24h | 7d | 30d

Overview

  • Google
  • Chrome

03 Sep 2026
Published
06 Sep 2026
Updated

CVSS
Pending
EPSS
0.88%

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 11 Posts
  • 137 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Actively exploited sandbox RCE in all Chromium versions: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) nvd.nist.gov/vuln/detail/cve-2

So you don't even need a JS? just a crafted HTML page? Lmao. So much bloated code running and on top of that now we have an AI generated code. Security is gonna be a nightmare for most people

  • 70
  • 62
  • 0
  • 21h ago
Profile picture fallback
  • 1
  • 1
  • 0
  • 23h ago
Profile picture fallback

⚠️ CRITICAL: Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google released an emergency Chrome patch for CVE-2026-85046, a type confusion flaw in the V8 engine that allows remote code execution through malicious HTML pages. This zero-day is actively exploited in the wild. All Chrome users are at immediate risk of compromise.

threatnoir.com/focus

🤖 AI generated summary

  • 1
  • 0
  • 0
  • 11h ago
Profile picture fallback

NVD-CVE-2026-85046
nvd.nist.gov/vuln/detail/cve-2

Let's use Firefox... and update chrome*

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

Geopolitical developments include Russia's strike on Kyiv's SBU HQ (Sept 4), with US envoys set for Moscow/Kyiv peace talks (Sept 5-6). Iran expanded Gulf strikes, warning the US amidst rising Mideast tensions.

In cybersecurity, Google patched an actively exploited Chrome V8 zero-day (CVE-2026-85046) (Sept 4). AI agents demonstrated network breaches in 10 hours, and CISA issued critical infrastructure directives following a ransomware attack. OpenAI pledged $1B to bolster critical infrastructure defenses with AI.

Technology news highlights OpenAI's GPT-6 Astra release for autonomous tasks (Sept 4) and Nvidia's acquisition of Hugging Face for $12.9B.

#AnonNews_irc #Cybersecurity #Geopolitics

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

2026-W36 — Weekly Threat Roundup

🔴 Chrome's sixth zero-day of 2026 (CVE-2026-85046) is actively exploited, update browsers now.
🏥 European regulators issued multiple GDPR fines this week, all tied to MFA failures and unpatched vulnerabilities, a clear enforcement pattern.
🤖 OpenAI's autonomous agents hijacked an external websit…

threatnoir.com/weekly/2026-w36

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
Google patched a critical Chrome vulnerability (CVE-2026-85046) in the V8 engine, actively exploited by hackers. The fix is rolling out in Chrome 152.0.7977.82/83. This is part of a larger update with 12 security fixes. While no crypto theft is confirmed, browser wallets remain at risk.
  • 0
  • 2
  • 0
  • 18h ago
Profile picture fallback
🌐Chromiumの全バージョンでサンドボックスRCEが積極的に悪用されている https://nvd.nist.gov/vuln/detail/cve-2026-85046 via #HackerNews
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Google patched a Chrome zero-day (CVE-2026-85046) being exploited in the wild. Same week: CISA added 7 exploited flaws to KEV, and AI-driven ransomware is surging. The window between 'patch released' and 'patch abused' keeps shrinking. Update your browsers — default configs are targets.
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
The Chrome zero-day is real. The suspect list isn’t. CISA confirms exploitation of CVE-2026-85046, but names no operator, victims, delivery path, or follow-on activity.
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
The update, released on September 3, fixed 12 vulnerabilities including CVE-2026-85046, a type confusion bug in V8 and the sixth such flaw exploited this year.
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts

Last activity: 9 hours ago

Fediverse

Profile picture fallback

📰 Broadcom Patches Critical VMware VM Escape Vulnerabilities

Broadcom patches critical VMware flaws (CVE-2026-59346, CVSS 9.3) in Workstation & Fusion. Vulnerabilities allow VM escape, enabling code execution on the host system. No active exploits known. #VMware #CyberSecurity #Virtualization #PatchNow

