Chrome 153 Patches 42 Security Flaws, Including Three Critical Memory Bugs
Google’s Chrome 153 stable update closes 42 vulnerabilities, including three critical memory-safety issues in Internals, Workers and WebGL. Users and administrators should ensure the browser has restarted on...
Apple’s Largest Coordinated Update Closes 273 Unique Vulnerabilities
Apple has issued coordinated updates across its device ecosystem addressing 273 unique CVEs. The fixes cover remote code execution, kernel privilege escalation, authentication bypass, privacy failures and web-content...
Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure
This week’s security picture is dominated by exploited Windows and Chrome zero-days, dangerous flaws in perimeter products and increasingly automated attack operations. Defenders need risk-based patch sequencing, exposure...
Security Teams Face a Week of Zero-Days, Router Intrusions and AI-Accelerated Attacks
A packed week of security disclosures combined active browser and commerce exploitation with router espionage, identity failures and faster AI-assisted intrusions. Defenders should use the converging signals to...
Microsoft Ships KB5095189 Cumulative Update to Patch the Windows 11 Setup Experience
Microsoft's KB5095189 update patches the Windows 11 setup experience for versions 24H2 and 25H2. It carries no CVE, but enterprises relying on Autopilot-style provisioning should confirm devices aren't...
CISA BOD 26-04: Federal Agencies Must Patch Critical Vulnerabilities Within 3 Days Under New Risk-Based Mandate
CISA has issued Binding Operational Directive BOD 26-04, requiring federal civilian agencies to patch the most critical vulnerabilities — those that are internet-exposed, KEV-listed, automatable, and grant full...
SAP June 2026 Patch Day: Four Critical Flaws Including CVSS 9.9 SAML Bypass in NetWeaver ABAP
SAP's June 2026 Security Patch Day addressed 15 security notes including four critical vulnerabilities. The most severe — CVE-2026-44748 (CVSS 9.9) — is an XML Signature Wrapping flaw...
Critical SAP SQL Injection CVE-2026-27681 (CVSS 9.9) Exposes Financial Data in Business Planning and Warehouse Systems
SAP's April 2026 Patch Day addresses CVE-2026-27681, a near-perfect CVSS 9.9 SQL injection flaw in SAP Business Planning and Consolidation (BPC) and Business Warehouse (BW). A low-privileged user...