The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible.
Hi, what are you looking for?
The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible.
The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities.
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.
Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix.
Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data.
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.
Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.
Administrators are advised to check their deployments for newly created user accounts they don’t recognize.
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance.
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.
The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates.
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution.
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine.
Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed...
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents.