Google names fixed Chrome releases for six critical flaws as CISA flags active exploitation in Linux and Zyxel gear
Six 9.6-rated Chrome vulnerabilities arrived with fixed releases named, alongside confirmed in-the-wild exploitation of three Linux kernel flaws and a Zyxel switch flaw, and a fake LastPass Authenticator installer that disables security software.
Google's Chrome stable channel advisories list six vulnerabilities, each carrying a CVSS 3.1 base score of 9.6 (vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). CVE-2026-93374, CVE-2026-93373 and CVE-2026-93372 affect Chrome up to the fix in 153.0.8010.52 (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html). CVE-2026-91738, CVE-2026-91729 and CVE-2026-91728 affect Chrome up to the fix in 153.0.8010.47 (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html). Google names those fixed releases; update Chrome across your estate to at least 153.0.8010.52 and restart the browser to apply it.
BleepingComputer reported that CISA is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. Separately, CISA's own catalog update added one vulnerability based on evidence of active exploitation: a stack-based buffer overflow in Zyxel GS1900 Series switches. CISA states this type of vulnerability is a frequent attack vector for malicious cyber actors, and its Binding Operational Directive 26-04 sets remediation priorities for federal agencies. If you run Zyxel GS1900 switches or Linux hosts, prioritise the vendor updates for these and check exposure.
The Hacker News reported that a fake LastPass Authenticator installer offered on GitHub installs a Microsoft-signed Windows kernel driver that shuts off antivirus and other security software before a password stealer runs; researchers at LastPass and Delphos Labs said on September 17. Treat unofficial LastPass Authenticator downloads as hostile and hunt for unexpected kernel driver installs.
BleepingComputer reported that a proof-of-concept exploit was published for a WordPress cross-site request forgery flaw dubbed "Click2Shell" affecting the platform's Core component, letting attackers execute PHP on the server. BleepingComputer also reported BigCommerce alerted merchants to data breaches after attackers compromised credentials for third-party Ribon applications and injected malicious scripts into stores. The Register reported a Meta Muse AI app flaw lets local malware redirect dictation traffic. The Hacker News reported, citing a joint cybersecurity advisory, that North Korean threat actors behind the Contagious Interview campaign compromised at least 30,000 devices in more than 100 countries and stole $10.71M in crypto. BleepingComputer reported Microsoft will retire the Calendar, People and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. The Record and SecurityWeek reported Ireland's Data Protection Commission will fine Google more than €403 million ($462–463 million) over its processing of location data.
Sources
- The Register — Anthropic-linked CVEs pile up, attackers mostly shrug
- BleepingComputer — BigCommerce alerts merchants of data breach linked to Ribon apps
- The Record — EU data regulator fines Google more than $460 million for location data violations
- The Hacker News — Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
- SecurityWeek — Google Hit With $463 Million Fine for EU Location Data Rule Breach
- Schneier on Security — Reverse-Engineering Flock Cameras
- Help Net Security — The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
- CISA — CISA Adds One Known Exploited Vulnerability to Catalog
- BleepingComputer — CISA alerts of active exploitation of three Linux kernel flaws
- The Register — Meta Muse AI app flaw lets local malware redirect dictation traffic
- The Register — Treasury chief says AI bosses, not their bots, will carry the can for criminal acts
- BleepingComputer — WordPress Click2Shell flaw lets hackers execute PHP on the server
- BleepingComputer — Microsoft to retire Microsoft 365 Companion apps in December
- The Hacker News — Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto