
Fake Chrome Web Store DMCA Notices Target Extension Developers
Attackers send fake Chrome Web Store DMCA notices using real extension data to steal developer accounts and push malicious updates

Attackers send fake Chrome Web Store DMCA notices using real extension data to steal developer accounts and push malicious updates

Huntress disclosed a Windows Search URI handler flaw that silently sends NTLMv2 hashes to attacker servers with one click. Microsoft

CVE-2026-8206 in the Kirki WordPress plugin is under active attack, with Wordfence detecting 222 exploitation attempts targeting admin account takeover.

CISA confirmed active exploitation of Oracle WebLogic CVE-2024-21182, giving federal agencies a June 4 deadline to patch the unauthenticated data-access

CVE-2026-49975 HTTP/2 Bomb exploit achieves 5,700:1 amplification against Envoy, crashing 32 GB of server memory with a single residential connection.

Researcher Ammar Askar publicly disclosed a VS Code zero-day that lets malicious extensions steal GitHub OAuth tokens, granting full repository

Attackers backdoored 32 Red Hat npm packages with the Miasma worm, stealing CI/CD secrets, cloud keys, and SSH keys across

A confused deputy flaw in Meta’s AI support chatbot let attackers hijack Instagram accounts including @obamawhitehouse, Sephora, and U.S. Space

CVE-2026-8633 is a CVSS 9.8 unauthenticated RCE in IBM WebSphere’s Web Server Plug-ins. Patches are available for WebSphere 8.5 and

CVE-2026-8633 is a CVSS 9.8 unauthenticated RCE in IBM WebSphere’s Web Server Plug-ins. Patches are available for WebSphere 8.5 and
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.