A Web Page Was Enough. Chrome’s V8 Zero-Day Was Already Being Exploited.

Google patched an actively exploited V8 memory-corruption flaw reachable through a crafted web page. The fix is not complete until the browser restarts.

Google patched an actively exploited V8 memory-corruption flaw reachable through a crafted web page. The fix is not complete until the browser restarts.

A Check Point IKEv1 authentication bypass was exploited for a month before disclosure, with at least one intrusion linked to a Qilin ransomware affiliate.

Cisco’s new infrastructure-security platform combines faster vulnerability research with runtime protections. It could reduce emergency patch pressure, provided temporary shields do not become permanent exceptions. Cisco announced an agentic platform for operating and defending critical IT infrastructure on 2 June.…

CISA confirmed active exploitation of an unauthenticated SolarWinds Serv-U flaw that let one crafted request crash file-transfer services.

A malicious notebook could turn github.dev into a GitHub OAuth-token theft path with read and write access across the developer's repositories.

Google’s new AI Threat Defense portfolio aims to connect threat intelligence, exposure context and code repair. Its value will depend on whether organisations can govern the decisions between those stages. Google announced AI Threat Defense on 27 May, presenting a…

Attackers exploited a GlobalProtect authentication-cookie bypass to obtain unauthorized VPN access before a public proof of concept appeared.

Oracle fixed an unauthenticated HTTP flaw that could take over the Payments component in E-Business Suite 12.2.3 through 12.2.15.

Attackers turned FortiClient EMS into a trusted malware-delivery system, pushing the EKZ credential stealer to managed endpoints as a fake vendor patch.

A compromised Nx Console update reached a GitHub employee device, stole credentials, and exposed roughly 3,800 internal repositories.