Google shipped an out-of-band Chrome update patching CVE-2026-3909 (Skia out-of-bounds write) and CVE-2026-3910 (V8 JavaScript engine bug), both under active exploitation. Security teams should update Chrome to the latest 146 build immediately and restart browsers, and consider fast-tracking patches across Chromium-based browsers. The flaws can allow memory corruption and sandbox escape, raising the risk of code execution.
Source: The Hacker News
CISA orders urgent fixes for exploited Cisco Catalyst SD‑WAN flaw
A critical authentication bypass in Cisco Catalyst SD‑WAN (CVE-2026-20127) is being actively exploited, prompting a CISA deadline for U.S. federal agencies to patch and mitigate. The flaw exposes SD‑WAN controllers to takeover, potentially enabling lateral movement across high-privilege network segments; organizations should update software, rotate credentials/tokens, and review logs for anomalous sessions.
Source: HackRead
Global takedown dismantles SocksEscort proxy network used in massive fraud
Authorities seized 34 domains and 23 servers tied to SocksEscort, a residential proxy service powered by the AVrecon botnet that hijacked roughly 360,000 home and small business routers since 2020. Investigators also froze about $3.5 million in crypto linked to the operation, which enabled large-scale fraud and account abuse; defenders should update router firmware, disable remote admin, and audit for unusual outbound proxy traffic.
Source: Help Net Security
INTERPOL’s “Synergia III” knocks out 45,000 malicious IPs and makes 94 arrests
In a 72-country crackdown, INTERPOL dismantled infrastructure used for phishing, malware, and ransomware, taking down 45,000 malicious IPs/servers and arresting 94 suspects. The action highlights ongoing pressure on cybercrime supply chains; expect threat actors to rotate command-and-control and hosting rapidly, increasing the value of adaptive blocklists and telemetry-driven detections.
Source: The Hacker News
Iran-linked attack on Stryker disrupted manufacturing using legitimate tools
Stryker’s production and shipping were disrupted after attackers leveraged existing endpoint management software to wipe devices—no custom malware required. The incident underscores the potency of “living-off-the-land” sabotage and the need to tightly monitor privileged IT tooling, enforce change controls, and log high-risk management actions.
Source: SecurityWeek
‘CrackArmor’: Nine Linux AppArmor bugs allow root escalation and container escapes
Qualys researchers disclosed nine “confused deputy” flaws in AppArmor that let unprivileged users bypass kernel protections, escalate to root, and break container isolation. Organizations should prioritize kernel/AppArmor updates on servers and container hosts, and review hardening to ensure isolation assumptions still hold.
Source: The Hacker News
SEO poisoning pushes trojanized, signed VPN clients to steal enterprise credentials
Microsoft warns of a Storm‑2561 campaign using SEO poisoning to serve fake, digitally signed installers that impersonate VPN clients from Cisco, Fortinet, Ivanti, and others. The trojans exfiltrate credentials while later redirecting victims to legitimate downloads to reduce suspicion; verify hashes and download sources, enforce application allowlists, and flag suspicious ZIPs and installers.
Source: The Hacker News
You May Also Be Interested In...
CISA adds n8n RCE flaw to Known Exploited Vulnerabilities
Fake Temu coin airdrop uses “ClickFix” to install stealthy malware
DOJ: Ransomware incident responder aided BlackCat in boosting payouts