we_are_coded.by CODE · The world, decoded
БГ
we are coded

Security, p. 3

Security

68 stories · page 3 of 8
Security
Google Chrome Releases9 September 2026Browsers

Chrome 153 fixed 230 security holes, and one of them in V8 is already used in attacks

Google released Chrome 153 on 8 September with 230 security fixes and wrote that it is aware of an exploit in the wild for CVE-2026-87491. The next day CISA added the vulnerability to its catalog of actively exploited flaws. Other Chromium browsers are affected too.

Read →
Security
CISA9 September 2026Network devices

Three devices that guard the network entered the catalog of exploited flaws in one day, with three days to patch

On 9 September CISA listed as actively exploited flaws in Cisco Secure Firewall Management Center, NetScaler ADC and Gateway, and FortiOS. The deadline for all three is 12 September. The Cisco one was disclosed back in March with the highest possible score.

Read →
Security
CISA8 September 2026Vulnerabilities

A Magento flaw rated 10 entered the catalog of exploited vulnerabilities, with three days to patch

On 8 September CISA listed four vulnerabilities as actively exploited. The one closest to online shops is in Adobe Commerce and Magento Open Source: code execution without login, rated 10.0 by Adobe, patched the day before. Next to it sit N-able N-central and two local Windows flaws.

Read →
Security
CERT Polska7 September 2026Routers

Poland's CERT confirmed attacks on MikroTik routers over SSH that began at least a day before the patch bulletin

On 5 September CERT Polska said two of the six flaws it found in RouterOS are being combined to take full control of routers with SSH open to the internet. The fixes were announced on 3 September, and the successful attacks go back to at least 2 September.

Read →
Security
Chrome Releases4 September 2026Vulnerabilities

Chrome patched a V8 flaw that Google knows is already being used

On 3 September Google released Chrome 152 with 12 security fixes. For CVE-2026-85046, a type confusion in V8, the company writes that an exploit already exists in the wild. On 4 September CISA added it to the KEV catalogue with a deadline of 18 September.

Read →
Security
CISA2 September 2026Vulnerabilities

Seven flaws in one day in the actively exploited catalogue, LiteLLM and Artifactory among them

On 2 September CISA added seven CVEs to KEV. For people running AI infrastructure, two stand out: LiteLLM lets anyone with a made-up token reach the MCP tools, and Artifactory hands out admin rights without a login. The deadline for Artifactory and SonicWall is 5 September.

Read →
Security
CISA31 August 2026Vulnerabilities

Two PaperCut flaws entered the actively exploited catalogue, and they chain together

On 31 August CISA added CVE-2026-82078 and CVE-2026-81578 in PaperCut NG and MF to the KEV catalogue. The two chain into code execution. The vendor said on 27 August that it was investigating active exploitation, and advises closing the web interface to the internet immediately.

Read →
Security
CISA27 August 2026Vulnerabilities

CISA added three actively exploited flaws to KEV: Artifactory, the Linux kernel and ownCloud

On 27 August three CVEs entered the catalogue of actively exploited vulnerabilities. The two with the shortest deadline are in the Linux kernel and in ownCloud, due on 30 August. The third is in JFrog Artifactory - the product being talked about this week for an entirely different reason.

Read →
Security
OpenAI26 August 2026Agents and security

OpenAI's models built themselves a secret mailbox in the package server, and rode it into Hugging Face

On 26 August OpenAI published the full technical report on the July incident. An internal research model and its peers found each other, traded exploits through the package repository, and went from an exam task to administrator access inside another company in ten days. They call it a warning shot themselves.

Read →