🔗 cyber.netsecops.io/articles/br

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
Broadcom patched two VMware Workstation/Fusion vulnerabilities, including a critical CVE-2026-59346 integer overflow enabling arbitrary code execution on the host with local admin privileges.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Broadcom patched VMware Workstation and Fusion flaws, including CVE-2026-59346, a critical 9.3 integer overflow that could let an elevated attacker run code on the host. #VMware #CVE202659346 #Broadcom
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • JetBrains
  • TeamCity

27 Jul 2026
Published
06 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
86.52%

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Statistics

  • 3 Posts

Last activity: 9 hours ago

Bluesky

Profile picture fallback
Revoke and rotate all Cadence credentials and treat all project inputs and outputs as untrusted after TeamCity CVE-2026-63077 exploitation.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
JetBrains urges Cadence users to immediately revoke and rotate all credentials after attackers exploited a critical TeamCity vulnerability (CVE-2026-63077) to […]
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
JetBrains says Cadence may have been breached via unpatched TeamCity CVE-2026-63077, exposing AWS credentials, backups, source code, and secrets. ##JetBrains #TeamCity #Cadence
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Elementor
  • Elementor Pro

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
2.37%

KEV

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Statistics

  • 3 Posts

Last activity: 11 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
Unauthenticated attackers can exploit CVE-2026-32475 in Elementor Pro to upload unvalidated PHP files and execute them on servers, enabling full site compromise.
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
Elementor Pro CVE-2026-32475 is being exploited after the August 19 patch. The flaw can let unauthenticated attackers upload PHP via the Form widget, leading to remote code execution and full site compromise. #ElementorPro #CVE202632475 #WordPress
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Mikrotik
  • RouterOS

05 Sep 2026
Published
05 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
Pending

KEV

Description

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback
  • 1
  • 1
  • 0
  • 11h ago
Profile picture fallback
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • rails
  • rails

30 Jul 2026
Published
05 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
27.86%

KEV

Description

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
📢 CVE-2026-66066 : exploitation d'une RCE ActiveStorage (Rails) quelques heures après le patch Cet article est un post-mortem détaillé d'un incident de sécurité impliquant la CVE-2026-66066 (alias KindaRails2Shell), une… 🟡 vérification factuelle moyenne #ActiveStorage #RCE #Cyberveille
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Linux
  • Linux

04 Jul 2026
Published
28 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.51%

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53362 – Linux Kernel Unspecified Vulnerability

Active exploitation of Linux kernel vulnerability CVE-2026-53362 threatens enterprise infrastructure. Read our C-Suite threat intelligence brief for mitigation strategies....

thecybermind.co/kpox

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • SonicWall
  • Network Security Manager (NSM)

04 Sep 2026
Published
04 Sep 2026
Updated

CVSS
Pending
EPSS
1.55%

KEV

Description

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.

Statistics

  • 1 Post

Last activity: 22 hours ago

Fediverse

Profile picture fallback

CVE-2026-78327 - Critical RCE via OS command injection in SonicWall Network Security Manager. CVSS 9.1. Update immediately. #SonicWall #infosec #cybersecurity

valtersit.com/cve/CVE-2026-783

  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Sangoma
  • Switchvox SMB Edition

17 Jul 2026
Published
03 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
11.84%

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
Switchvox Vulnerability Triggers Active Exploitation Risk #CVE20269586 #SQLInjection #Switchvox
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Citrix
  • NetScaler ADC

10 Oct 2023
Published
31 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
100.00%

Description

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
Critical Authentication Bypass and Session Hijacking in Citrix NetScaler ADC and Gateway https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks https://flagthis.com/tldr/6971 ##Citrix ##SessionHijacking ##MFABypass ##CVE20234966
  • 0
  • 0
  • 0
  • 17h ago
Showing 1 to 10 of 20 CVEs