緊急
The Hacker News
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google Chrome V8 engine contains an actively exploited type confusion vulnerability (CVE-2026-85046, CVSS 8.8) affecting versions prior to 152.0.7977.82. Immediate patching is required to prevent remote code execution through malicious web content.
▸ 対策 Immediately update all Chrome instances to version 152.0.7977.82 or later across all endpoints
ArrayArrayArray
公式アドバイザリを開く →
緊急
The Hacker News
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters' C-Track court management platform was breached in March 2026, exposing sensitive court records including SSNs and sealed data across 11 U.S. states and Canadian jurisdictions. Immediate defensive actions required to protect affected individuals and systems.
▸ 対策 Audit all C-Track instances in your organization for unauthorized access logs between March-June 2026
ArrayArrayArrayArray
公式アドバイザリを開く →
緊急
The Hacker News
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
BraZetsu is a Python-based malware framework that compromises Windows hosts and converts them into sellable access inventory for Initial Access Brokers. This represents a critical threat to enterprise security as it enables systematic monetization of network breaches.
▸ 対策 Implement behavioral detection for Python-based malware execution on Windows endpoints
ArrayArrayArrayArray
公式アドバイザリを開く →
緊急
BleepingComputer
HPE patches critical ArubaOS-CX remote code execution flaw
HPE ArubaOS-CX contains a critical RCE vulnerability requiring immediate patching. Network switches running affected versions are at risk of unauthorized remote code execution.
▸ 対策 Identify all ArubaOS-CX devices in your network inventory
ArrayArray
公式アドバイザリを開く →
緊急
BleepingComputer
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure to distribute malicious Terraform modules with credential-stealing capabilities. Organizations using Coder's registry may have downloaded compromised infrastructure-as-code containing embedded malware.
▸ 対策 Audit all Terraform modules sourced from Coder's registry for suspicious credential access patterns
ArrayArrayArrayArray
公式アドバイザリを開く →
緊急
The Hacker News
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Unauthenticated remote code execution as root affects Cisco Nexus 9000 Silicon One switches (CVE-2026-20212, CVSS 9.8). IOS XR also has 7 umbrella CVEs including two rated 9.8 with no available workarounds.
▸ 対策 Immediately inventory all Cisco Nexus 9000 Silicon One-based switches in your environment
ArrayArrayArray
公式アドバイザリを開く →
緊急
The Hacker News
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA has added seven actively exploited vulnerabilities to the KEV catalog, including a critical CVSS 10.0 SSRF flaw in SonicWall SMA 1000 appliances. Attackers are deploying reverse shells and crypto miners through these vulnerabilities.
▸ 対策 Immediately inventory all SonicWall SMA 1000 appliances in your environment
ArrayArrayArrayArray
公式アドバイザリを開く →
緊急
The Hacker News
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
CrowdStrike Falcon Sensor contains a privilege escalation vulnerability (FalconFlank) exploitable through the office malicious macros remediation feature. Immediate patching and monitoring for exploitation attempts are required.
▸ 対策 Immediately update CrowdStrike Falcon Sensor to the latest patched version
ArrayArray
公式アドバイザリを開く →
緊急
BleepingComputer
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
緊急
CISA KEV
CVE-2026-85046 · Google Chromium V8
Google Chromium V8 Type Confusion Vulnerability
▸ 対策 Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
公式アドバイザリを開く →
高
The Hacker News
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex Media Server and Desktop have patched multiple undisclosed security vulnerabilities in versions 1.43.3 and 1.115.0 respectively. Immediate patching is critical as CVE details are pending and exploitation risk is unknown.
▸ 対策 Immediately update Plex Media Server to version 1.43.3 or later
ArrayArrayArray
公式アドバイザリを開く →
高
The Hacker News
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
▸ 対策 Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.
公式アドバイザリを開く →
高
CISA News
Tycon Systems TPDIN-Monitor-WEB3
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabi
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
高
CISA News
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA Loc
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
高
CISA News
Inductive Automation Ignition
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Cri
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
高
CISA News
Tycon Systems TPDIN-Monitor-WEB2 (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vend
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
高
CISA News
Rockwell Automation 1756-ENBT Module
Rockwell Automation 1756-ENBT Module (all versions) contains an improper exception handling vulnerability (CVE-2025-10478) that can crash the module, requiring manual restart. This affects industrial control systems and requires immediate patching or mitigation.
▸ 対策 Inventory all 1756-ENBT modules in your environment and document current firmware versions
ArrayArrayArray
公式アドバイザリを開く →
高
BleepingComputer
IDScan sued over alleged data breach affecting 153 million drivers
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
高
The Hacker News
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
▸ 対策 Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.
公式アドバイザリを開く →
高
BleepingComputer
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
高
The Hacker News
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
高
The Hacker News
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →
高
BleepingComputer
39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]
▸ 対策 Rotate exposed keys, remove unused permissions, enable secret scanning, and review cloud audit logs for abuse.
公式アドバイザリを開く →
高
The Hacker News
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
▸ 対策 Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
公式アドバイザリを開く →