173Articles
9Categories
2026-04-10Date
🚨
Analysis of one billion CISA KEV remediation records exposes limits of human-scale securityAnalysis of 1 billion CISA KEV remediation records reveal a breaking point for human-scale security. Qualys shows most critical flaws are exploited before defenders can patch them. [...]
KEV
🚨
Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up AI Exploit Speed.Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up AI Exploit Speed. So? Many years ago while at Gartner , I wrote a blog post where I defined the concept of the β€œPatch Sound Barrier.” ( original via Archive if you don’t believe that I was that smar…
KEV
πŸ›
Juniper Networks Default Credential Vulnerability Allows Unauthorized Full Access
πŸ›
CVE-2026-23405 apparmor: fix: limit the number of levels of policy namespaces
πŸ›
CVE-2026-40026 Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
πŸ›
CVE-2026-40025 Sleuth Kit APFS Keybag Parser Out-of-Bounds Read
πŸ›
CVE-2026-40024 Sleuth Kit tsk_recover Path Traversal
πŸ›
CVE-2026-39881 Vim Ex command injection in Vims NetBeans integration
πŸ›
CVE-2026-23403 apparmor: fix memory leak in verify_header
πŸ›
CVE-2026-23404 apparmor: replace recursive profile removal with iterative approach
πŸ›
CVE-2026-23406 apparmor: fix side-effect bug in match_char() macro usage
πŸ›
CVE-2026-23407 apparmor: fix missing bounds check on DEFAULT table in verify_dfa()
πŸ›
CVE-2026-23408 apparmor: Fix double free of ns_name in aa_replace_profiles()
πŸ›
CVE-2026-23409 apparmor: fix differential encoding verification
πŸ›
CVE-2026-23410 apparmor: fix race on rawdata dereference
πŸ›
CVE-2026-23411 apparmor: fix race between freeing data and fs accessing it
πŸ›
New React Server Components Flaw Could Let Attackers Trigger DoS
πŸ›
HPE Aruba Private 5G Vulnerability Opens Door to Credential Theft Attacks
πŸ›
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
πŸ›
Claude uncovers a 13‑year‑old ActiveMQ RCE bug within minutes
πŸ›
Hackers Exploit GitHub Copilot Flaw to Exfiltrate Sensitive Data
πŸ›
Bringing Rust to the Pixel Baseband
πŸ›
Old Docker authorization bypass pops up despite previous patch
πŸ›
Chromium: CVE-2026-5899 Incorrect security UI in History Navigation
πŸ›
Chromium: CVE-2026-5897 Incorrect security UI in Downloads
πŸ›
Chromium: CVE-2026-5898 Incorrect security UI in Omnibox
πŸ›
Chromium: CVE-2026-5896 Policy bypass in Audio
πŸ›
Chromium: CVE-2026-5894 Inappropriate implementation in PDF
πŸ›
Chromium: CVE-2026-5893 Race in V8
πŸ›
Chromium: CVE-2026-5891 Insufficient policy enforcement in browser UI
πŸ›
Chromium: CVE-2026-5892 Insufficient policy enforcement in PWAs
πŸ›
Chromium: CVE-2026-5886 Out of bounds read in WebAudio
πŸ›
Chromium: CVE-2026-5888 Uninitialized Use in WebCodecs
πŸ›
Chromium: CVE-2026-5890 Race in WebCodecs
πŸ›
Chromium: CVE-2026-5884 Insufficient validation of untrusted input in Media
πŸ›
Chromium: CVE-2026-5885 Insufficient validation of untrusted input in WebML
πŸ›
Chromium: CVE-2026-5895 Incorrect security UI in Omnibox
πŸ›
Chromium: CVE-2026-5883 Use after free in Media
πŸ›
Chromium: CVE-2026-5887 Insufficient validation of untrusted input in Downloads
πŸ›
Chromium: CVE-2026-5889 Cryptographic Flaw in PDFium
πŸ›
Chromium: CVE-2026-5880 Incorrect security UI in browser UI
πŸ›
Chromium: CVE-2026-5879 Insufficient validation of untrusted input in ANGLE
πŸ›
Chromium: CVE-2026-5882 Incorrect security UI in Fullscreen
πŸ›
Chromium: CVE-2026-5881 Policy bypass in LocalNetworkAccess
πŸ›
Chromium: CVE-2026-5876 Side-channel information leakage in Navigation
πŸ›
Chromium: CVE-2026-5878 Incorrect security UI in Blink
πŸ›
Chromium: CVE-2026-5877 Use after free in Navigation
πŸ›
Chromium: CVE-2026-5874 Use after free in PrivateAI
πŸ›
Chromium: CVE-2026-5871 Type Confusion in V8
πŸ›
Chromium: CVE-2026-5872 Use after free in Blink
πŸ›
Chromium: CVE-2026-5873 Out of bounds read and write in V8
