Security news.
Today's cybersecurity news is dominated by a record-breaking Patch Tuesday from Microsoft and a stark warning about China's industrial-scale AI model "distillation" efforts. Multiple critical vulnerabilities are under active exploitation, highlighting the ongoing threat landscape for IT teams and developers.
Microsoft Patches a Record 974 Security Holes, Including Actively Exploited Zero-Days
Microsoft released its largest-ever Patch Tuesday, addressing 974 vulnerabilities across its products, with two actively exploited zero-days and 113 critical flaws.
Google Chrome V8 Zero-Day (CVE-2026-87491) Actively Exploited
Google patched 230 vulnerabilities in Chrome, including a critical out-of-bounds write flaw in the V8 JavaScript engine (CVE-2026-87491) that is currently under active exploitation.
CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog
CISA updated its Known Exploited Vulnerabilities (KEV) Catalog with four new entries, including critical flaws in Fortinet, Citrix NetScaler (CVE-2026-19490), Google Chromium V8 (CVE-2026-87491), and Microsoft Windows.
Active Exploitation of Cisco Secure Firewall Management Center Vulnerabilities
Cisco Talos is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) software, urging users to apply patches immediately.
Four Spy Groups Used BlueMoon Exploit Kit for Chrome and Windows
Multiple state-sponsored espionage groups, including China-aligned APT31, have been observed deploying a new exploit kit named "BlueMoon" that chains vulnerabilities in Microsoft Windows and Google Chrome.
US Accuses Chinese AI Firms of "Industrial-Scale Distillation" of Frontier AI Models
U.S. cybersecurity and intelligence agencies accuse China-based AI companies of systematically extracting proprietary functionalities and capabilities from American frontier models like Claude, GPT, Gemini, and Grok through "distillation attacks."
Passkey-Themed Social Engineering Leads to Identity and Cloud Compromise
Threat actors are leveraging passkey-themed social engineering to compromise user identities, establish MFA persistence, and abuse Microsoft Graph for reconnaissance, ultimately accessing SharePoint, OneDrive, and email data.
Critical cPanel Flaw (CVE-2026-41940) Allows Root Code Execution
cPanel has patched a critical vulnerability (CVE-2026-41940) that could allow an authenticated hosting account with mail-related privileges to create arbitrary files and execute code as the root user, compromising the entire server.