Security news.
Today's cybersecurity landscape is dominated by critical zero-day vulnerabilities and ongoing exploitation campaigns. Google has patched a new actively exploited Chrome zero-day, while long-standing flaws in PostgreSQL and WordPress plugins are under widespread attack. Additionally, major data breaches and ransomware threats continue to impact organizations globally.
Google Warns of New Chrome Zero-Day Flaw Exploited in Attacks
Google released an urgent update for Chrome to address an actively exploited high-severity zero-day vulnerability (CVE-2026-85046) in the V8 engine, along with 11 other flaws.
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
A critical 12-year-old PostgreSQL vulnerability, dubbed PostGREShell (CVE-2026-6471), allows attackers to escalate low-level replication access to code execution, permanent superuser privileges, and a persistent database backdoor.
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) to upload arbitrary files and take over sites.
VMware Workstation and Fusion Updates Patch Critical Vulnerability
VMware has released updates for Workstation and Fusion to patch a critical vulnerability that could allow attackers with administrative access to a virtual machine to execute code on the host system.
Exchange Online Outage Causes Email Delays, 'Server busy' Errors
Microsoft is actively working to resolve an ongoing Exchange Online outage causing significant email delays and "Server busy" errors for messages sent to and received from external domains.
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is advising users to update their Plex Media Server to version 1.43.3 and Plex Desktop to 1.115.0 to address multiple undisclosed security flaws for which CVE identifiers have been requested.
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
The Manchester Airports Group (MAG) experienced a data breach where a hacker group leaked approximately 550GB of data, impacting 8.8 million people, after MAG reportedly refused to pay a ransom demand.
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
The rise of AI-powered vulnerability discovery is generating a "tidal wave" of bug reports, overwhelming software vendors and exposing secure-by-design failures, leading to disclosure bottlenecks.