Actively exploited Chrome flaw and an exploited Acronis backup plugin headline Tuesday's fixes
Two flaws under active exploitation — one in Google Chrome, one in Acronis's backup plugin — landed alongside a record Apple patch run, a backdoored WordPress plugin, and fresh Iranian and Brazilian malware reporting.
Patch Google Chrome first. Google's advisory records CVE-2026-87491, carrying a CVSS base score of 8.8 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), affecting Chrome up to the fix in 153.0.8010.36. CISA lists CVE-2026-87491 on its Known Exploited Vulnerabilities catalog as known to be exploited. Google's advisory names 153.0.8010.36 as the fixed release. Google's advisory also records five further Chrome flaws — CVE-2026-91738, CVE-2026-91729, CVE-2026-91728, CVE-2026-91718 and CVE-2026-91716 — each scored 9.6 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) and each affecting Chrome up to the fix in 153.0.8010.47, the release Google's advisory names. CISA does not list those five on its KEV catalog. Update to the named builds and restart the browser so the fix takes effect.
Acronis is the second actively exploited item. BleepingComputer reported that Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM) and Plesk, and that it is being exploited in the wild. If you run that plugin on hosting infrastructure, treat it as a priority and follow Acronis's advisory.
On credential theft through the browser: The Hacker News reported a previously undocumented Brazilian banking malware operation delivering a toolkit called KREMLIN that hijacks Chrome and Edge to steal credentials and session tokens. Elastic Security Labs tracks the activity as REF9334 and dates it to at least May 2025, using lures that impersonate Brazilian brands.
On state espionage: The Register reported that Iranian spies hit Windows machines with data-stealing malware it calls Chosen Brick. Separately, The Hacker News reported that cybersecurity agencies in the United States, the United Kingdom and the Netherlands detailed a Telegram-controlled Windows malware they say Iran's intelligence service uses to spy on dissidents, journalists and activists, capable of copying a target's emails.
On the supply chain: BleepingComputer reported that malicious versions of the Admin Menu Editor Pro plugin for WordPress reached more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account, backdooring 1,500 sites. Audit for unrecognised administrator accounts.
CISA published an ICS advisory for CareCam CM2507, stating that successful exploitation could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation and recover stored credentials; CISA lists HMT.CM2507 Firmware v251211.1507 as affected.
Also Tuesday: BleepingComputer reported CenterPoint Energy confirmed customer personal information was stolen after an attacker leaked data, and The Register reported Apple shipped a record-setting number of patches.
Sources
- The Register — The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
- BleepingComputer — Acronis warns of actively exploited flaw in its cPanel backup plugin
- SecurityWeek — Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
- The Record — Norway announces investigations into telecom Telenor’s work with Myanmar junta
- The Hacker News — KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
- Help Net Security — F5 Bot Defense uses real-time risk scoring to detect fraud and abuse
- CISA — CareCam CM2507
- Schneier on Security — 25 Years of Mass Surveillance Is Enough
- BleepingComputer — Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
- The Register — Low-quality casino sites conceal highly dangerous threat actors
- SecurityWeek — “We Think the Security Control Is Working” Is No Longer Good Enough
- The Register — Iranian spies hit Windows machines with Chosen Brick data-stealing malware
- BleepingComputer — CenterPoint Energy confirms customer data stolen in cyberattack
- The Hacker News — Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists