2026-83549 are being exploited against SonicWall SMA1000 appliances. Patching closes the flaws, but exposed gateways still need compromise assessment and credential recovery.

8 September 2026
Vulnerability Network Security Zero-Day

Exploited Before the PoC Existed: CVE-2026-46817 in Oracle Payments

A critical, unauthenticated flaw in Oracle E-Business Suite's Payments module was hit in the wild on June 27, 2026 — six weeks after the patch, with no public exploit code anywhere. Here's what's confirmed, what's still speculation, and how to check if you're exposed.

21 July 2026
ERP Security Vulnerability Management Blue Team

ShinyHunters Were Inside Two Weeks Before Oracle Noticed

A critical, unauthenticated RCE in Oracle PeopleSoft let ShinyHunters compromise universities and other organizations for weeks before Oracle's advisory caught up. Google notified 100+ potentially exposed organizations. The technical breakdown, IOCs, and what to hunt for.

17 June 2026
Threat Intelligence Vulnerability Zero-Day

RoguePlanet: Nightmare Eclipse's New Windows Defender LPE PoC After the June 2026 Patch

RoguePlanet is the latest public Nightmare Eclipse proof-of-concept targeting Microsoft Defender. The code points to a race condition that turns Defender cleanup behavior into SYSTEM execution.

10 June 2026
Windows Vulnerability Zero-Day

YellowKey: The BitLocker Bypass Hidden in Windows Recovery

A researcher discovered a zero-day that bypasses BitLocker encryption on Windows 11 using a USB stick and the recovery environment — and suspects the component may be intentional. CVE-2026-45585, CVSS 6.8. Microsoft released an official mitigation on May 21, 2026.

Updated 21 May 2026
Windows Vulnerability Encryption

CVE-2026-42897: Exchange Server Zero-Day Executes JavaScript Through Your Inbox

Microsoft's on-prem Exchange Server has an actively exploited XSS zero-day (CVSS 8.1). A single crafted email in OWA triggers arbitrary JavaScript — here's how it works and how to stop it.

16 May 2026
Cybersecurity Web Security Blue Team
HiveSecurity

Offensive thinking. Defensive expertise.

Content
  • Home
  • Blog
  • Tags
  • Vulnerabilities
Resources
  • Tools
  • Cheat Sheet
  • Security Guides
Company
  • Contact
  • About
  • RSS
  • Privacy
  • Security Policy

© 2026 Hive Security. All rights reserved.

Built with zero trust & least privilege