Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Google has issued emergency updates to address the eighth zero-day vulnerability in Chrome for 2025. The flaw, identified as 466192044, was actively exploited in the wild, prompting the company to roll out fixes for users on Windows and macOS. The updates are now available in the Stable Desktop chan...
A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subseque...
On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing sig...
Intellexa, a spyware maker known for its Predator software, has been found to have remote access to the surveillance systems of its government clients, allowing staff to view personal data of hacked individuals. Despite being sanctioned by the US government, Intellexa continues to operate and evade...