● On the wire
Ubuntu GStreamer Bad Plugins USN-8855-1 reveals DoS vulnerability//Debian Thunderbird Critical Arbitrary Code Exec Advisory DSA-6536-1//Ubuntu 22.04 LTS Linux Kernel Critical Memory Protection Issues USN-8818-6//ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)//Ubuntu Linux Kernel Critical Network Issues Advisory USN-8851-2//Ubuntu 26.04 Authen-SASL Major Network Vulnerability Report USN-8858-1//YARA-X 1.21.0 Release, (Sat, Oct 3rd)//Ubuntu 26.04 LTS OpenStack Designate Important DNS Issue USN-8860-1//Ubuntu Linux Kernel Update Security Advisory USN-8864-1 CVE-2025-38724//Debian webkit2gtk Critical Regression Crash Fix DSA-6534-2//Ubuntu ImageMagick Security Advisory USN-8859-1 CVE-2026-56367 DoS//Debian libpng Use-After-Free Denial of Service Vulnerability DSA-6537-1//Debian DSA-6532-1 Resolves Tor Denial of Service Vulnerabilities//Debian php-mongodb Severe Injection Denial of Service Problems DSA-6539-1//Ubuntu 26.04 LTS libXpm Denial of Service Issue CVE-2026-94287//Ubuntu GStreamer Bad Plugins USN-8855-1 reveals DoS vulnerability//Debian Thunderbird Critical Arbitrary Code Exec Advisory DSA-6536-1//Ubuntu 22.04 LTS Linux Kernel Critical Memory Protection Issues USN-8818-6//ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)//Ubuntu Linux Kernel Critical Network Issues Advisory USN-8851-2//Ubuntu 26.04 Authen-SASL Major Network Vulnerability Report USN-8858-1//YARA-X 1.21.0 Release, (Sat, Oct 3rd)//Ubuntu 26.04 LTS OpenStack Designate Important DNS Issue USN-8860-1//Ubuntu Linux Kernel Update Security Advisory USN-8864-1 CVE-2025-38724//Debian webkit2gtk Critical Regression Crash Fix DSA-6534-2//Ubuntu ImageMagick Security Advisory USN-8859-1 CVE-2026-56367 DoS//Debian libpng Use-After-Free Denial of Service Vulnerability DSA-6537-1//Debian DSA-6532-1 Resolves Tor Denial of Service Vulnerabilities//Debian php-mongodb Severe Injection Denial of Service Problems DSA-6539-1//Ubuntu 26.04 LTS libXpm Denial of Service Issue CVE-2026-94287//
Chrome/V8 zero-day attivamente sfruttato e inserito nel catalogo CISA KEV
Top story — News

Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog

Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming…

Read the article →
From the newsroom
Zero-day SonicWall SMA 1000 sfruttati in rete
News

Zero-day SonicWall SMA 1000 exploited in the wild

SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers…

Read the article →
Spotlight
More news