ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardDaily Briefing › 13 Sept 2026

Daily Briefing

Today's outlook

Three actively exploited flaws land on CISA's KEV list; Google ships a Chrome release fixing four bugs

Good morning. CISA lists three vulnerabilities from the record as known to be exploited. CVE-2026-87491 is in Google Chrome and carries a CVSS base score of 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Google's advisory names 153.0.8010.36 as the fixed desktop release (chromereleases.googleblog.com). CVE-2026-85880 and CVE-2026-81963 are in Microsoft Windows Server, each scored CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Microsoft's advisory names build 10.0.14393.9512 as the fix for CVE-2026-85880 and build 10.0.26100.33438 as the fix for CVE-2026-81963 (msrc.microsoft.com). Match these products against your inventory and apply the named fixes; CISA's KEV entry directs stakeholders to follow vendor mitigations under BOD 26-04.

The same Chrome release addresses three further vulnerabilities, each scored CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H): CVE-2026-87654, CVE-2026-87650 and CVE-2026-87646. These are not on the KEV list. Google's advisory names 153.0.8010.36 as the fixed release for all three. Updating Chrome to that build covers this trio and CVE-2026-87491 together.

BleepingComputer reported that threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. If Sogou Input Method runs on Windows endpoints in your estate, treat those hosts as in scope and hunt for backdoor activity.

The Hacker News reported that Microsoft disclosed two campaigns: one abusing third-party email delivery infrastructure to send over a million financial-fraud scam messages, and one using passkey-themed social engineering to breach cloud environments and exfiltrate data. Review passkey enrolment and consent flows in your Microsoft cloud tenant, and inspect mail routed through third-party delivery infrastructure.

Help Net Security's week-in-review flagged a Linux rootkit deployed on F5 BIG-IP APM devices and Cisco FMC bugs being exploited. Operators of those products should follow the vendor advisories.

In wider news, The Record reported the NSA is reorganizing into five mission centers, including cyber and AI. SecurityWeek reported that Anthropic CEO Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The Register argued that security through obscurity is dead.

Zoom out: Three of the day's catalogued vulnerabilities are on CISA's Known Exploited Vulnerabilities list as actively exploited, alongside two active campaigns Microsoft disclosed.

Vulnerability in focus

CVE-2026-87491 — Google. CVSS 8.8 CISA lists it as known to be exploited.

Affected: chrome.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

What we're tracking

  • The Record: Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI Read it
  • BleepingComputer: Hackers exploit Tencent app flaw to deploy GrayRabbit malware Read it
  • SecurityWeek: Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up Read it
  • The Register: Security through obscurity is dead, and AI delivered the fatal blow Read it

Sources

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →