GlassWorm supply chain attack hits OpenVSX with 73 malicious extensions
Image: Primary
Image: Primary
Google released Chrome 153 to the stable channel with fixes for 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine. Google says an exploit for the medium-severity...
Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...
CloudSEK researchers said the BigBear 2.0 phishing-as-a-service operation bypassed multi-factor authentication at 258 organizations and collected more than 5,000 Microsoft 365 credential records. The researchers said the operatio...
Arctic Wolf has described a data-theft and extortion cluster targeting Microsoft 365 and other SaaS accounts through fraudulent IT-help-desk calls, adversary-in-the-middle login pages and residential-proxy session replay. The acti...
Cloudflare has introduced Vulnerability Discovery and Remediation in early access through Cloudflare Managed Defense, according to Blockonomi. The service uses OpenAI technology, including GPT-5.6 Cyber, to identify critical softw...
N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...