ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardBriefings › Actively exploited Chrome flaw and an exploited Acronis backup plugin headline Tuesday's fixes
IT SECURITY DESK

Actively exploited Chrome flaw and an exploited Acronis backup plugin headline Tuesday's fixes

Two flaws under active exploitation — one in Google Chrome, one in Acronis's backup plugin — landed alongside a record Apple patch run, a backdoored WordPress plugin, and fresh Iranian and Brazilian malware reporting.

Patch Google Chrome first. Google's advisory records CVE-2026-87491, carrying a CVSS base score of 8.8 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), affecting Chrome up to the fix in 153.0.8010.36. CISA lists CVE-2026-87491 on its Known Exploited Vulnerabilities catalog as known to be exploited. Google's advisory names 153.0.8010.36 as the fixed release. Google's advisory also records five further Chrome flaws — CVE-2026-91738, CVE-2026-91729, CVE-2026-91728, CVE-2026-91718 and CVE-2026-91716 — each scored 9.6 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) and each affecting Chrome up to the fix in 153.0.8010.47, the release Google's advisory names. CISA does not list those five on its KEV catalog. Update to the named builds and restart the browser so the fix takes effect.

Acronis is the second actively exploited item. BleepingComputer reported that Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM) and Plesk, and that it is being exploited in the wild. If you run that plugin on hosting infrastructure, treat it as a priority and follow Acronis's advisory.

On credential theft through the browser: The Hacker News reported a previously undocumented Brazilian banking malware operation delivering a toolkit called KREMLIN that hijacks Chrome and Edge to steal credentials and session tokens. Elastic Security Labs tracks the activity as REF9334 and dates it to at least May 2025, using lures that impersonate Brazilian brands.

On state espionage: The Register reported that Iranian spies hit Windows machines with data-stealing malware it calls Chosen Brick. Separately, The Hacker News reported that cybersecurity agencies in the United States, the United Kingdom and the Netherlands detailed a Telegram-controlled Windows malware they say Iran's intelligence service uses to spy on dissidents, journalists and activists, capable of copying a target's emails.

On the supply chain: BleepingComputer reported that malicious versions of the Admin Menu Editor Pro plugin for WordPress reached more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account, backdooring 1,500 sites. Audit for unrecognised administrator accounts.

CISA published an ICS advisory for CareCam CM2507, stating that successful exploitation could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation and recover stored credentials; CISA lists HMT.CM2507 Firmware v251211.1507 as affected.

Also Tuesday: BleepingComputer reported CenterPoint Energy confirmed customer personal information was stolen after an attacker leaked data, and The Register reported Apple shipped a record-setting number of patches.

Related