Daily Briefing
Today's outlook
Google names fixed Chrome releases for six critical flaws as CISA flags active exploitation in Linux and Zyxel gear
Good morning. Google's Chrome stable channel advisories list six vulnerabilities, each carrying a CVSS 3.1 base score of 9.6 (vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). CVE-2026-93374, CVE-2026-93373 and CVE-2026-93372 affect Chrome up to the fix in 153.0.8010.52 (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html). CVE-2026-91738, CVE-2026-91729 and CVE-2026-91728 affect Chrome up to the fix in 153.0.8010.47 (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html). Google names those fixed releases; update Chrome across your estate to at least 153.0.8010.52 and restart the browser to apply it.
BleepingComputer reported that CISA is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. Separately, CISA's own catalog update added one vulnerability based on evidence of active exploitation: a stack-based buffer overflow in Zyxel GS1900 Series switches. CISA states this type of vulnerability is a frequent attack vector for malicious cyber actors, and its Binding Operational Directive 26-04 sets remediation priorities for federal agencies. If you run Zyxel GS1900 switches or Linux hosts, prioritise the vendor updates for these and check exposure.
The Hacker News reported that a fake LastPass Authenticator installer offered on GitHub installs a Microsoft-signed Windows kernel driver that shuts off antivirus and other security software before a password stealer runs; researchers at LastPass and Delphos Labs said on September 17. Treat unofficial LastPass Authenticator downloads as hostile and hunt for unexpected kernel driver installs.
BleepingComputer reported that a proof-of-concept exploit was published for a WordPress cross-site request forgery flaw dubbed "Click2Shell" affecting the platform's Core component, letting attackers execute PHP on the server. BleepingComputer also reported BigCommerce alerted merchants to data breaches after attackers compromised credentials for third-party Ribon applications and injected malicious scripts into stores. The Register reported a Meta Muse AI app flaw lets local malware redirect dictation traffic. The Hacker News reported, citing a joint cybersecurity advisory, that North Korean threat actors behind the Contagious Interview campaign compromised at least 30,000 devices in more than 100 countries and stole $10.71M in crypto. BleepingComputer reported Microsoft will retire the Calendar, People and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. The Record and SecurityWeek reported Ireland's Data Protection Commission will fine Google more than €403 million ($462–463 million) over its processing of location data.
Vulnerability in focus
CVE-2026-93374 — Google. CVSS 9.6
Affected: chrome.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- The Register: Anthropic-linked CVEs pile up, attackers mostly shrug Read it
- BleepingComputer: BigCommerce alerts merchants of data breach linked to Ribon apps Read it
- The Record: EU data regulator fines Google more than $460 million for location data violations Read it
- The Hacker News: Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR Read it
Sources
- Anthropic-linked CVEs pile up, attackers mostly shrug The Register
- BigCommerce alerts merchants of data breach linked to Ribon apps BleepingComputer
- EU data regulator fines Google more than $460 million for location data violations The Record
- Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR The Hacker News
- Google Hit With $463 Million Fine for EU Location Data Rule Breach SecurityWeek
- Reverse-Engineering Flock Cameras Schneier on Security
- The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files Help Net Security
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- CISA alerts of active exploitation of three Linux kernel flaws BleepingComputer
- Meta Muse AI app flaw lets local malware redirect dictation traffic The Register
- Treasury chief says AI bosses, not their bots, will carry the can for criminal acts The Register
- WordPress Click2Shell flaw lets hackers execute PHP on the server BleepingComputer
- Microsoft to retire Microsoft 365 Companion apps in December BleepingComputer
- Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto The Hacker News
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.