Security news.
Today's cybersecurity landscape is marked by critical zero-day vulnerabilities in popular software and a significant data breach. Actively exploited flaws in Google Chrome and Citrix NetScaler demand immediate attention, while identity verification company IDScan faces lawsuits following a breach affecting over 153 million driver's licenses.
CISA Adds Chrome Zero-Day to KEV Catalog
CISA has added Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046) to its Known Exploited Vulnerabilities Catalog, urging immediate patching due to active exploitation.
Google Patches Actively Exploited Chrome Zero-Day
Google has released an urgent update for Chrome to address a high-severity zero-day flaw (CVE-2026-85046) in the V8 engine, actively exploited in the wild.
Critical Citrix NetScaler Auth Bypass Exploited
Attackers are now actively targeting a critical-severity authentication bypass flaw (CVE-2026-19490) in Citrix NetScaler products.
IDScan Sued Over Breach Affecting 153 Million Drivers
Identity verification company IDScan faces multiple lawsuits after hackers allegedly breached its service and offered to sell over 153 million driver's licenses.
HPE Patches Critical RCE Vulnerabilities in AOS-CX
HPE has released patches for nearly two dozen issues, collectively tracked as CVE-2026-73749 (CVSS 9.8), addressing critical remote code execution flaws in its AOS-CX network operating system.
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw
PostgreSQL has released updates to address a 12-year-old security flaw (CVE-2026-6471, CVSS 7.2) that could allow an account with REPLICATION privileges to execute arbitrary code as the database server user.
CrowdStrike Falcon Zero-Day Grants SYSTEM Privileges
A new zero-day exploit named "FalconFlank" has been released, allowing attackers to escalate privileges to SYSTEM on up-to-date Windows systems running CrowdStrike Falcon.
Phishing Campaign Uses Invisible Unicode to Evade Filters
Microsoft warns of a high-volume phishing campaign employing invisible Unicode tag characters to bypass email filters by splitting financial lure words.