● On the wire
Debian Trixie SPIP Important Remote Code Execution DSA-6495-1//Scans for Proxmox Servers, (Wed, Sep 9th)//Ubuntu 26.04 LTS .NET Important Info Exposure and Code Exec 2026-8740-1//Debian libevent Important HTTP Header Injection DoS Advisory CVE-2026-63379//Ubuntu 26.04 KissFFT Notable Denial of Service Vulnerability USN-8745-1//Ubuntu Flatpak File Access Deletion Issues CVE-2026-34078 CVE-2026-34079//The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)//CNAs — Call for Topics for “CVE Program Fall Technical Workshop: Advancing CVE Record Quality” on…//ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)//Debian Slurm WLM High Risk Privilege Escalation SQL Injection DSA-6491-1//Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability//Debian Kamailio Important Denial of Service Vulns DSA-6494-1//Vulnerability Data Enrichment for CVE Records: 269 CNAs on the Enrichment Recognition List for…//MISP 2.5.46 released - security hardening, major performance gains, knowledge-base updates and Overmind moving forward//Ubuntu 26.04 Beets Media Injection Vulnerability USN-8747-1 CVE-2026-42052//Debian Trixie SPIP Important Remote Code Execution DSA-6495-1//Scans for Proxmox Servers, (Wed, Sep 9th)//Ubuntu 26.04 LTS .NET Important Info Exposure and Code Exec 2026-8740-1//Debian libevent Important HTTP Header Injection DoS Advisory CVE-2026-63379//Ubuntu 26.04 KissFFT Notable Denial of Service Vulnerability USN-8745-1//Ubuntu Flatpak File Access Deletion Issues CVE-2026-34078 CVE-2026-34079//The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)//CNAs — Call for Topics for “CVE Program Fall Technical Workshop: Advancing CVE Record Quality” on…//ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)//Debian Slurm WLM High Risk Privilege Escalation SQL Injection DSA-6491-1//Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability//Debian Kamailio Important Denial of Service Vulns DSA-6494-1//Vulnerability Data Enrichment for CVE Records: 269 CNAs on the Enrichment Recognition List for…//MISP 2.5.46 released - security hardening, major performance gains, knowledge-base updates and Overmind moving forward//Ubuntu 26.04 Beets Media Injection Vulnerability USN-8747-1 CVE-2026-42052//
Chrome/V8 zero-day attivamente sfruttato e inserito nel catalogo CISA KEV
Top story — News

Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog

Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming…

Read the article →
From the newsroom
Zero-day SonicWall SMA 1000 sfruttati in rete
News

Zero-day SonicWall SMA 1000 exploited in the wild

SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers…

Read the article →
Spotlight
More news