[HIGH] – Google Patches Actively Exploited Chrome V8 Flaw
Google issued Chrome updates for an exploited V8 out-of-bounds write; update desktop Chrome to the patched Stable release.
Cybersecurity, AI, etc.
Red teaming (offensive research, new TTPs, exploitation techniques, PoC releases, adversary simulation findings)
Google issued Chrome updates for an exploited V8 out-of-bounds write; update desktop Chrome to the patched Stable release.
CISA added a pre-authentication N-central remote-code-execution flaw to KEV; self-hosted administrators should apply N-able's hotfix.
Calif demonstrated a zero-click WeChat account-takeover worm; it says Tencent has mitigated the exploit.
CISA-listed, actively exploited Switchvox SQL injection can enable unauthenticated remote code execution.
A critical FreeIPA flaw can give an unauthenticated LDAP client administrator-group membership.
Microsoft addressed two Windows privilege-escalation flaws that CISA added to the KEV Catalog on September 8.
Rapid7 details a stealthy Linux toolkit targeting South Korean automotive and media organizations.
Sansec reports active exploitation of an unauthenticated Magento and Adobe Commerce code-execution chain.
Elastic documented persistent REVSTEALER-linked modules that steal data, weaken defenses, and mine cryptocurrency.
CERT Polska reports active exploitation of an unauthenticated RouterOS takeover chain on internet-exposed SSH services.