Chrome 148 Update Patches 151 Vulnerabilities
Google released Chrome 148 with 151 security patches, including critical flaws enabling remote code execution. It's one of the largest security releases in Chrome's history.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
Google released Chrome 148 with 151 security patches, including critical flaws enabling remote code execution. It's one of the largest security releases in Chrome's history.
Russian-linked GREYVIBE has targeted Ukraine with AI-powered malware since August 2025, striking military, government, and civilian targets. The state-sponsored group merges state resources with cybercriminal tactics across six documented attack chains.
Google engineer Michele Spagnuolo used confidential "Year in Search" data to place highly accurate bets on Polymarket under the alias "AlphaRaccoon," netting $1.2 million before federal authorities uncovered the insider trading scheme. He faces charges from the SEC and CFTC.
Troy Murray sold data on 7M elderly Americans to scammers for $5.2M, enabling $9.5M in fraud. Sentenced to 10+ years, his prosecution exposes the hidden data layer of elder fraud schemes.
Google rolls out Device-Bound Session Credentials globally to protect against session cookie theft, which can bypass MFA. The feature binds cookies to devices, preventing stolen credentials from being used for account takeover.
Kimsuky deployed HTTPSpy and exploited VS Code Tunnels against South Korean military/tech sectors via spear-phishing in March-April 2026. IT admins were compromised with spoofed security lures.
Frontier X/X2 wearables lack Bluetooth authentication, enabling attackers to manipulate health data remotely. CVE-2026-5768 (CVSS 8.8) threatens patient safety through data poisoning.
ABB Busch-Welcome door actuators (CVE-2025-7705) have debug code enabled by default, letting attackers bypass authentication and gain unauthorized building access with just physical proximity. The flaw affects access control systems protecting offices, data centers, and secure facilities worldwide.
Hard-coded credentials in PUSR USR-W610 firmware enable full device takeover via network access. CVE-2026-7786 (CVSS 9.8) threatens manufacturing and utility infrastructure deployed globally.
Schneider Electric disclosed CVE-2026-6332, a cleartext vulnerability in HVAC control software used across critical infrastructure. Local attackers with system access can steal proprietary control logic, potentially enabling manipulation of data centers, water treatment plants, and manufacturing fac
ABB EIBPORT gateways vulnerable to session hijacking (CVE-2021-22291, CVSS 8.0), allowing authenticated attackers to reconfigure building automation systems controlling HVAC, lighting, and security. Patch: firmware 3.9.2+.
Dutch police seized 800 servers from Russian bulletproof host THE.Hosting and arrested two operators, but the provider's core infrastructure survived intact and could resume operations quickly.
Geordie raised $30M to govern AI agents at enterprise scale. The platform provides real-time visibility and control over autonomous systems, solving critical security and compliance risks.
Agentic AI's real security risk lies in how developers code it, not the AI itself. Teams overlook vulnerabilities in the code connecting models to tools and systems, treating AI as a black box rather than auditing the actual integration code where security gaps reside.
Threat actors exploit CVE-2026-35616 in Fortinet's EMS to bypass authentication, inject malicious scripts, and deploy a credential stealer to all connected endpoints via a fake update.
Gogs has an unpatched RCE in Git rebase operations allowing authenticated users to execute arbitrary code. The exploit requires minimal setup, risking full server compromise and credential theft across all repositories.
A Fortinet FortiClient flaw (CVE-2026-35616) enables attackers to deploy credential-stealing malware disguised as security updates, exposing passwords, financial data, and session tokens. The vulnerability bypasses authentication, allowing remote code execution across thousands of internet-exposed i
CVE-2026-35616 is a critical unauthenticated RCE in FortiClient EMS actively being exploited. Attackers distribute credential-stealing malware using legitimate management pathways, threatening entire enterprise networks.
BTMOB, a $5,000 Android RAT with a no-code builder, lets non-technical criminals compromise devices via malware-as-a-service. It offers full control and SMS interception, surging across Latin America.
Critical Gogs zero-day allows RCE on 2,400+ servers through malicious branch names in pull requests. Unpatched in versions 0.14.2 and 0.15.0; default configurations make most instances vulnerable.
Cyber insurers now demand quantified risk assessments, forcing organizations to measure security maturity. This links insurance rates to security practices, driving executive investment in defenses.
Researcher publicly disclosed unpatched Microsoft zero-days. Microsoft criticized the action, sparking debate over coordinated vs public disclosure practices amid the researcher's account suspension.
Despite rapid threat detection, incident response stays slow due to manual investigation and coordination delays across departments. AI-assisted automation could streamline the investigation phase to reduce overall dwell time and breach impact.
MSPs struggle with alert fatigue, missing real threats buried in millions of daily log events. SIEM platforms help filter noise and prioritize genuine security risks, enabling faster threat response and better client protection.
Autonomous AI attacks now move faster than human defenders can respond, adapting and scaling exponentially across multiple vectors. This speed asymmetry has rendered traditional cybersecurity defenses obsolete, forcing CISOs to fundamentally rethink organizational security strategies.
A critical container registry flaw in Gitea (CVE-2026-27771) allowed unauthenticated attackers to download private container images from ~31,750 self-hosted instances for nearly four years, exposing source code, credentials, and infrastructure secrets to widespread compromise across organizations wo
Edamame detects when AI agents drift from intended behavior and leak secrets—a blind spot in current security. The startup fills this gap as developers deploy AI agents with deep system access.
Nordic CISOs report stable cyberattack severity, contradicting AI-surge predictions. Either AI attacks haven't materialized as feared or organizations have successfully adapted defenses.
CISA flagged three actively exploited vulnerabilities in its KEV Catalog, including embedded malicious code in widely-used tools like Daemon Tools Lite and Nx Console. The additions underscore an escalating supply chain threat, with adversaries targeting popular software to compromise downstream use
Britain's top intelligence chief warns that Russia is escalating hybrid cyberattacks—including AI, critical infrastructure strikes, and election interference—in a "gray zone" below traditional warfare. Western nations risk losing the cyberspace battle unless governments and companies dramatically st