← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity landscape is marked by critical zero-day vulnerabilities in popular software and a significant data breach. Actively exploited flaws in Google Chrome and Citrix NetScaler demand immediate attention, while identity verification company IDScan faces lawsuits following a breach affecting over 153 million driver's licenses.

CISAZERO-DAY
Sep 4READ

CISA Adds Chrome Zero-Day to KEV Catalog

CISA has added Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046) to its Known Exploited Vulnerabilities Catalog, urging immediate patching due to active exploitation.

BLEEPINGZERO-DAY
Sep 4READ

Google Patches Actively Exploited Chrome Zero-Day

Google has released an urgent update for Chrome to address a high-severity zero-day flaw (CVE-2026-85046) in the V8 engine, actively exploited in the wild.

BLEEPINGEXPLOIT
Sep 4READ

Critical Citrix NetScaler Auth Bypass Exploited

Attackers are now actively targeting a critical-severity authentication bypass flaw (CVE-2026-19490) in Citrix NetScaler products.

BLEEPINGBREACH
Sep 4READ

IDScan Sued Over Breach Affecting 153 Million Drivers

Identity verification company IDScan faces multiple lawsuits after hackers allegedly breached its service and offered to sell over 153 million driver's licenses.

SECURITYWEEKRCE
Sep 4READ

HPE Patches Critical RCE Vulnerabilities in AOS-CX

HPE has released patches for nearly two dozen issues, collectively tracked as CVE-2026-73749 (CVSS 9.8), addressing critical remote code execution flaws in its AOS-CX network operating system.

THNPATCH
Sep 4READ

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw

PostgreSQL has released updates to address a 12-year-old security flaw (CVE-2026-6471, CVSS 7.2) that could allow an account with REPLICATION privileges to execute arbitrary code as the database server user.

BLEEPINGZERO-DAY
Sep 4READ

CrowdStrike Falcon Zero-Day Grants SYSTEM Privileges

A new zero-day exploit named "FalconFlank" has been released, allowing attackers to escalate privileges to SYSTEM on up-to-date Windows systems running CrowdStrike Falcon.

THNPHISHING
Sep 4READ

Phishing Campaign Uses Invisible Unicode to Evade Filters

Microsoft warns of a high-volume phishing campaign employing invisible Unicode tag characters to bypass email filters by splitting financial lure words.

Generated twice daily from public security RSS feeds. Informational only.