Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Google has released an urgent Chrome update addressing 26 security fixes, including two critical use-after-free vulnerabilities and an actively exploited flaw in the V8 engine (CVE-2026-85046). Attackers can exploit these flaws via crafted HTML pages to execute arbitrary code, making immediate patching essential for all users.
Two zero-day vulnerabilities, a pre-auth SSRF (CVE-2026-83548, CVSS 10.0) and a post-auth OS command injection (CVE-2026-83549, CVSS 7.8), are being actively exploited in a chain against SonicWall SMA 1000 series VPN appliances. SonicWall has released hotfixes (versions 12.4.3-03526 and 12.5.0-02952) and recommends immediate patching, checking for IoCs, and re-imaging compromised devices.
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links.
Research by: Amit Yardeni Key Points A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025.
A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports .
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.