Chrome's Sixth Zero-Day of 2026, and Browser Zero-Days Keep Falling
CVE-2026-85046 is a V8 type confusion patched in Chrome 152 with a CISA deadline of 18 September. Across all browsers th...
ASEAN edition · Wed, 9 Sep 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
CVE-2026-85046 is a V8 type confusion patched in Chrome 152 with a CISA deadline of 18 September. Across all browsers th...
Fifty-seven attacks caused physical damage in 2025. Ransomware flat-lined while nation-state and hacktivist attacks roug...
Unit 42 describes agents running reconnaissance through to CI/CD hijacking in under ten hours. The 80-page report left b...
A campaign that ran in 2016 and 2017 reaches court next month. It targeted freelancers, a population whose work makes th...
Sality has no command server to seize, so investigators poisoned the peer lists instead and let the botnet's own houseke...
Sygnia has documented an espionage group running fake services on Cisco routers during alternating hours. The authentica...
The exploits were ordinary: a token-refresh flaw, an HDF5 bug, a template injection. What was not ordinary was two month...
Google patched 1,072 Chrome bugs in June against 1,036 in the prior two years. Whether that drains the exploit supply de...
The advisory that published the fix is what told attackers where to look, and the draining began the following day. The...
The agency confirmed an incident on a standalone system and the Justice Department designated it major, a statutory cate...
The International Burke Institute had a website, an address and a country ranking. The AI drafted the social posts and s...
An Iran-linked attack stopped a small UK plant for four days in July. The energy department says the wider system was ne...
CVE-2026-68820 sits in Winsock, the same component North Korean operators abused in 2024. Check Point ties current explo...
CVE-2026-64849 is an unauthenticated server-side request forgery in MLflow scoring 9.3. Two days after disclosure CISA a...
MAS and the Association of Banks stood up the ACT taskforce on 28 July with DBS, OCBC, UOB, SGX, NETS and Banking Comput...
A five-agency advisory names Siemens S7 PLCs at water, energy, chemical and manufacturing sites, with exploitation scrip...
CVE-2026-59310 was disclosed on 29 July, exploited from 3 August, and 95 per cent of the campaign's eventual victims wer...
An unauthenticated SQL injection reaching remote code execution was posted publicly on 12 August. Scanning began within...
CrowdStrike puts 88 per cent of observed proof-of-concept exploitation inside two days, and two China-linked groups insi...
A six-agency advisory documents operators who altered a virtual desktop authentication portal so an attacker-chosen one-...
Taiwan confirms AI agent-assisted attacks on government agencies in July. A vendor calls it near-autonomous; the ministr...
Zoom patched four flaws in its annotation protocol on 11 August. The researchers say they went from decompiled binary to...
Zscaler tracked 351 victims across 334 organisations in one campaign. Sixty-two per cent were managers or above, the ave...
July produced 799 ransomware attacks by the standard count, second only to March in 2026. Victims confirmed 51 of them....