← Back
VulnerabilityMalwarebytes Labs·2 hours ago

Update Chrome before you browse again

Chrome's latest update addresses 327 security vulnerabilities, with some posing immediate risk to users through malicious websites. Security professionals should prioritize deploying this update across their environments to close exploitation vectors that require no user interaction beyond visiting a compromised site.

Read full article at Malwarebytes Labs

Related Articles

VulnerabilityTenable·3 hours ago

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable and SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored and criminal threat actors independently converge on the same edge infrastructure vendors, with 79% vendor-level overlap despite minimal CVE-level overlap across two independent datasets. Twelve vulnerabilities show confirmed multi-nexus attribution spanning China, Russia, DPRK, Iran, and ransomware operators, demonstrating that the shared attack surface is the persistent exploitation target rather than any single adversary category. High-priority edge device CVEs face a statistically significant 24-day remediation delay compared to other vulnerabilities, with F5 showing the broadest exposure (54% of monitored customers) and Citrix showing the slowest patching timelines (461 days median), creating extended windows of opportunity for attackers across all threat actor categories.

VulnerabilitySentinelOne Labs·3 hours ago

Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter

A joint study from Tenable and SentinelOne examining two independent datasets reveals that both state-sponsored and criminal threat actors are targeting the same vulnerable edge infrastructure. The research highlights a concerning convergence where different adversary motivations lead to exploitation of perimeter defenses, suggesting organizations face multifaceted threats at their network boundaries.

VulnerabilitySecurityWeek·3 hours ago

Adobe and Nvidia Patch Dozens of Vulnerabilities

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek.

VulnerabilityCISA Advisories·4 hours ago

CISA Vulnerability Review

CISA's Vulnerability Review analyzes fiscal years 2024 and 2025 data to show that most compromises exploit well-known vulnerabilities and basic security failures rather than advanced techniques, emphasizing the need for organizations to prioritize remediation based on risk factors like exposure status, KEV Catalog inclusion, automation potential, and technical impact. The review advocates for Secure by Design principles to shift focus from reactive threat response to proactive vulnerability prevention, while identifying common software weaknesses that producers can address systematically to eliminate entire classes of vulnerabilities. Organizations can use the guidance and BOD 26-04 framework to reduce risk through foundational security improvements rather than addressing individual vulnerabilities in isolation.