● On the wire
Ubuntu python-sql Critical SQL Injection Risk USN-8765-1 CVE-2024-9774//The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)//Cisco Secure Email Gateway SQL Injection Vulnerability//Ubuntu CivetWeb Important Denial Of Service Risks USN-8749-1//Ubuntu 26.04 LTS Kitty Important Arbitrary Code Execution Vuln 8763-1//Ubuntu 24.04 LTS USN-8761-1 Linux Kernel Azure Security Fix//Ubuntu libvips Denial of Service Crash Vulnerability USN-8755-1//Debian DSA-6496-2 nginx Update Fixes Module Build Regression//Ubuntu 24.04 Shibboleth Important SQL Injection Risk USN-8768-1//Ubuntu 16.04 LTS cgit Important Information Disclosure USN-8757-1//Debian Trixie SPIP Important Remote Code Execution DSA-6495-1//Debian Network Manager L2TP Moderate Escalation Vulnerabilities DSA-6498-1//Debian libevent Important HTTP Header Injection DoS Advisory CVE-2026-63379//Debian xorg-server Important Privilege Escalation Fix DSA-6497-1//Ubuntu Freeciv Denial Of Service Crash Vuln 8754-1 CVE-2026-33250//Ubuntu python-sql Critical SQL Injection Risk USN-8765-1 CVE-2024-9774//The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)//Cisco Secure Email Gateway SQL Injection Vulnerability//Ubuntu CivetWeb Important Denial Of Service Risks USN-8749-1//Ubuntu 26.04 LTS Kitty Important Arbitrary Code Execution Vuln 8763-1//Ubuntu 24.04 LTS USN-8761-1 Linux Kernel Azure Security Fix//Ubuntu libvips Denial of Service Crash Vulnerability USN-8755-1//Debian DSA-6496-2 nginx Update Fixes Module Build Regression//Ubuntu 24.04 Shibboleth Important SQL Injection Risk USN-8768-1//Ubuntu 16.04 LTS cgit Important Information Disclosure USN-8757-1//Debian Trixie SPIP Important Remote Code Execution DSA-6495-1//Debian Network Manager L2TP Moderate Escalation Vulnerabilities DSA-6498-1//Debian libevent Important HTTP Header Injection DoS Advisory CVE-2026-63379//Debian xorg-server Important Privilege Escalation Fix DSA-6497-1//Ubuntu Freeciv Denial Of Service Crash Vuln 8754-1 CVE-2026-33250//
Chrome/V8 zero-day attivamente sfruttato e inserito nel catalogo CISA KEV
Top story — News

Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog

Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming…

Read the article →
From the newsroom
Zero-day SonicWall SMA 1000 sfruttati in rete
News

Zero-day SonicWall SMA 1000 exploited in the wild

SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers…

Read the article →
Spotlight
More news