Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

1+ day, 17+ hour ago   (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...

SecurityWeek
securityweek.com > new-shieldcrash-zero-day-exploit-targets-microsoft-defender > amp

New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender

2+ day, 19+ hour ago   (397+ words) The exploit provides full System privileges on Windows machines running the September 2026 patches. The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare. However,…...

SecurityWeek
securityweek.com > chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

3+ day, 12+ hour ago   (453+ words) Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products. AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could…...

SecurityWeek
securityweek.com > androids-september-2026-updates-patch-180-vulnerabilities

Android’s September 2026 Updates Patch 180 Vulnerabilities

3+ day, 12+ hour ago   (577+ words) The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security…...

SecurityWeek
securityweek.com > ivanti-patches-critical-flaws-across-enterprise-security-products

Ivanti Patches Critical Flaws Across Enterprise Security Products

3+ day, 18+ hour ago   (410+ words) Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for…...

SecurityWeek
securityweek.com > new-phishing-attack-creates-malicious-pages-inside-the-victims-browser

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

3+ day, 18+ hour ago   (434+ words) Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. Future phishing campaigns may no longer involve a detectable physical web page. The attack flow…...

SecurityWeek
securityweek.com > microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

4+ day, 9+ hour ago   (727+ words) Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local…...

SecurityWeek
securityweek.com > adobe-patches-over-170-vulnerabilities-including-commerce-zero-day

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

4+ day, 10+ hour ago   (547+ words) Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score…...

SecurityWeek
securityweek.com > hpe-patches-critical-rce-vulnerabilities-in-aos-cx

HPE Patches Critical RCE Vulnerabilities in AOS-CX

1+ week, 1+ day ago   (479+ words) Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in the Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are…...

SecurityWeek
securityweek.com > vmware-workstation-and-fusion-updates-patch-critical-vulnerability

VMware Workstation and Fusion Updates Patch Critical Vulnerability

1+ week, 1+ day ago   (440+ words) The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion. The first issue, tracked as…...