Chrome’s sixth zero-day of 2026: CVE-2026-85046 exploited in the wild
Google shipped an emergency Chrome Stable update on September 3 and confirmed that one of the twelve bugs it patched is already being exploited in the wild. The flaw, CVE-2026-85046, is a type confusion vulnerability in V8 with a CVSS score of 8.8. It is the sixth actively exploited Chrome zero-day of 2026, and all […]
Azure Front Door WAF policies now attach at profile and route level
Azure Front Door’s Web Application Firewall has always had a scoping problem. You could associate a WAF policy with a custom domain, and that was mostly it. One policy per domain, which sounds fine until you run a real Front Door profile with a dozen domains behind it and every team wants different rules. The […]
8,300 Gitea servers still exposed to actively exploited RCE flaw
More than 8,300 internet-exposed Gitea instances remain unpatched against a critical remote code execution flaw that attackers are actively exploiting, according to Shadowserver Foundation scans. The watchdog counted 8,393 vulnerable IP addresses on August 27, more than a month after a fix shipped. The bug, tracked as CVE-2026-60004, carries a CVSS score of 9.8 and […]
Two alleged TeamPCP hackers arrested over the Shai-Hulud supply chain worm
Australian Federal Police arrested two men this week accused of operating as members of TeamPCP, the hacking group behind the Shai-Hulud supply-chain worm that has infected more than 1,000 organizations since December. The AFP statement says the men, from the Western Australian towns of Cottesloe and Mandurah, face 14 charges in a joint operation with […]
Snowflake Deprecates Service Account Passwords as Teams Face Credential Mapping
Snowflake is systematically eliminating single-factor password authentication for legacy service accounts across its data platform. Under the enforcement timeline, automated service accounts designated with the legacy service user type will no longer be permitted to authenticate using static passwords. Instead, data engineering and platform teams must transition automated workloads to public-key cryptography, OAuth flows, or […]
Avada WordPress Theme Zero-Click RCE Chains Six Flaws into Remote Takeover
A zero-click remote code execution chain affecting the Avada WordPress theme and its companion Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code on vulnerable hosts. Tracked collectively as CVE-2026-18431, the vulnerability carries a CVSS score of 9.8. Because Avada stands as one of the most widely sold commercial WordPress themes in history […]
Attackers Abuse npm Mirrors and unpkg CDNs to Host Fake CAPTCHA Phishing Pages
Turning Public Package CDNs into Phishing Infrastructure A newly uncovered supply chain campaign has demonstrated how threat actors are repurposing npm package mirrors and public content delivery networks (CDNs) to host deceptive phishing pages. By publishing lightweight packages containing malicious HTML files to the npm registry, attackers exploit open CDN services like unpkg to serve […]
AnonyMousKIT Phishing Platform Uses Conversational Voice AI to Unlock Stolen iPhones
Automating the Social Engineering of Device Unlocks Security researchers at SOCRadar have uncovered a sophisticated phishing-as-a-service platform dubbed AnonyMousKIT. Designed specifically to bypass Apple Activation Lock on stolen iOS devices, the kit integrates conversational voice AI agents alongside automated multi-channel messaging to deceive device owners into surrendering their screen passcodes. When an iPhone or iPad […]
Unpatched Flaw in Calix Fiber Gateways Lets Attackers Bypass NAT to Expose Internal Devices
Residential gateways and broadband routers form the first and often only line of defense protecting home and small office networks from direct Internet exposure. Security researchers have disclosed an unpatched vulnerability in widely deployed Calix GS7 XGS (GS5239XG) residential gateways that allows unauthenticated remote attackers on the public Internet to bypass Network Address Translation (NAT) […]
seL4 Microkernel Completes Full Formal Security Proofs on AArch64 Architecture
Formal verification represents the gold standard in software security, replacing probabilistic testing with mathematical proofs that code behaves exactly according to its formal specification. Proofcraft, in collaboration with the seL4 Foundation and supported by the UK National Cyber Security Centre (NCSC), has announced the completion of formal security proofs for the seL4 microkernel on the […]
ToxicPanda 2.0 Abuses Android VPN Permissions to Blindside Google Play Protect
The Evolution of a Targeted Banking Trojan Security researchers tracking mobile threats have documented a significant architectural update to ToxicPanda, an Android banking trojan that first surfaced in late 2024. The new variant, labeled ToxicPanda 2.0, has expanded its target list to 349 financial and banking applications across Europe, Latin America, and emerging markets. Beyond […]
Poisoned arrayref Rust Crate Shows Why Build-Time Execution Needs Guardrails
A Compromised Maintainer and Three Poisoned Crates Earlier this week, security researchers identified a coordinated supply-chain attack targeting the Rust package ecosystem. Attackers compromised the crates.io account of a maintainer responsible for arrayref, a widely used Rust library with tens of millions of downloads across cryptography, networking, and graphics packages. Once inside the account, the […]