Google has released Chrome version 146 with important security updates for Windows, Mac, and Linux users. If the flaw remains unpatched, attackers run arbitrary code, compromise systems, or cause denial-of-service issues. The critical vulnerability in this release is CVE-2026-3913, which is a severe heap buffer overflow in the WebML component. …
Read More »ALERT
ALERT
Zoom Windows Workplace Vulnerabilities Allow Privilege Escalation
Zoom has issued four security bulletins detailing several vulnerabilities in its windows client suite. The critical vulnerability CVE-2026-30903 (ZSB-26005) affects the Mail feature in Zoom Workplace for Windows. The issue arises from External Control of File Name or Path, which allows attackers to manipulate file references and carry out unauthorized …
Read More »Fortinet Patches for Multiple Vulnerabilities in its products
Fortinet issued a major security advisory on March 10, 2026, highlighting eleven vulnerabilities in its key products, such as FortiManager, FortiAnalyzer, FortiSwitchAXFixed, and FortiSandbox. The flaws include authentication bypasses, buffer overflows, OS command injection, and SQL injection, which could enable remote attackers to run arbitrary commands or gain higher privileges …
Read More »Microsoft patches 84 flaw including 2 zero days
Today is Microsoft’s March 2026 Patch Tuesday, featuring security updates for 84 flaws, which include 2 zero-day vulnerabilities that were publicly disclosed. This Patch Tuesday also addresses three “Critical” vulnerabilities, 2 of which are remote code execution flaws and the other is an information disclosure flaw. The number of bugs …
Read More »Hackers Allegedly Selling Exploit for Windows RDS 0-Day Flaw
A hacker is reportedly selling a zero-day exploit for a Windows Remote Desktop Services vulnerability, CVE-2026-21533, for $220,000 on the dark web. This exploit takes advantage of poor privilege management to give attackers local admin access. A new user, Kamirmassabi, is auctioning an exploit for CVE-2026-21533 on a dark web …
Read More »
ALERT
PoC Released for Cisco SD-WAN 0-Day Vuln Exploited in the Wild
A public POC exploit for CVE-2026-20127, a critical zero-day vulnerability in Cisco Catalyst SD-WAN Controller and Manager, has been released. This vulnerability has been actively exploited since 2023. Cisco Talos is tracking the threat activity under the cluster UAT-8616, describing it as a “highly sophisticated cyber threat actor” targeting critical …
Read More »Cisco Secure FMC Flaw Enables Remote Code Execution allowing root access
Cisco has released an urgent security alert for a critical flaw in its Secure Firewall Management Center (FMC) software. The critical flaw with a CVSS score of 10.0 lets remote, unauthenticated attackers execute arbitrary code and take full control of the affected system. This vulnerability is found in Cisco Secure FMC’s …
Read More »CISA flags VMware and Qualcomm flaw actively exploited
CISA has included the VMware Aria Operations vulnerability CVE-2026-22719 in its Known Exploited Vulnerabilities list, indicating that it is being exploited in attacks. Broadcom also warned that it is aware of reports indicating the vulnerability is exploited but says it cannot independently confirm the claims. VMware Aria Operations is a monitoring …
Read More »Android update Patched 129 Vulns and Actively Exploited Zero-Day
Google has launched a major security update, fixing 129 vulnerabilities in the March 2026 Android Security Bulletin. This update is crucial due to reports that attackers are exploiting a high-severity flaw. The centerpiece of this month’s alert is CVE-2026-21385, a high-severity memory corruption vulnerability affecting a Qualcomm display component. Google …
Read More »
Integrates 100+ security tools
Hackers To Use “CyberStrikeAI” Tool Breaching Fortinet FortiGate Devices
Team Cymru’s threat intelligence researchers found an open-source AI tool, CyberStrikeAI, being used to target Fortinet FortiGate devices extensively. According to GitHub, “CyberStrikeAI is an AI-native security testing platform built in Go. It integrates 100+ security tools, an intelligent orchestration engine, role-based testing with predefined security roles, a skills system …
Read More »
InfoSecBulletin Cybersecurity for mankind