Daily Briefing
Today's outlook
Three actively exploited flaws hit CISA's KEV list — Chrome and Windows Server both named
Good morning. Start with the three flaws CISA lists as known to be exploited. CVE-2026-87491 affects Google Chrome up to the fix in 153.0.8010.36; its CVSS:3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8, requiring user interaction over the network. CVE-2026-85880 and CVE-2026-81963 both affect Microsoft Windows Server, each carrying the CVSS:3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, base score 7.8 — local, low-privilege paths to full confidentiality, integrity and availability loss. Match your estate against those products and treat them as first in the queue.
For remediation, Google's advisory names the fixed Chrome release as 153.0.8010.36. Microsoft's advisory names the fixed Windows Server builds as 10.0.14393.9512 for CVE-2026-85880 and 10.0.26100.33438 for CVE-2026-81963. Apply the vendor patches named in each advisory. CISA directs stakeholders to evaluate each asset's internet exposure and follow BOD 26-04 patching guidance.
Google's same Chrome release also fixes three flaws that are not on the KEV list: CVE-2026-87654, CVE-2026-87650 and CVE-2026-87646. Each carries the CVSS:3.1 vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, a scope change with a base score of 9.6. Updating Chrome to 153.0.8010.36 addresses these alongside the exploited one.
SecurityWeek reports a new zero-day exploit it calls "ShieldCrash" targeting Microsoft Defender, and says the exploit provides full System privileges on Windows machines running the September 2026 patches.
In other reporting for the day: BleepingComputer reports that Microsoft's September 2026 Patch Tuesday updates fix a known issue that caused desktop settings to be lost or reset on some Windows devices. SecurityWeek reports a Fortinet unauthenticated code execution flaw, patched in January 2026, is being exploited in PivotC2 RAT attacks. BleepingComputer reports that Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. Help Net Security, citing Barracuda researchers, reports a phishing campaign that routes victims through genuine Microsoft OAuth and Teams infrastructure before assembling a fake login page entirely inside the victim's own browser. The Hacker News reports the U.S. Department of Justice announced actions against the Xinbi Guarantee scam marketplace, seizing Telegram channels, confiscating two cryptocurrency wallets and freezing $52.8 million in crypto.
Zoom out: The Register reports that a novel "Blue Moon" kit targeting Chrome and Windows reflects a new reality of AI-driven exploits.
Vulnerability in focus
CVE-2026-87491 — Google. CVSS 8.8 CISA lists it as known to be exploited.
Affected: chrome.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- BleepingComputer: Microsoft fixes bug that wiped Windows desktop settings Read it
- SecurityWeek: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender Read it
- The Register: Dental contractor set up secret account with access to 4,000 patient records then left the company Read it
- Help Net Security: Product showcase: GitGuardian Honeytoken catches credential theft as it happens Read it
Sources
- Microsoft fixes bug that wiped Windows desktop settings BleepingComputer
- New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender SecurityWeek
- Dental contractor set up secret account with access to 4,000 patient records then left the company The Register
- Product showcase: GitGuardian Honeytoken catches credential theft as it happens Help Net Security
- CISA head says agency must change quickly to prevent the 'worst that could happen' The Record
- U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto The Hacker News
- Trezor warns users of email provider breach, phishing attacks BleepingComputer
- Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks SecurityWeek
- Cybercriminals are building phishing pages that exist only inside victims’ browsers Help Net Security
- AI adoption brings new security headaches for already stretched CISOs Help Net Security
- A new open standard locks AI weights to approved hardware Help Net Security
- Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity Help Net Security
- Anthropic reveals fourth likely crime committed by its AI The Register
- Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits The Register
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.