Chrome 149 Update Patches 28 Vulnerabilities
Chrome 149 patched 429 vulnerabilities, including zero-day CVE-2026-11645 actively exploited in June 2026. Attackers chained this V8 flaw with sandbox escapes for unrestricted code execution.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Chrome 149 patched 429 vulnerabilities, including zero-day CVE-2026-11645 actively exploited in June 2026. Attackers chained this V8 flaw with sandbox escapes for unrestricted code execution.
Critical unauthenticated RCE in Ivanti Sentry allows root-level command execution. Active exploitation detected via honeypots globally. Attackers have complete system control once compromised.
Iranian cyber group Handala claims California Water Company breach with 5GB stolen customer data and platform credentials affecting 2M residents, posing risks to critical infrastructure security.
Security experts debate Claude Fable 5's safeguards. While Anthropic implemented tiered access controls, the model's speed and lower cost increase accessibility for both legitimate and malicious uses, raising dual-use concerns despite built-in safety measures.
Operation Ramz shut down Sniper Dz phishing platform, arresting 201 attackers across 13 countries. The decade-long marketplace attacked financial institutions and governments in MENA.
Self-hosted LangGraph deployments are vulnerable to remote code execution through SQL injection and unsafe deserialization flaws affecting SQLite and Redis checkpoints. The managed LangSmith cloud platform is unaffected. Immediate patching is critical for self-hosted instances.
AI-powered attacks now exceed MDR capabilities: 60% of alerts go unreviewed as human analysts drown in noise. Attackers exploit this structural gap, hiding threats at speeds security teams cannot match.
Agentjacking exploits AI coding agents like Claude Code through malicious Sentry errors, tricking them into executing arbitrary code with full developer privileges. This attack bypasses traditional security entirely by exploiting trust in error-tracking integrations, achieving 85% success in testing
Danish pharma giant Novo Nordisk disclosed a breach exposing pseudonymized clinical trial data and healthcare professional contacts, raising concerns about data protection standards in the regulated pharmaceutical sector. The incident marks a security lapse at the world's largest insulin producer am
Microsoft fixed a year-long Windows update bug affecting enterprise deployments. The WUSA installer failed when deploying multiple updates from network shares, impacting Windows 11 and Server 2025 since May 2025.
Anthropic disputed researcher Pliny the Liberator's Fable 5 jailbreak claims and released system prompts. The debate centers on whether multi-agent prompting represents a genuine safety bypass or inherent LLM behavior.
Ivanti Sentry's unauthenticated RCE (CVE-2026-10520) is actively exploited, with backdoors established hours after patching. This critical gateway vulnerability threatens enterprise perimeter access and CISA's 72-hour deadline signals urgent remediation priority.
Tchap, France's government messenger, was breached, exposing 73,000 employees' contact details. The leaked metadata compromises government security despite encrypted messages remaining protected.
Google confirmed ShinyHunters actively exploits PeopleSoft zero-day CVE-2026-35273, which Oracle hasn't publicly disclosed. Unknown organizations face compromise with unconfirmed breach scope.
Europol dismantled AudiA6, a crypto laundering service that processed €336 million for ransomware gangs. The takedown severed a critical financial pipeline for organized cybercrime.
Fraudsters exploited Maine's unverified breach database to file fake breach notifications under VRChat and Discord. This reveals a critical gap in how states vet and publish breach disclosures that millions of consumers rely on.
Kyushu Electric lost a backup drive with 10.9M customers' data from a locked server room, signaling a security breach or insider threat. The missing data includes names, addresses, and usage records but excludes financial information.
Two critical authentication flaws in Brickcom cameras expose live feeds and administrative access to unauthenticated attackers worldwide. No patch is available as the vendor ignores CISA coordination requests, leaving critical infrastructure like hospitals and financial institutions vulnerable.
Naxclow IoT devices suffer three critical flaws enabling silent takeover and permanent unauthorized access. The vendor remains unresponsive to disclosure, leaving no patches or timeline for fixes.
ShinyHunters exploited a critical Oracle PeopleSoft zero-day exposing 455,000+ individuals across 100+ organizations, primarily universities. The unauthenticated RCE flaw was patched June 10.
Hard-coded MQTT credentials in Yarbo apps expose thousands of robots to remote command injection attacks. Attackers can monitor and control devices fleet-wide using only a serial number, risking disruption of critical infrastructure operations.
OT networks need more than network segmentation: textbook best practices create false security when implementation and monitoring fall short. Vigilant oversight remains critical.
Critical Ivanti vulnerability enabling unauthenticated RCE was exploited within 24 hours of disclosure. Attackers had pre-reconnaissance on customer networks before patch details were public.
Despite a 20% drop in phishing volume, success rates surged 40-60% as attackers use AI for personalized, harder-to-detect campaigns. Fewer attacks land, but more succeed—a dangerous paradox that demands smarter defense strategies. (186 characters, 2 sentences)