24h | 7d | 30d

Overview

  • Google
  • Chrome

09 Sep 2026
Published
21 Sep 2026
Updated

CVSS
Pending
EPSS
3.14%

Description

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

A vulnerability can be patched and still be a zero-day for millions of users. Volexity co-founder and president Steven Adair will deliver the keynote at our upcoming Volexity Cyber Sessions in Amsterdam (October 29) on multiple cases from September 2026, when Volexity uncovered three distinct Chinese threat actors exploiting Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) vulnerabilities. The Chrome vulnerabilities had already been fixed upstream in Chromium—but hadn't yet reached a public Chrome release—potentially allowing the threat actors to compromise fully up-to-date users. The identical exploit code reused across otherwise unrelated operations points to a shared supplier.

Steven will reconstruct these campaigns, tracing the exploit from upstream patch to active deployment and examining the evidence linking the operators despite their different infrastructure, targeting, and tooling, including a false-flag campaign designed to pin the blame on a Russian threat actor. The talk covers what this reveals about exploit supply chains, the risks created by the patch gap, and the attribution challenges posed when capabilities are shared between threat actors.

Seating is limited. Register now to secure your spot: luma.com/0qtkw49c

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

08 Sep 2026
Published
25 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
3.62%

Description

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

A vulnerability can be patched and still be a zero-day for millions of users. Volexity co-founder and president Steven Adair will deliver the keynote at our upcoming Volexity Cyber Sessions in Amsterdam (October 29) on multiple cases from September 2026, when Volexity uncovered three distinct Chinese threat actors exploiting Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) vulnerabilities. The Chrome vulnerabilities had already been fixed upstream in Chromium—but hadn't yet reached a public Chrome release—potentially allowing the threat actors to compromise fully up-to-date users. The identical exploit code reused across otherwise unrelated operations points to a shared supplier.

Steven will reconstruct these campaigns, tracing the exploit from upstream patch to active deployment and examining the evidence linking the operators despite their different infrastructure, targeting, and tooling, including a false-flag campaign designed to pin the blame on a Russian threat actor. The talk covers what this reveals about exploit supply chains, the risks created by the patch gap, and the attribution challenges posed when capabilities are shared between threat actors.

Seating is limited. Register now to secure your spot: luma.com/0qtkw49c

  • 0
  • 0
  • 0
  • 14h ago
Showing 61 to 62 of 62 CVEs