Security news
Latest security news
Wed, 9 Sept 2026
- Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
Mind the patch gap, please and thank you
The RegisterWindows, Chrome - Google security advisory (AV26-904)
Serial Number: AV26-904 Date: September 9, 2026 As of September 8, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.37 Google is aware that an exploit for CVE-2026-87491 exists in the wild. On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87491 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Stable Channel Update for Desktop CISA KEV: CVE-2026-87491
Canadian Centre for Cyber SecurityGoogle, Chrome - Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
The Hacker NewsGoogle, Microsoft, Windows - Fortinet security advisory (AV26-898)
Serial Number: AV26-898 Date: September 9, 2026 As of September 8, 2026, Fortinet is affected by vulnerabilities in the following products: FortiOS 7.6 Versions 7.6.1 to 7.6.6 FortiProxy 7.6 Versions 7.6.2 to 7.6.6 FortiPAM Chrome Extension 8.0 All versions FortiPAM Chrome Extension 7.4 All versions FortiSandbox 5.0 Versions 5.0.0 to 5.0.5 FortiSandbox 4.4 Versions 4.4.0 to 4.4.8 FortiSandbox Cloud 5.0 Versions 5.0.4 to 5.0.5 FortiSandbox PaaS 5.0 Versions 5.0.4 to 5.0.5 FortiMonitorOnSight 7.2 Versions 7.2.4 to 7.2.7 FortiMonitorOnSight 7.2 Versions 7.2.0 to 7.2.2 The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Fortinet PSIRT Advisories
Canadian Centre for Cyber SecurityFortinet, Chrome - Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to
The Hacker NewsGoogle, Chrome - Google warns of new Chrome zero-day bug exploited in attacks
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
BleepingComputerGoogle, Chrome
Mon, 7 Sept 2026
- PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences
The Hacker NewsChrome - ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
The Hacker NewsChrome
Fri, 4 Sept 2026
- Google security advisory (AV26-883) – Update 1
Serial Number: AV26-883 Date: September 4, 2026 As of September 3, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 152.0.7977.82 Google is aware that an exploit for CVE-2026-85046 exists in the wild. Update 1 On September 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85046 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Stable Channel Update for Desktop CISA KEV: CVE-2026-85046
CriticalUsed in attacksCanadian Centre for Cyber SecurityGoogle, Chrome - Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote
CriticalUsed in attacksThe Hacker NewsGoogle, Chrome
About this news
- 1,256
- Stories
- 35
- Added in the last 24 hours
- 18
- Critical in the last 7 days
- 4
- Reported by several outlets