VulnerabilitiesChrome Fixes Sixth Zero-Day of 2026: Active Attacks Target V8 Engine
Google patched CVE-2026-85046, a V8 type confusion zero-day exploited in the wild. Update Chrome to 152.0.7977.82+ immediately to stay protected.
VulnerabilitiesGoogle patched CVE-2026-85046, a V8 type confusion zero-day exploited in the wild. Update Chrome to 152.0.7977.82+ immediately to stay protected.
Cloud SecurityCoder registry was hijacked on Aug 31, 2026 to serve malicious Terraform modules stealing cloud credentials, AI keys and tokens. Learn impact and fixes.
VulnerabilitiesCVE-2026-77393 lets authenticated Ignition users create projects due to empty default role; affects 8.1.53 and earlier, fixed in 8.1.54.
VulnerabilitiesCisco fixed CVE-2026-20212 (CVSS 9.8) in 10 Nexus 9000 models allowing unauthenticated remote root code execution via TCP ports 43210, 43211.
VulnerabilitiesHPE fixed CVE-2026-73749, a critical 9.8 unauthenticated RCE flaw in ArubaOS-CX switches, plus 23 other vulnerabilities. Update affected versions now.
VulnerabilitiesCISA flags two Tycon TPDIN-Monitor-WEB2 flaws pre-2.4.5, including critical auth bypass CVE-2026-61884 allowing relay control. Fix: update to 2.4.5.
MalwareCitizen Lab confirmed Pegasus zero-click iMessage compromise of Serbian student activist's iPhone, amid 14 spyware targets and NoviSpy Android cases.
VulnerabilitiesCisco disclosed Sept 2026 flaws in Secure Email, IOS XR, Nexus 9000 and IP Phones, including S/MIME decryption issues, RCE and root compromise risks.
VulnerabilitiesCVE-2026-19949 in All-in-One WP Migration up to 7.109 enables RCE via second-order SQL injection, exposing 3.2M sites. Update to 7.110 immediately.