Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
The Chain That Opened the Crisis: How SonicWall SMA1000’s First Zero-Day Turned VPN Appliances Into MFA Harvesting Machines
57+ min ago (129+ words) CVE-2026-15409 chained SSRF and code injection to achieve root on SMA1000 appliances, stealing TOTP MFA seeds and turning the VPN gateway into a persistent surveillance platform. CISA flagged it for ransomware exploitation. We covered the second chain but never the first…...
Check Point VPN CVE-2026-85102 and CVE-2026-85103: Early Warning for Pre-Authentication RCE
8+ hour, 20+ min ago (1541+ words) 1. Basic Information Original Title: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Source: BleepingComputer, Dutch NCSC, Check Point Published Date: 2026-09-12 Severity: High Basis for Severity: Both CVSS 9.8 vulnerabilities allow unauthenticated remote code execution. Although the reference materials do…...
Automox Launches AI-Speed Cybersecurity Vulnerability Mitigation Pipeline to Reduce Exposure for Unpatchable Vulnerabilities
3+ day, 4+ hour ago (295+ words) AI-powered Automox Worklet™ generation closes the time window between AI-speed cybersecurity vulnerability disclosure and exposure mitigation: built to mitigate at AI speed, vetted by humans, turning vulnerabilities into verified endpoint action even when a patch isn't the immediate fix. These…...
Dutch NCSC says Check Point VPN flaw exploitation is imminent – 4sysops
16+ hour, 30+ min ago (25+ words) The Dutch NCSC now expects attackers to target two critical Check Point VPN flaws soon, despite no public proof-of-concept exploit. The warning raises the urgen...
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
1+ day, 23+ hour ago (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...
Memory64 moved the browser ceiling and exposed an ABI gap
1+ day, 6+ hour ago (364+ words) A 32-bit WebAssembly heap put the browser playground near a 4 GB ceiling. With weights and AdamW state, that limited the fp32 model size to roughly 250 million parameters. Compiling the same C++ source with Memory64 and BigInt support changed the pointer width. One…...
BlueMoon Exploit Kit Can Escape Chrome and Elevate Windows Privileges
2+ day, 2+ hour ago (355+ words) Published on September 11, 2026 BlueMoon exploit kit chains Windows and Chrome zero-days in targeted attacks, giving cyber-espionage groups a way to execute code, escape Chrome’s sandbox, and gain elevated Windows privileges. Proofpoint observed attacks involving BlueMoon starting on August 28, 2026, while Volexity…...
Attackers are weaponizing the gap between Chromium fixes and Chrome patches
2+ day, 9+ hour ago (642+ words) A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities…...
Microsoft Fixes Nearly 1,000 Vulnerabilities Across Windows, Office, and Azure
2+ day, 19+ hour ago (23+ words) TechPowerUp Automated bot check in progress Drag the handle to the target...
Record September Patch Tuesday: 974 flaws, two exploited
2+ day, 17+ hour ago (302+ words) Microsoft's September Patch Tuesday fixes a record 974 flaws, two already exploited and 20 wormable. What to patch first, and why AI is behind it....