Chrome Zero-Day Vulnerability Exploited Before the Patch

A Chrome zero-day vulnerability was already being exploited when Google shipped the fix — the sixth such Chrome bug patched in 2026.

Google says a Chrome zero-day vulnerability was already being exploited in the wild when it shipped a fix for it. Tracked as CVE-2026-85046 (CVSS 8.8), the flaw sits in V8, Chrome’s JavaScript and WebAssembly engine, and lets a crafted web page execute attacker-controlled code inside the browser sandbox. Security reporting identifies it as the sixth…

Read More

TerminalFix ClickFix Attack Campaign Hits Germany

A TerminalFix ClickFix attack campaign compromised a German state institution, BSI confirms — heise links it to Berlin's Rhysida actor cluster.

A TerminalFix ClickFix attack campaign has compromised a German state institution’s network, Germany’s Federal Office for Information Security (BSI) confirmed on September 4. TerminalFix is an evolution of the ClickFix social-engineering technique: a fake CAPTCHA tricks a user into pasting a command, but instead of the old single-machine Run-dialog trick, it opens Windows Terminal and…

Read More

SonicWall SMA1000 RCE Vulnerability: Patch Now

SonicWall SMA1000 RCE vulnerability

A new SonicWall SMA1000 RCE vulnerability is under active exploitation: an unauthenticated server-side request forgery chained with an OS command injection lets an attacker take full root-level control of the appliance with no login required. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, with a federal deadline of September 5,…

Read More

Top 5 Cybersecurity News Stories September 4, 2026

This week’s Cybersecurity News Stories September 4, 2026 illustrate a consistent challenge: the gap between a protective measure and what that measure actually closes. SonicWall enterprise remote-access appliances confirmed actively exploited via a zero-day chain requiring no credentials and no user interaction. Microsoft Exchange Server 2016 deployments without Extended Security Update eligibility facing an authentication…

Read More