Google has patched the sixth actively exploited Chrome zero-day of 2026, and the bug lives in the same place most of the serious ones do: the V8 JavaScript and WebAssembly engine. CVE-2026-85046 is a…
An npm supply chain attack that started with a single compromised library, keyv, has spread to at least 868 packages carrying a combined total of more than two billion monthly installs. The attack begins…
WordPress shipped a fix for a critical local file inclusion flaw on September 22. The first exploitation attempt was recorded the same day, at 11:49 UTC. Within hours it had moved from reconnaissance to…
Cisco Identity Services Engine, the box that decides who and what gets onto your network, had an authentication bypass that scored the maximum possible CVSS: 10.0 out of 10. CVE-2026-76460 sits in an API…
Fortinet is telling FortiMail customers to act now: CVE-2026-104286, a critical path traversal flaw in the appliance’s Identity-Based Encryption (IBE) component, is being actively exploited, and there is still no official patch. The bug…
Most EU AI Act write-ups are written by lawyers for lawyers, and by the end you still do not know what to put in your code. Let us fix that. The Act entered into…
GitLab patched a 9.9 in its AI Gateway this week, and it is worth more than a “patch now” headline, because it is a clean example of the bug class that is going to…
Let us be honest. If you have read anything about prompt injection, you have probably seen the party trick: paste “ignore previous instructions” into a chatbot and watch it fall over. Cute, but if…
The last five months broke the old frame where AI is a tool in an attacker’s hands. Increasingly the culprit is the AI itself: autonomous agents find and exploit flaws with no human steering…
OpenAI says it identified and disrupted a coordinated campaign that pulled protected reasoning, the model’s internal chain of thought, out of its models. The core of the activity, going back to the first week…