CISA Flags Active V8 Type Confusion Zero-Day in Chromium
Google patched an actively exploited zero-day vulnerability in Chromium's V8 JavaScript engine that allows arbitrary code execution inside browser sandboxes.
Category
Google patched an actively exploited zero-day vulnerability in Chromium's V8 JavaScript engine that allows arbitrary code execution inside browser sandboxes.
A new public opinion poll reveals overwhelming opposition in the United Kingdom to government proposals that would mandate the scanning of encrypted messaging applications.
Security researchers warn that modern AI analysis tools allow attackers to synthesize working exploit payloads from vague patch notes and commit messages in minutes.
A severe code injection flaw in Gitea's diffpatch API endpoint allows authenticated users to execute arbitrary shell commands on host servers.
Unauthenticated attackers are actively exploiting a command injection vulnerability in Zimbra Collaboration Suite to execute arbitrary OS commands via crafted SMTP requests.
Cisco has patched a critical heap inspection vulnerability (CVE-2026-20349) in ASA and FTD firewalls that is currently being actively exploited in the wild.
A new security framework reveals how reusable 'skills' in AI agents create a new attack surface for data theft and unauthorized system access.
A critical vulnerability in GitHub Enterprise Server allowed attackers to execute code remotely via malformed Git hooks, threatening the security of internal corporate codebases.
A critical Remote Code Execution vulnerability in GitHub Actions allowed attackers to hijack runners through malicious pull requests, threatening private repository secrets.
Five specific pieces of hardware that each close a concrete attack path for normal people. No subscriptions, no yearly fees, around 250 euros all-in.
SMS and authenticator-app 2FA looks like security but leaves a trivial opening. A 50-dollar piece of hardware closes it — and almost nothing else will.