Two critical Chrome flaws put users at risk on malicious websites
Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
SonicWall has disclosed two zero-day vulnerabilities that are currently being exploited in active attacks and has issued an urgent call for customers to apply patches. The vulnerabilities are being chained together by threat actors in real-world exploitation campaigns.
Read full article at Infosecurity Magazine ↗Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
SonicWall has patched two zero-day vulnerabilities affecting its SMA 1000 VPN appliances that are being actively exploited in the wild. The flaws, including a critical pre-authentication SSRF vulnerability with a CVSS score of 10.0, may be chained together by attackers to compromise affected systems. Security updates are now available to address these issues discovered during SonicWall's internal security review.
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold appeared first on SecurityWeek.
Two vulnerabilities in GeoNetwork can be chained together to achieve unauthenticated remote code execution against the open-source geospatial metadata catalog commonly deployed behind government and agency geoportals. The project released fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, with vulnerability details publicly disclosed on August 31.