● On the wire
Debian WebKitGTK Important Heap Corruption Privilege Escalation DSA-6534-1//Ubuntu 26.04 OpenSSL Critical DDoS Risk CVE-2026-42772 CVE-2026-54873//User Agent Strings Curiosities, (Sun, Oct 4th)//Ubuntu 26.04 Linux Kernel Security Advisory USN-8816-4 Released Today//Probabilistic analysis of MTE tagging schemes//Ubuntu 26.04 Django Important Multiple Issues Fixed USN-8848-1//Debian ruby-rack-session Important Auth Bypass and Escalation DSA-6542-1//Ubuntu Linux Kernel Critical Network Issues Advisory USN-8851-2//Someone Clicked the Link. Is Your Security Team Ready?//Debian Thunderbird Critical Arbitrary Code Exec Advisory DSA-6536-1//Debian Firefox-esr Critical Privilege Escalation Vulnerabilities DSA-6533-1//ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)//ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)//Debian php-mongodb Severe Injection Denial of Service Problems DSA-6539-1//Ubuntu 26.04 LTS OpenStack Designate Important DNS Issue USN-8860-1//Debian WebKitGTK Important Heap Corruption Privilege Escalation DSA-6534-1//Ubuntu 26.04 OpenSSL Critical DDoS Risk CVE-2026-42772 CVE-2026-54873//User Agent Strings Curiosities, (Sun, Oct 4th)//Ubuntu 26.04 Linux Kernel Security Advisory USN-8816-4 Released Today//Probabilistic analysis of MTE tagging schemes//Ubuntu 26.04 Django Important Multiple Issues Fixed USN-8848-1//Debian ruby-rack-session Important Auth Bypass and Escalation DSA-6542-1//Ubuntu Linux Kernel Critical Network Issues Advisory USN-8851-2//Someone Clicked the Link. Is Your Security Team Ready?//Debian Thunderbird Critical Arbitrary Code Exec Advisory DSA-6536-1//Debian Firefox-esr Critical Privilege Escalation Vulnerabilities DSA-6533-1//ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)//ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)//Debian php-mongodb Severe Injection Denial of Service Problems DSA-6539-1//Ubuntu 26.04 LTS OpenStack Designate Important DNS Issue USN-8860-1//
Chrome/V8 zero-day attivamente sfruttato e inserito nel catalogo CISA KEV
Top story — News

Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog

Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming…

Read the article →
From the newsroom
Zero-day SonicWall SMA 1000 sfruttati in rete
News

Zero-day SonicWall SMA 1000 exploited in the wild

SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers…

Read the article →
Spotlight
More news