● On the wire
Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability//Ubuntu PHP Critical SQL Injection and DoS Vulnerabilities USN-8743-1//Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026//Ubuntu FFmpeg Important Memory Issues Fixed DoS USN-8750-1//Are Security Teams Keeping Pace With AI-Accelerated Threats?//CNAs — Call for Topics for “CVE Program Fall Technical Workshop: Advancing CVE Record Quality” on…//PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector//Ubuntu 24.04 LTS USN-8742-1 Netty Cache Poisoning CVE-2026-47691//MISP 2.5.46 released - security hardening, major performance gains, knowledge-base updates and Overmind moving forward//Debian xorg-server Important Privilege Escalation Fix DSA-6497-1//Ubuntu Urwid Important Denial of Service Local Access USN-8751-1//Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)//Ubuntu Flatpak File Access Deletion Issues CVE-2026-34078 CVE-2026-34079//The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)//Debian Stable ruby-rack Important Access Restriction Issues DSA-6492-1//Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability//Ubuntu PHP Critical SQL Injection and DoS Vulnerabilities USN-8743-1//Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026//Ubuntu FFmpeg Important Memory Issues Fixed DoS USN-8750-1//Are Security Teams Keeping Pace With AI-Accelerated Threats?//CNAs — Call for Topics for “CVE Program Fall Technical Workshop: Advancing CVE Record Quality” on…//PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector//Ubuntu 24.04 LTS USN-8742-1 Netty Cache Poisoning CVE-2026-47691//MISP 2.5.46 released - security hardening, major performance gains, knowledge-base updates and Overmind moving forward//Debian xorg-server Important Privilege Escalation Fix DSA-6497-1//Ubuntu Urwid Important Denial of Service Local Access USN-8751-1//Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)//Ubuntu Flatpak File Access Deletion Issues CVE-2026-34078 CVE-2026-34079//The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)//Debian Stable ruby-rack Important Access Restriction Issues DSA-6492-1//
Chrome/V8 zero-day attivamente sfruttato e inserito nel catalogo CISA KEV
Top story — News

Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog

Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming…

Read the article →
From the newsroom
Zero-day SonicWall SMA 1000 sfruttati in rete
News

Zero-day SonicWall SMA 1000 exploited in the wild

SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers…

Read the article →
Spotlight
More news