04/09/2026
Source : BleepingComputer Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.
04/09/2026
Source : The Hacker News Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any […]
04/09/2026
Source : The Hacker News Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are – CVE-2026-14894 (CVSS score: 9.8) – A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated […]
04/09/2026
Source : BleepingComputer A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte […]
04/09/2026
Source : The Hacker News Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome’s JavaScript and WebAssembly engine. « Type confusion in V8 in […]
02/09/2026
Source : The Hacker News Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork […]
02/09/2026
Source : BleepingComputer International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.
02/09/2026
Source : The Hacker News The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry […]
02/09/2026
Source : BleepingComputer SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.
02/09/2026
Source : The Hacker News Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of […]