Zero Day Wire

Zero Day Wire
Critical MetInfo and Weaver E-cology Flaws Under Active Exploitation — Unauthenticated RCE Targeting Chinese Enterprise Infrastructure

Alerts

Critical MetInfo and Weaver E-cology Flaws Under Active Exploitation — Unauthenticated RCE Targeting Chinese Enterprise Infrastructure

Two critical vulnerabilities in widely deployed Chinese enterprise software are under active exploitation, with threat actors leveraging unauthenticated remote code execution flaws in MetInfo CMS and Weaver E-cology to compromise servers without requiring any credentials. CVE-2026-29014 (CVSS 9.8) affects MetInfo, a PHP and MySQL-based enterprise

By Zero Day Wire
Microsoft Defender Zero-Day Exploited in the Wild — BlueHammer Attack Chain Extracts SAM Hashes and Kills Defender via Race Condition

Alerts

Microsoft Defender Zero-Day Exploited in the Wild — BlueHammer Attack Chain Extracts SAM Hashes and Kills Defender via Race Condition

A privilege escalation vulnerability in Microsoft Defender is under active exploitation using publicly available proof-of-concept code, with Huntress confirming attacks began on April 10 — four days before Microsoft released a patch. CISA added the flaw to its Known Exploited Vulnerabilities catalog on Wednesday, setting a May 6 federal

By Zero Day Wire