Risk
-
Google patches Chrome zero-day CVE-2026-11645 after active exploitation
Google has patched 74 Chrome flaws, including CVE-2026-11645, a high-severity zero-day in the V8 engine that the company said was being exploited in the wild. Users are urged to update Chrome and other Chromium-based browsers.
-
Browser-based FROST attack can infer site visits from SSD timing
Researchers at Graz University of Technology say a browser-based attack called FROST can infer site visits and app launches from SSD timing, reaching 88.95% accuracy in one macOS test and working without native code or a permission prompt.
-
Microsoft removes 73 GitHub repositories during malware investigation
Microsoft removed 73 GitHub repositories on June 5 while investigating potential malicious content, briefly disrupting developer pipelines tied to Azure Functions. Researchers linked the incident to a broader Miasma and Shai-Hulud supply-chain campaign.
-
Veeam patches critical backup software flaw that could allow remote code execution
Veeam patched a critical flaw in Backup & Replication that could allow remote code execution on a backup server. The bug affects some 12.x releases and was fixed in version 12.3.2.4854.
-
Russia-Aligned Hackers Keep Exploiting WinRAR Flaw to Target Ukraine
Russia-aligned hacking groups have kept exploiting a patched WinRAR flaw against Ukrainian organizations, using crafted archives, hidden payloads and stolen browser data in campaigns that researchers said remained active into 2026.
-
Malicious PyPI packages tied to Hades attack wave, researchers say
Researchers said a new Hades supply chain campaign poisoned 37 wheel artifacts across 19 PyPI packages, using startup hooks to run Bun-based malware that sought cloud, repository and developer credentials.
-
CISA flags LiteLLM flaw as exploited in the wild
CISA said a high-severity LiteLLM command injection flaw is being actively exploited. The bug can let authenticated users run commands on the host, and researchers warned it may be chained with a Starlette issue for unauthenticated access.
-
VS Code adds 2 hour delay for extension auto updates
Microsoft has added a two hour delay before Visual Studio Code auto updates most extensions, a move aimed at limiting supply chain risk. Trusted publishers are exempt, and users can still update manually.
-
Oxford University says CareerConnect breach exposed user names, emails and passwords
Oxford University said a breach of its third-party CareerConnect platform exposed user names, email addresses and encrypted passwords on May 28. The university said its own systems were not compromised and warned of possible phishing attempts.
-
China-nexus group used BSD variant of BRICKSTORM in long-running intrusion, Volexity says
A China-nexus group used a BSD variant of BRICKSTORM, PLENET and AGENTPSD in a long-running intrusion against Linux systems, according to a Volexity technical analysis that traced activity through a victim, an MSP and a NAS device.









