[HIGH] – Google Patches Actively Exploited Chrome V8 Flaw
Google issued Chrome updates for an exploited V8 out-of-bounds write; update desktop Chrome to the patched Stable release.
Cybersecurity, AI, etc.
Google issued Chrome updates for an exploited V8 out-of-bounds write; update desktop Chrome to the patched Stable release.
CISA added a pre-authentication N-central remote-code-execution flaw to KEV; self-hosted administrators should apply N-able's hotfix.
Calif demonstrated a zero-click WeChat account-takeover worm; it says Tencent has mitigated the exploit.
Google observed an agent-enabled credential-harvesting campaign planned and executed in under six hours.
Check Point demonstrated a prompt-driven ChatGPT channel that could relay connected-app data across accounts.
SAP's September security updates address a CVSS 10.0 Extended Passport Processing memory-corruption vulnerability.
A critical FreeIPA flaw can give an unauthenticated LDAP client administrator-group membership.
CISA-listed, actively exploited Switchvox SQL injection can enable unauthenticated remote code execution.
Microsoft addressed two Windows privilege-escalation flaws that CISA added to the KEV Catalog on September 8.
Berlin says newly released breach data includes login credentials; officials are assessing affected systems and people.