BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days in Espionage Attacks
Multiple espionage groups are using the BlueMoon exploit kit to chain Chrome and Windows flaws against government, defense and commercial targets. The campaign highlights the danger of patch-gap...
Microsoft’s September Patch Wave Fixes 973 Flaws and Two Exploited Zero-Days
Microsoft’s September 2026 security release addresses 973 vulnerabilities across Windows, Office, SQL Server and other enterprise products. Two privilege-escalation zero-days are already being exploited, making rapid testing and...
Microsoft’s September Patch Tuesday Closes 973 Holes, Including Two Zero-Days Already Under Attack
Microsoft's September 2026 security update addresses 973 vulnerabilities — one of its largest releases on record — including two Windows elevation-of-privilege flaws that attackers are actively exploiting. Several...
Adobe Commerce Stores Face Active StyleSmuggler Zero-Day Attacks With No Official Patch
Attackers are exploiting an unauthenticated remote-code-execution flaw across current Magento Open Source and Adobe Commerce releases. Store operators should treat the incident as an active compromise risk and...
Security Teams Face a Week of Zero-Days, Router Intrusions and AI-Accelerated Attacks
A packed week of security disclosures combined active browser and commerce exploitation with router espionage, identity failures and faster AI-assisted intrusions. Defenders should use the converging signals to...
Google Rushes Emergency Chrome Patch as Attackers Exploit V8 Zero-Day
Google has pushed an emergency Chrome update after confirming that a type confusion flaw in the V8 engine, tracked as CVE-2026-85046, is being actively exploited in the wild....
Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified
A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...
Hard-Coded Password in Cisco’s Firewall Manager Is Being Actively Exploited, CISA Warns
CISA has issued an urgent warning about CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center that attackers are already exploiting. The bug lets unauthenticated intruders...