πŸ›
Chromium: CVE-2026-5875 Policy bypass in Blink
πŸ›
Chromium: CVE-2026-5869 Heap buffer overflow in WebML
πŸ›
Chromium: CVE-2026-5870 Integer overflow in Skia
πŸ›
Chromium: CVE-2026-5868 Heap buffer overflow in ANGLE
πŸ›
Chromium: CVE-2026-5864 Heap buffer overflow in WebAudio
πŸ›
Chromium: CVE-2026-5862 Inappropriate implementation in V8
πŸ›
Chromium: CVE-2026-5867 Heap buffer overflow in WebML
πŸ›
Chromium: CVE-2026-5860 Use after free in WebRTC
πŸ›
Chromium: CVE-2026-5863 Inappropriate implementation in V8
πŸ›
Chromium: CVE-2026-5858 Heap buffer overflow in WebML
πŸ›
Chromium: CVE-2026-5859 Integer overflow in WebML
πŸ›
Chromium: CVE-2026-5861 Use after free in V8
πŸ›
Chromium: CVE-2026-5918 Inappropriate implementation in Navigation
πŸ›
Chromium: CVE-2026-5919 Insufficient validation of untrusted input in WebSockets
πŸ›
Chromium: CVE-2026-5913 Out of bounds read in Blink
πŸ›
Chromium: CVE-2026-5915 Insufficient validation of untrusted input in WebML
πŸ›
Chromium: CVE-2026-5914 Type Confusion in CSS
πŸ›
Chromium: CVE-2026-5911 Policy bypass in ServiceWorkers
πŸ›
Chromium: CVE-2026-5909 Integer overflow in Media
πŸ›
Chromium: CVE-2026-5912 Integer overflow in WebRTC
πŸ›
Chromium: CVE-2026-5910 Integer overflow in Media
πŸ›
Chromium: CVE-2026-5908 Integer overflow in Media
πŸ›
Chromium: CVE-2026-5907 Insufficient data validation in Media
πŸ›
Chromium: CVE-2026-5904 Use after free in V8
πŸ›
Chromium: CVE-2026-5865 Type Confusion in V8
πŸ›
Chromium: CVE-2026-5906 Incorrect security UI in Omnibox
πŸ›
Chromium: CVE-2026-5905 Incorrect security UI in Permissions
πŸ›
Chromium: CVE-2026-5900 Policy bypass in Downloads
πŸ›
Chromium: CVE-2026-5866 Use after free in Media
πŸ›
Chromium: CVE-2026-5903 Policy bypass in IFrameSandbox
πŸ›
Chromium: CVE-2026-5902 Race in Media
πŸ›
Chromium: CVE-2026-5901 Policy bypass in DevTools
πŸ›
CVE-2026-33119 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
πŸ›
CVE-2026-33118 Microsoft Edge (Chromium-based) Spoofing Vulnerability
⚠️
News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk
⚠️
AWS Fixes Severe RCE, Privilege Escalation Flaws in Research and Engineering Studio
⚠️
ChatGPT, Claude, and Gemini Among 11 AI Models Vulnerable to One-Line Jailbreak
⚠️
Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users
⚠️
TP-Link Devices at Risk as Multiple Security Flaws Enable Takeover
⚠️
Critical Marimo Flaw Exploited Hours After Public Disclosure
⚠️
The cyber winners and losers in Trump’s 2027 budget
⚠️
CMMC compliance in the age of AI
⚠️
Why most zero-trust architectures fail at the traffic layer
⚠️
Fake BTS Tour Ticket Scams Target Fans Worldwide
⚠️
Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
⚠️
Hungarian government email passwords exposed ahead of election
⚠️
Juniper Networks Patches Dozens of Junos OS Vulnerabilities
⚠️
EngageSDK Vulnerability puts millions of crypto wallets at risk
⚠️
FCC Can’t Define a Router
⚠️
In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack
⚠️
Hacker Unknown now known, named on Europol’s most-wanted list
⚠️
Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises
⚠️
Crushing the Axios supply chain threat with Tenable Hexa AI: Use cases for agentic AI
⚠️
[local] NetBT e-Fatura - Privilege Escalation
⚠️
Microsoft: Third-Party Android Vulnerability Leaves Over 50M Users Exposed
⚠️
AI Expansion, Security Crises, and Workforce Upheaval Define This Week in Tech
⚠️
Webloc surveillance system tracks millions using mobile ad data
⚠️
Warten auf Sicherheitsupdate: Angreifer attackieren Adobe Reader
πŸ“’
Rising Compliance Oversight Pressure: From Audit Fatigue to Continuous Readiness
πŸ“’
Google Chrome security advisory (AV26-337)
πŸ“’
Friday Squid Blogging: Squid Overfishing in the South Pacific
πŸ“’
ur best techno-babble to bypass clueless auditors?
πŸ“’
ur best techno-babble to bypass clueless auditors?
