CRITICAL
The Hacker News
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google Chrome V8 engine contains an actively exploited type confusion vulnerability (CVE-2026-85046, CVSS 8.8) affecting versions prior to 152.0.7977.82. Immediate patching is required to prevent remote code execution through malicious web content.
▸ countermeasure Immediately update all Chrome instances to version 152.0.7977.82 or later across all endpoints
ArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters' C-Track court management platform was breached in March 2026, exposing sensitive court records including SSNs and sealed data across 11 U.S. states and Canadian jurisdictions. Immediate defensive actions required to protect affected individuals and systems.
▸ countermeasure Audit all C-Track instances in your organization for unauthorized access logs between March-June 2026
ArrayArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
BraZetsu is a Python-based malware framework that compromises Windows hosts and converts them into sellable access inventory for Initial Access Brokers. This represents a critical threat to enterprise security as it enables systematic monetization of network breaches.
▸ countermeasure Implement behavioral detection for Python-based malware execution on Windows endpoints
ArrayArrayArrayArray
Open source advisory →
CRITICAL
BleepingComputer
HPE patches critical ArubaOS-CX remote code execution flaw
HPE ArubaOS-CX contains a critical RCE vulnerability requiring immediate patching. Network switches running affected versions are at risk of unauthorized remote code execution.
▸ countermeasure Identify all ArubaOS-CX devices in your network inventory
ArrayArray
Open source advisory →
CRITICAL
BleepingComputer
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure to distribute malicious Terraform modules with credential-stealing capabilities. Organizations using Coder's registry may have downloaded compromised infrastructure-as-code containing embedded malware.
▸ countermeasure Audit all Terraform modules sourced from Coder's registry for suspicious credential access patterns
ArrayArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Unauthenticated remote code execution as root affects Cisco Nexus 9000 Silicon One switches (CVE-2026-20212, CVSS 9.8). IOS XR also has 7 umbrella CVEs including two rated 9.8 with no available workarounds.
▸ countermeasure Immediately inventory all Cisco Nexus 9000 Silicon One-based switches in your environment
ArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA has added seven actively exploited vulnerabilities to the KEV catalog, including a critical CVSS 10.0 SSRF flaw in SonicWall SMA 1000 appliances. Attackers are deploying reverse shells and crypto miners through these vulnerabilities.
▸ countermeasure Immediately inventory all SonicWall SMA 1000 appliances in your environment
ArrayArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
CrowdStrike Falcon Sensor contains a privilege escalation vulnerability (FalconFlank) exploitable through the office malicious macros remediation feature. Immediate patching and monitoring for exploitation attempts are required.
▸ countermeasure Immediately update CrowdStrike Falcon Sensor to the latest patched version
ArrayArray
Open source advisory →
CRITICAL
BleepingComputer
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
CRITICAL
CISA News
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based o
▸ countermeasure Confirm exposure, apply vendor patches, add temporary WAF/IPS rules, and run post-patch vulnerability validation.
Open source advisory →
CRITICAL
CISA KEV
CVE-2026-85046 · Google Chromium V8
Google Chromium V8 Type Confusion Vulnerability
▸ countermeasure Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Open source advisory →
CRITICAL
CISA News
Preparing for the Post-Quantum Era: A Call to Action
CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats. The G7 Cyber Security Working Group’s call to action out
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
The Hacker News
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex Media Server and Desktop have patched multiple undisclosed security vulnerabilities in versions 1.43.3 and 1.115.0 respectively. Immediate patching is critical as CVE details are pending and exploitation risk is unknown.
▸ countermeasure Immediately update Plex Media Server to version 1.43.3 or later
ArrayArrayArray
Open source advisory →
HIGH
The Hacker News
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
▸ countermeasure Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.
Open source advisory →
HIGH
CISA News
Tycon Systems TPDIN-Monitor-WEB3
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabi
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA Loc
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
Inductive Automation Ignition
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Cri
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
Tycon Systems TPDIN-Monitor-WEB2 (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vend
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
Rockwell Automation 1756-ENBT Module
Rockwell Automation 1756-ENBT Module (all versions) contains an improper exception handling vulnerability (CVE-2025-10478) that can crash the module, requiring manual restart. This affects industrial control systems and requires immediate patching or mitigation.
▸ countermeasure Inventory all 1756-ENBT modules in your environment and document current firmware versions
ArrayArrayArray
Open source advisory →
HIGH
BleepingComputer
IDScan sued over alleged data breach affecting 153 million drivers
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
The Hacker News
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
▸ countermeasure Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.
Open source advisory →
HIGH
BleepingComputer
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
The Hacker News
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
The Hacker News
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →