Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A new zero-day vulnerability in Apple's WebKit, identified as CVE-2025-14174, has been confirmed and is actively being exploited. This follows the recent disclosure of another critical zero-day vulnerability in Gladinet’s Triofox, CVE-2025-12480. The ongoing exploitation of these vulnerabilities hig...
Google and Apple released urgent security updates to address zero-day vulnerabilities affecting their platforms. The vulnerabilities were exploited in a sophisticated attack targeting specific users, with one bug actively exploited before a patch was available. Apple identified two zero-day flaws tr...
A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subseque...
On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing sig...