πŸ”₯
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
πŸ”₯
Iranian APT alert: 5,219 Rockwell PLCs exposed online
πŸ”₯
Massive Data Breach Exposes 337K LAPD-Linked Records
πŸ”₯
Healthcare IT solutions provider ChipSoft hit by ransomware attack
πŸ”₯
Cryptocurrency ATM giant Bitcoin Depot reports $3.6 million stolen in cyberattack | The Record from Recorded Future News
πŸ”₯
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
πŸ”₯
CPUID hijacked to serve malware as HWMonitor downloads
πŸ”₯
VIP Credential Monitoring Blog
πŸ•΅οΈ
WhatsApp Adds Username Feature to Boost Privacy and Reduce Number Sharing
πŸ•΅οΈ
DesckVB RAT Uses Fileless .NET Loader to Evade Detection
πŸ•΅οΈ
GlassWorm Trojan Hits VS Code, Cursor, Windsurf via OpenVSX Extension
πŸ•΅οΈ
Obfuscated JavaScript or Nothing, (Thu, Apr 9th)
πŸ•΅οΈ
MuddyWater Uses Russian MaaS in New ChainShell Attack
πŸ•΅οΈ
GitHub, GitLab Abused for Malware and Phishing Campaigns
πŸ•΅οΈ
Google Rolls Out Cookie Theft Protections in Chrome
πŸ•΅οΈ
Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action
πŸ•΅οΈ
Middle East Espionage Attack Uses Fake Secure Messaging Apps to Deliver ProSpy
πŸ•΅οΈ
MITRE Releases Fight Fraud Framework
πŸ•΅οΈ
Sen. Sanders Talks to Claude About AI and Privacy
πŸ•΅οΈ
Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000
πŸ•΅οΈ
Do extremely short credential lifetimes actually help security?
πŸ•΅οΈ
Microsoft: Canadian employees targeted in payroll pirate attacks
πŸ•΅οΈ
Smart Slider updates hijacked to push malicious WordPress, Joomla versions
πŸ•΅οΈ
New β€˜LucidRook’ malware used in targeted attacks on NGOs, universities
πŸ•΅οΈ
Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday
πŸ•΅οΈ
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet Installs
πŸ•΅οΈ
Google Warns of New Threat Group Targeting BPOs and Helpdesks - Infosecurity Magazine
πŸ•΅οΈ
FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database
πŸ•΅οΈ
Storm-2755 Uses AiTM Hijacking to Divert Employee Salaries
πŸ•΅οΈ
Phishing Campaign Targets Japanese Firms During Tax Season
πŸ•΅οΈ
Staypuft, Claude, One Pixel, deepfakes, Raccoon, BOFH, Satoshi Nakamoto, Josh Marpet. - SWN #571
πŸ•΅οΈ
Samsung Eyes Vietnam for $4B Semiconductor Packaging Project
πŸ•΅οΈ
Alibaba Launches AI Data Center Powered by 10,000 Homegrown Chips
πŸ•΅οΈ
Google Brings NotebookLM to Gemini for Easy Project Organization
πŸ•΅οΈ
New Apple Rumor: iPhone Air 2 Leak Suggests Major Upgrades After First-Gen Criticism
πŸ•΅οΈ
Mitsubishi Targets Hybrid Vehicle Production in the Philippines by 2028
πŸ•΅οΈ
When Are Payroll Taxes Due? 2026 Due Dates and Requirements
πŸ•΅οΈ
Embedded Finance vs Banking as a Service in 2026: Key Differences Explained
πŸ•΅οΈ
Session says funding will last until July, pauses development
πŸ•΅οΈ
Signal is testing a new plaintext chat export feature in Beta 8.7
πŸ•΅οΈ
HWMonitor and CPU-Z downloads hijacked to deliver malware to users
🌐
Supply chain attack at CPUID pushes malware with CPU-Z/HWMonitor
🌐
Fake Claude site installs malware that gives attackers access to your computer
πŸŽ™οΈ
Snake Oilers: Burp AI, Sondera and Truffle Security
πŸ“‘
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
πŸ“‘
Google rolls out Gmail end-to-end encryption on mobile devices
πŸ“‘
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
πŸ“‘
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
πŸ“‘
France to ditch Windows for Linux to reduce reliance on US tech
πŸ“‘
How to protect your organization from AirSnitch Wi-Fi vulnerabilities | Kaspersky official blog
πŸ“‘
ChatGPT rolls out new $100 Pro subscription to challenge Claude
πŸ“‘
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike
πŸ“‘
AI and cryptocurrency scams are costing Americans billions, FBI reports
πŸ“‘
[webapps] D-Link DIR-650IN - Authenticated Command Injection
πŸ“‘
ClickFix finds a new way to infect Macs
πŸ“‘
iOS: GelΓΆschte Signal-Daten von FBI via Benachrichtigungsdatenbank extrahiert
πŸ“‘
Frankreichs Plan: Weg von Windows, hin zu Linux
πŸ“‘
Google Chrome macht Cookie-Klau unter Windows sinnlos
πŸ“‘
Pornografische KI-Plattform MyLovely.ai: Datenleck von 106.000 Konten