● On the wire
Ubuntu 24.04 LTS Linux Kernel Security Update USN-8911-1 CVE-2026//Debian Tor Important Multiple Security Issues Advisory DSA-6551-1//MISP 2.5.50 Released - Security hardening, Overmind improvements, and streamlined workflows//Cisco NX-OS Software NX-API Remote Code Execution Vulnerability//Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)//Ubuntu 24.04 LTS Linux Kernel Security Advisory USN-8903-2//Cisco NX-OS Software Control Plane Denial of Service Vulnerability//Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability//Cisco Application Policy Infrastructure Controller Security Hardening Release: October 2026//Debian Ghostscript High Risk Remote Code Exec Denial of Service Alert//Why TLP should not replace your internal information classification, (Sat, Oct 10th)//ISC Stormcast For Friday, October 9th, 2026 https://isc.sans.edu/podcastdetail/10130, (Fri, Oct 9th)//Microsoft, Adobe, Apple, and Foxit vulnerabilities//Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities//Ubuntu 24.04 Kernel Major Integrity Vulnerabilities Patch USN-8887-3//Ubuntu 24.04 LTS Linux Kernel Security Update USN-8911-1 CVE-2026//Debian Tor Important Multiple Security Issues Advisory DSA-6551-1//MISP 2.5.50 Released - Security hardening, Overmind improvements, and streamlined workflows//Cisco NX-OS Software NX-API Remote Code Execution Vulnerability//Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)//Ubuntu 24.04 LTS Linux Kernel Security Advisory USN-8903-2//Cisco NX-OS Software Control Plane Denial of Service Vulnerability//Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability//Cisco Application Policy Infrastructure Controller Security Hardening Release: October 2026//Debian Ghostscript High Risk Remote Code Exec Denial of Service Alert//Why TLP should not replace your internal information classification, (Sat, Oct 10th)//ISC Stormcast For Friday, October 9th, 2026 https://isc.sans.edu/podcastdetail/10130, (Fri, Oct 9th)//Microsoft, Adobe, Apple, and Foxit vulnerabilities//Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities//Ubuntu 24.04 Kernel Major Integrity Vulnerabilities Patch USN-8887-3//
Chrome/V8 zero-day attivamente sfruttato e inserito nel catalogo CISA KEV
Top story — News

Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog

Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming…

Read the article →
From the newsroom
Zero-day SonicWall SMA 1000 sfruttati in rete
News

Zero-day SonicWall SMA 1000 exploited in the wild

SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers…

Read the article →
Spotlight
More news