Microsoft fixes 974 flaws, including two exploited Windows zero-days
Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...
BigBear phishing operation reportedly bypassed MFA at 258 organizations
CloudSEK researchers said the BigBear 2.0 phishing-as-a-service operation bypassed multi-factor authentication at 258 organizations and collected more than 5,000 Microsoft 365 credential records. The researchers said the operatio...
Cloudflare rolls out early access to AI-driven vulnerability remediation
Cloudflare has introduced Vulnerability Discovery and Remediation in early access through Cloudflare Managed Defense, according to Blockonomi. The service uses OpenAI technology, including GPT-5.6 Cyber, to identify critical softw...
N-able issues hotfix for N-central zero-day
N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...
Chrome 153 fixes actively exploited V8 flaw
Google released Chrome 153 to the stable channel with fixes for 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine. Google says an exploit for the medium-severity...
CISA adds exploited Chromium V8 flaw to KEV catalog
CISA has added CVE-2026-85046, a Chromium V8 type-confusion vulnerability, to its Known Exploited Vulnerabilities catalog, saying it is actively exploited. The flaw can be triggered when a target loads a specially crafted HTML pag...