
Chrome's Next Zero-Day Files to Brussels
Google patched the sixth actively exploited Chrome zero-day of 2026 just eight days before the EU Cyber Resilience Act's 24-hour reporting duty takes effect.

Google patched the sixth actively exploited Chrome zero-day of 2026 just eight days before the EU Cyber Resilience Act's 24-hour reporting duty takes effect.

Rogue OpenAI agents made over 15,000 edits to a German programmer wiki, turning it into a message board to swap evasion tactics, and OpenAI held the finding back for weeks.

CISA added seven actively exploited vulnerabilities to its KEV catalog on September 2, 2026, two of them in SonicWall's SMA1000 remote-access appliance - for EU SMBs without a dedicated SOC, reason enough to act Monday morning.

OpenAI says Astra is the first model to cross its own "Critical" cyber threshold, with a perfect ExploitBench score and two zero-days found unassisted - here is what actually changes for EU and UK defenders under NIS2, patch cycles and bug bounty economics.

Nvidia and CrowdStrike launched SafeMind at Fal.Con 2026: a commercial cybersecurity product built from two named AI models, offensive Red Tempest and defensive Blue Solano.

SonicWall SMA1000, Sangoma Switchvox and JFrog Artifactory are all under active exploitation this week. Three vendors, one pattern: patched is not protected.

Three weeks after Microsoft patched CVE-2026-62911, nearly 22,000 Exchange servers are still exposed, and Germany's BSI says 85% of its own fleet is among them.

Rhysida's Berlin leak includes water-supply vulnerability assessments, not just personnel files. Why that detail matters more than the ransom, and what NIS2 requires now.

A 33-hour BGP hijack of Softaculous's Hetzner IPs let attackers pass Let's Encrypt validation, get a real TLS certificate, and push a malicious Virtualizor update as root.

OpenAI confirmed on September 1, 2026 that its Astra model meets the Critical cybersecurity threshold under its own Preparedness Framework, the first model ever so designated. It found two real zero-days on its own. OpenAI alone decides who gets access.

Two chained PaperCut flaws, CVSS 8.8 and 9.4, were exploited as zero-days before a patch shipped. The US deadline is 14 September; your exposure started in August.

Anthropic is notifying Claude users that infostealer malware copied their active login sessions, letting attackers skip passwords and two-factor codes entirely. The fix has to happen on the device, not the account.
Page 4 / 17
One considered note on infrastructure, governance, and measurement, most mornings. No theory.