Three actively exploited flaws land on CISA's KEV list; Google ships a Chrome release fixing four bugs
CISA lists one Chrome flaw and two Windows Server flaws as known to be exploited, while Microsoft discloses two active campaigns and BleepingComputer reports a China-aligned group deploying a backdoor through a Tencent app.
CISA lists three vulnerabilities from the record as known to be exploited. CVE-2026-87491 is in Google Chrome and carries a CVSS base score of 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Google's advisory names 153.0.8010.36 as the fixed desktop release (chromereleases.googleblog.com). CVE-2026-85880 and CVE-2026-81963 are in Microsoft Windows Server, each scored CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Microsoft's advisory names build 10.0.14393.9512 as the fix for CVE-2026-85880 and build 10.0.26100.33438 as the fix for CVE-2026-81963 (msrc.microsoft.com). Match these products against your inventory and apply the named fixes; CISA's KEV entry directs stakeholders to follow vendor mitigations under BOD 26-04.
The same Chrome release addresses three further vulnerabilities, each scored CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H): CVE-2026-87654, CVE-2026-87650 and CVE-2026-87646. These are not on the KEV list. Google's advisory names 153.0.8010.36 as the fixed release for all three. Updating Chrome to that build covers this trio and CVE-2026-87491 together.
BleepingComputer reported that threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. If Sogou Input Method runs on Windows endpoints in your estate, treat those hosts as in scope and hunt for backdoor activity.
The Hacker News reported that Microsoft disclosed two campaigns: one abusing third-party email delivery infrastructure to send over a million financial-fraud scam messages, and one using passkey-themed social engineering to breach cloud environments and exfiltrate data. Review passkey enrolment and consent flows in your Microsoft cloud tenant, and inspect mail routed through third-party delivery infrastructure.
Help Net Security's week-in-review flagged a Linux rootkit deployed on F5 BIG-IP APM devices and Cisco FMC bugs being exploited. Operators of those products should follow the vendor advisories.
In wider news, The Record reported the NSA is reorganizing into five mission centers, including cyber and AI. SecurityWeek reported that Anthropic CEO Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The Register argued that security through obscurity is dead.
Sources
- The Record — Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI
- BleepingComputer — Hackers exploit Tencent app flaw to deploy GrayRabbit malware
- SecurityWeek — Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
- The Register — Security through obscurity is dead, and AI delivered the fatal blow
- The Hacker News — Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
- Help Net Security — Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited