105Articles
9Categories
2026-03-13Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-3909 Google Skia Out-of-Bounds Write Vulnerability CVE-2026-3910 Google Chromium V8 Unspecified Vulnerability These types of vulnerabil…
KEV
πŸ›
OpenSSH GSSAPI Flaw Can Be Exploited to Crash SSH Child Processes
πŸ›
Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution
πŸ›
Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8
KEV
πŸ›
CVE-2026-3904
πŸ›
CVE-2026-3805 use after free in SMB connection reuse
πŸ›
Two Newly Discovered Chrome Zero-Days Exploited in the Wild to Run Malicious Code
KEV
πŸ›
Veeam warns admins to patch now as critical RCE flaws hit Backup & Replication
KEV
πŸ›
New Critical AdGuard Home Flaw Lets Attackers Bypass Authentication
πŸ›
Google warns of two actively exploited Chrome zero days
KEV
πŸ›
Chromium: CVE-2026-3942 Incorrect security UI in PictureInPicture
πŸ›
Chromium: CVE-2026-3931 Heap buffer overflow in Skia
πŸ›
Chromium: CVE-2026-3941 Insufficient policy enforcement in DevTools
πŸ›
Chromium: CVE-2026-3940 Insufficient policy enforcement in DevTools
πŸ›
Chromium: CVE-2026-3939 Use after free in WebView
πŸ›
Chromium: CVE-2026-3938 Insufficient policy enforcement in Clipboard
πŸ›
Chromium: CVE-2026-3937 Incorrect security UI in Downloads
πŸ›
Chromium: CVE-2026-3935 Incorrect security UI in WebAppInstalls
πŸ›
Chromium: CVE-2026-3934 Insufficient policy enforcement in ChromeDriver
πŸ›
Chromium: CVE-2026-3932 Insufficient policy enforcement in PDF
πŸ›
Chromium: CVE-2026-3925 Incorrect security UI in LookalikeChecks
πŸ›
Chromium: CVE-2026-3915 Heap buffer overflow in WebML
πŸ›
Chromium: CVE-2026-3936 Use after free in WebView
πŸ›
Chromium: CVE-2026-3929 Side-channel information leakage in ResourceTiming
πŸ›
Chromium: CVE-2026-3928 Insufficient policy enforcement in Extensions
πŸ›
Chromium: CVE-2026-3927 Incorrect security UI in PictureInPicture
πŸ›
Chromium: CVE-2026-3926 Out of bounds read in V8
πŸ›
Chromium: CVE-2026-3924 Use after free in WindowDialog
πŸ›
Chromium: CVE-2026-3923 Use after free in WebMIDI
πŸ›
Chromium: CVE-2026-3922 Use after free in MediaStream
πŸ›
Chromium: CVE-2026-3921 Use after free in TextEncoding
πŸ›
Chromium: CVE-2026-3920 Out of bounds memory access in WebML
πŸ›
Chromium: CVE-2026-3919 Use after free in Extensions
πŸ›
Chromium: CVE-2026-3918 Use after free in WebMCP
πŸ›
Chromium: CVE-2026-3917 Use after free in Agents
πŸ›
Chromium: CVE-2026-3916 Out of bounds read in Web Speech
πŸ›
Chromium: CVE-2026-3914 Integer overflow in WebML
πŸ›
Chromium: CVE-2026-3913 Heap buffer overflow in WebML
πŸ›
CVE-2026-0385 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
πŸ›
Chromium: CVE-2026-3930 Unsafe navigation in Navigation
πŸ›
Chromium: CVE-2026-3910 Inappropriate implementation in V8
⚠️
Telus Digital hit with massive data breach
⚠️
Starbucks discloses data breach affecting hundreds of employees
⚠️
Google fixes two new Chrome zero-days exploited in attacks
⚠️
Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet
⚠️
Chrome 146 Update Patches Two Exploited Zero-Days
⚠️
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation
⚠️
Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries
⚠️
Authorities Shut Down Proxy Service Linked to Malware Campaign Targeting Thousands of Users
⚠️
Starbucks Data Breach Exposes Personal Data of Hundreds of Users
⚠️
Storm-2561 Uses SEO Poisoning, Fake Signed VPN Apps to Steal Enterprise Credentials
⚠️
Iran War Bait Fuels TA453, TA473 Phishing Campaigns
⚠️
Apple Releases Emergency iOS 15.8.7 Update to Block β€˜Coruna’ Exploit Kit
⚠️
Critical CrackArmor Vulnerabilities Expose 12.6 Million Linux Servers to Full Root Takeover
⚠️
Hybrid resilience: Designing incident response across on-prem, cloud and SaaS without losing your mind
⚠️
Storm-2561 targets enterprise VPN users with SEO poisoning, fake clients
⚠️
The cyber perimeter was never dead. We just abandoned it.
⚠️
Police sinkholes 45,000 IP addresses in cybercrime crackdown
⚠️
AI May Speed Zero-Day Discovery
⚠️
In Other News: N8n Flaw Exploited, Slopoly Malware, Interpol Cybercrime Crackdown
⚠️
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials
⚠️
INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime
⚠️
Cyber criminals too are working from home… your home
⚠️
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
πŸ“‹
Microsoft: Windows 11 users can't access C: drive on some Samsung PCs
πŸ“’
Google Chrome security advisory (AV26-235)
πŸ“’
[Control systems] ABB security advisory (AV26-236)
πŸ”₯
AI Agent Hacks McKinsey Chatbot in 2 Hours
πŸ”₯
Fileless Remcos RAT Attack Uses JavaScript and PowerShell to Slip Past Detection
πŸ”₯
A React-based phishing page with credential exfiltration via EmailJS, (Fri, Mar 13th)
πŸ”₯
PsExec and Renamed Backup Tools Enabled Data Theft Before INC Ransomware Attack
πŸ”₯
Six Packagist Packages Linked to Trojanized jQuery Campaign
πŸ”₯
Iran-Linked Hackers Take Aim at US and Other Targets, Raising Risk of Cyberattacks During War
πŸ”₯
Starbucks Data Breach Impacts Employees
πŸ”₯
Poland's nuclear research centre targeted by cyberattack
πŸ”₯
Exposed: Bank Leak, Copilot Zero-Click, AI Agent Hijacks, Stryker Wipe & Josh Marpet - SWN #563
πŸ•΅οΈ
ISC Stormcast For Friday, March 13th, 2026 https://isc.sans.edu/podcastdetail/9848, (Fri, Mar 13th)
πŸ•΅οΈ
Off-Topic Friday
πŸ•΅οΈ
Microsoft Copilot Email and Teams Summarization Flaw Opens Door to Phishing Attacks
πŸ•΅οΈ
Academia and the β€œAI Brain Drain”
πŸ•΅οΈ
Bold Security Emerges From Stealth With $40 Million in Funding
πŸ•΅οΈ
Google Paid Out $17 Million in Bug Bounty Rewards in 2025
πŸ•΅οΈ
Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping
πŸ•΅οΈ
Onyx Security Launches With $40 Million in Funding
πŸ•΅οΈ
Email DLP: Everything You Need to Know
πŸ•΅οΈ
AI-HealthTech Innovator Humata Health Partners with AccuKnox for Zero Trust CNAPP
πŸ•΅οΈ
Fake enterprise VPN downloads used to steal company credentials
πŸ•΅οΈ
45,000 malicious IP addresses taken down in international cyber operation
πŸ•΅οΈ
Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware
πŸ•΅οΈ
Supply-chain attack using invisible code hits GitHub and other repositories
πŸ•΅οΈ
Friday Squid Blogging: Increased Squid Population in the Falklands
πŸ•΅οΈ
Anthropic Refused Pentagon AI Request
πŸ•΅οΈ
CyberRisk TV Live Coverage from RSAC 2026 - Day 4
πŸ•΅οΈ
CyberRisk TV Live Coverage from RSAC 2026 - Day 3
πŸ•΅οΈ
CyberRisk TV Live Coverage from RSAC 2026 - Day 2
πŸ•΅οΈ
CyberRisk TV Live Coverage from RSAC 2026 - Day 1
πŸ•΅οΈ
Risky Biz Soap Box: It took a decade, but allowlisting is cool again
🌐
Investigating a New Click-Fix Variant
🌐
The FBI is investigating malware hidden inside games hosted on Steam
🌐
FBI seeks victims of Steam games used to spread malware
πŸ“‘
From VMware to what’s next: Protecting data during hypervisor migration
πŸ“‘
Microsoft investigates classic Outlook sync and connection issues
πŸ“‘
Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026
πŸ“‘
Face value: What it takes to fool facial recognition
πŸ“‘
Managing Elastic Security Detection Rules with Terraform