Friday , September 18 2026
zero-day

Hackers Allegedly Selling Exploit for Windows RDS 0-Day Flaw

A hacker is reportedly selling a zero-day exploit for a Windows Remote Desktop Services vulnerability, CVE-2026-21533, for $220,000 on the dark web. This exploit takes advantage of poor privilege management to give attackers local admin access.

A new user, Kamirmassabi, is auctioning an exploit for CVE-2026-21533 on a dark web forum. CVE-2026-21533 is a severe Elevation of Privilege (EoP) vulnerability rooted in improper privilege management within Windows Remote Desktop.

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

The threat actor, who created their account on March 3, 2026, posted the listing in the “[Virology] – malware, exploits, bundles, AZ, crypt” section.

                         Windows Remote Desktop Services 0-Day Claim (Source: Dark Web Informer)

This vulnerability impacts a vast array of Microsoft operating systems, including various builds of Windows 10, Windows 11, and Windows Server editions ranging from 2012 to the latest 2025 releases.

The vulnerability has a CVSSv3 score of 7.8, categorizing it as high severity. Its inclusion in the CISA Known Exploited Vulnerabilities list highlights the urgent need for fixing it.

Organizations should quickly apply the latest Microsoft security patches to all affected systems and servers. If unable to implement these patches right away, administrators should refer to CISA BOD 22-01 guidance for cloud services or disable Remote Desktop Services.

Administrators should disable RDS if not strictly necessary, restrict access to trusted networks, and deploy Endpoint Detection and Response (EDR) solutions to monitor for anomalous registry changes and privilege escalation attempts.

Check Also

German

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor …