Open source package with 1 million monthly downloads compromised to steal credentials
Image: Primary
Image: Primary
Google released Chrome 153 to the stable channel with fixes for 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine. Google says an exploit for the medium-severity...
Administrators report that Microsoft's September 2026 Patch Tuesday cumulative updates are breaking Remote Desktop Services on Windows Server 2019, 2022 and 2025, according to BleepingComputer. Servers reportedly run normally for...
Microsoft's KB5002914 Office security update, released as part of the September 2026 Patch Tuesday cycle, is breaking copy-and-paste operations and formula dragging for some Excel users, according to reports on Reddit and Microsof...
Cloudflare has introduced Vulnerability Discovery and Remediation in early access through Cloudflare Managed Defense, according to Blockonomi. The service uses OpenAI technology, including GPT-5.6 Cyber, to identify critical softw...
The EU Cyber Resilience Act's vulnerability reporting obligations to ENISA arrive on September 11, according to an OpenSSF tech talk recap. The full regulation lands in December 2027. OpenSSF cited a 2026 readiness report finding...
Anthropic published a threat intelligence report on 10 September describing misuse of its Claude models that its Threat Intelligence team disrupted between December 2025 and August 2026. The company said the cases spanned cyber o...