Two critical Chrome flaws put users at risk on malicious websites
Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold appeared first on SecurityWeek.
Read full article at SecurityWeek ↗Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
SonicWall has patched two zero-day vulnerabilities affecting its SMA 1000 VPN appliances that are being actively exploited in the wild. The flaws, including a critical pre-authentication SSRF vulnerability with a CVSS score of 10.0, may be chained together by attackers to compromise affected systems. Security updates are now available to address these issues discovered during SonicWall's internal security review.
Two vulnerabilities in GeoNetwork can be chained together to achieve unauthenticated remote code execution against the open-source geospatial metadata catalog commonly deployed behind government and agency geoportals. The project released fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, with vulnerability details publicly disclosed on August 31.
Chrome and Firefox have released updates addressing multiple vulnerability categories including use-after-free bugs, sandbox escape flaws, and privilege escalation issues. Security professionals should prioritize deploying these browser updates to mitigate the patched attack vectors.