Daily Briefing
Today's outlook
Actively exploited Chrome flaw and an exploited Acronis backup plugin headline Tuesday's fixes
Good morning. Patch Google Chrome first. Google's advisory records CVE-2026-87491, carrying a CVSS base score of 8.8 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), affecting Chrome up to the fix in 153.0.8010.36. CISA lists CVE-2026-87491 on its Known Exploited Vulnerabilities catalog as known to be exploited. Google's advisory names 153.0.8010.36 as the fixed release. Google's advisory also records five further Chrome flaws — CVE-2026-91738, CVE-2026-91729, CVE-2026-91728, CVE-2026-91718 and CVE-2026-91716 — each scored 9.6 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) and each affecting Chrome up to the fix in 153.0.8010.47, the release Google's advisory names. CISA does not list those five on its KEV catalog. Update to the named builds and restart the browser so the fix takes effect.
Acronis is the second actively exploited item. BleepingComputer reported that Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM) and Plesk, and that it is being exploited in the wild. If you run that plugin on hosting infrastructure, treat it as a priority and follow Acronis's advisory.
On credential theft through the browser: The Hacker News reported a previously undocumented Brazilian banking malware operation delivering a toolkit called KREMLIN that hijacks Chrome and Edge to steal credentials and session tokens. Elastic Security Labs tracks the activity as REF9334 and dates it to at least May 2025, using lures that impersonate Brazilian brands.
On state espionage: The Register reported that Iranian spies hit Windows machines with data-stealing malware it calls Chosen Brick. Separately, The Hacker News reported that cybersecurity agencies in the United States, the United Kingdom and the Netherlands detailed a Telegram-controlled Windows malware they say Iran's intelligence service uses to spy on dissidents, journalists and activists, capable of copying a target's emails.
On the supply chain: BleepingComputer reported that malicious versions of the Admin Menu Editor Pro plugin for WordPress reached more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account, backdooring 1,500 sites. Audit for unrecognised administrator accounts.
CISA published an ICS advisory for CareCam CM2507, stating that successful exploitation could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation and recover stored credentials; CISA lists HMT.CM2507 Firmware v251211.1507 as affected.
Also Tuesday: BleepingComputer reported CenterPoint Energy confirmed customer personal information was stolen after an attacker leaked data, and The Register reported Apple shipped a record-setting number of patches.
Zoom out: Two separately confirmed, actively exploited vulnerabilities — Google Chrome and the Acronis backup plugin — were disclosed on the same day.
Vulnerability in focus
CVE-2026-87491 — Google. CVSS 8.8 CISA lists it as known to be exploited.
Affected: chrome.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- The Register: The vulnpocalypse rains iBugs down on Apple with record-setting number of patches Read it
- BleepingComputer: Acronis warns of actively exploited flaw in its cPanel backup plugin Read it
- SecurityWeek: Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? Read it
- The Record: Norway announces investigations into telecom Telenor’s work with Myanmar junta Read it
Sources
- The vulnpocalypse rains iBugs down on Apple with record-setting number of patches The Register
- Acronis warns of actively exploited flaw in its cPanel backup plugin BleepingComputer
- Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? SecurityWeek
- Norway announces investigations into telecom Telenor’s work with Myanmar junta The Record
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News
- F5 Bot Defense uses real-time risk scoring to detect fraud and abuse Help Net Security
- CareCam CM2507 CISA
- 25 Years of Mass Surveillance Is Enough Schneier on Security
- Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites BleepingComputer
- Low-quality casino sites conceal highly dangerous threat actors The Register
- “We Think the Security Control Is Working” Is No Longer Good Enough SecurityWeek
- Iranian spies hit Windows machines with Chosen Brick data-stealing malware The Register
- CenterPoint Energy confirms customer data stolen in cyberattack BleepingComputer
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists The Hacker News
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.