Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics

Zero-day exploit stories

Sep 8, 2026

Microsoft's September 2026 Patch Tuesday sets record with over 970 vulnerabilities fixed

Microsoft released its largest-ever security update in September 2026, patching between 966 and 974 vulnerabilities across its products, including 112 critical-severity flaws. Two vulnerabilities were already being actively exploited before patches were released, and security analysts highlighted concerns about an unauthenticated Exchange Server remote code execution flaw and 20 wormable bugs.

Sep 8, 2026·5 sources
00
May 13, 2026

Google Detects First AI-Generated Zero-Day Exploit Used by Criminal Hackers

Google's Threat Intelligence Group reported catching the first live zero-day exploit built with AI assistance, used by criminal and state-backed hackers. The exploit was discovered targeting software vulnerabilities before patches were available.

May 13, 2026·3 sources
00
May 12, 2026

Google Reports AI-Powered Hacking Has Reached Industrial Scale

Google disclosed that criminal groups and state-linked actors are using commercial AI models to refine and scale up cyberattacks, with evidence showing hackers used AI to build zero-day exploits before Google disrupted the operation.

May 12, 2026·2 sources
00

Google Reports Hackers Used AI to Build Zero-Day Attack

Google disclosed that hackers used AI and a large language model to create a zero-day exploit, though the company declined to name the threat actor or specific LLM used. Google stated researchers don't believe it was created using Anthropic's models.

May 12, 2026·1 source
00

Top claims

  • ▪The September 8, 2026 Microsoft release included CVE-2026-65669, a CVSS 9.6 elevation of privilege vulnerability in SQL Copilot, the AI assistant in SQL Server Management Studio, which allows attackers to access databases using a victim's permissions.
  • ▪The September 8, 2026 release addressed two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, which were actively exploited in the wild before the patches were released.
  • ▪In August 2026, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 other organizations published an open letter warning of a narrowing window to patch vulnerabilities before AI-enabled attackers exploit them.

Subtopics

AI security3AI2Cybersecurity threats2Critical infrastructure security1Cybercrime1Cybersecurity1Cybersecurity vulnerabilities1Enterprise AI security1Large language models (LLMs)1

Related timelines

AI Data Center Gold Rush

101 stories

Congress

108 stories

Crypto hacks

100 stories

Ebola outbreak

58 stories

Iran War

209 stories