
Chrome Called It Medium. CISA Gave It 15 Days.
Google confirms CVE-2026-87491 in Chrome's V8 engine is being exploited. CISA lists it as a known exploited vulnerability. Chromium still calls it Medium.

Google confirms CVE-2026-87491 in Chrome's V8 engine is being exploited. CISA lists it as a known exploited vulnerability. Chromium still calls it Medium.

A joint NSA, CISA and FBI advisory tells US AI firms to secretly downgrade suspected accounts. Its detection signals also describe a company scaling up fast.

A Gamers Nexus investigation found LG smart TVs recording ambient audio from up to 60 feet away even in standby, while LG denies collecting or storing any ambient conversations.

Security researchers at Calif used AI to turn a WeChat calling bug into a self-spreading, zero-click worm in about six weeks, a job that once took a skilled team months.

Blockstream's Liquid Network lost 4,019 BTC to a software bug on September 6, 2026. A fix for a related flaw had sat unreleased for weeks.

Google, Anthropic and OpenAI each rolled out a frontier cyber-capable model this month, and all three gated access behind a vetting program instead of a normal launch.

A flaw in Lenovo's identity system let attackers open Dropbox accounts without a password. The real defect is in what Dropbox chose to trust.

Cisco disclosed a 9.8-critical unauthenticated root RCE on Nexus 9000 Silicon One switches, the chips it sells for AI-scale data centers. A fix exists, finding it does not.

ShinyHunters used a phone call, not a password, to breach McKesson's Okta login and reach up to 284 million patient records. The same crew broke in two other ways this year.

An extortion group says it broke into Manchester Airports Group using a marketing API key anyone could see in the site's own code, then published 8.7 million records.

CVE-2026-85046, patched September 3, 2026, is Chrome's sixth actively exploited zero-day this year. Three of the six targeted the same component: V8.

Microsoft disclosed on September 3, 2026 that invisible Unicode characters built to fool AI models are now hiding phishing keywords from email filters at scale.
Page 3 / 17
One considered note on infrastructure, governance, and measurement, most mornings. No theory.