惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Recent Announcements
Recent Announcements
D
Docker
IT之家
IT之家
B
Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
博客园 - 司徒正美
李成银的技术随笔
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
T
Tailwind CSS Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
小众软件
小众软件
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
M
Microsoft Research Blog - Microsoft Research
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog

The Register - Security: Patches

Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Attackers are cashing in on fresh 'CopyFail' Linux flaw Brace for the patch tsunami: AI is unearthing decades of buried code debt First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed Google's fix for critical Gemini CLI bug might break your CI/CD pipelines Google's fix for critical Gemini CLI bug might break your CI/CD pipelines Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day Critical cPanel, WHM flaw probs exploited as 0-day, pros say Linux cryptographic code flaw offers fast route to root Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks More Cisco SD-WAN bugs battered in attacks Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP Ancient Excel bug comes out of retirement for active attacks Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Microsoft's massive Patch Tuesday: It's raining bugs Zombie Microsoft bugs rise from the dead, pave way for crims and ransomware scum Zombie Microsoft bugs rise from the dead, pave way for crims and ransomware scum Attackers exploited this critical FortiClient EMS bug as a 0-day Attackers exploited this critical FortiClient EMS bug as a 0-day Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat 1K+ cloud environments infected via Trivy attack Snoops plant info-stealing malware on iPhones, Google warns Ransomware crims abused Cisco 0-day weeks before disclosure, says Amazon security boss Google rushes Chrome update fixing two zero-days already under attack Google rushes Chrome update fixing two zero-days already under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis confirms data breach at Legal & Professional arm, some customer records affected Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's database listing all bank accounts, makes off with 1.2 million records CISA gives federal agencies three days to patch actively exploited Dell bug CISA gives federal agencies three days to patch actively exploited Dell bug Attackers finally get around to exploiting critical Microsoft bug from 2024 Attackers finally get around to exploiting critical Microsoft bug from 2024 Apple patches decade-old iOS zero-day, possibly exploited by commercial spyware Microsoft's Valentine's gift to admins: 6 exploited zero-day fixes Microsoft's Valentine's gift to admins: 6 zero-day fixes Critical SolarWinds Web Help Desk bug under attack Critical SolarWinds Web Help Desk bug under attack Critical React Native Metro dev server bug under attack as researchers scream into the void Critical React Native Metro dev server bug under attack OpenClaw patches one-click RCE as security Whac-A-Mole continues January blues return as Ivanti coughs up exploited EPMM zero-days Patch or die: VMware vCenter Server bug fixed in 2024 under attack today Critical VMware vCenter Server bug under attack Fortinet admits FortiGate SSO bug still exploitable despite December patch Ancient telnet bug happily hands out root to attackers Ancient telnet bug happily hands out root to attackers Another week, another emergency patch as Cisco plugs Unified Comms zero-day Cloudflare whacks WAF bypass bug that opened side door for attackers Cloudflare whacks WAF bypass bug that opened side door for attackers Anthropic quietly fixed flaws in its Git MCP server that allowed for remote code execution Anthropic quietly fixed flaws in its Git MCP server that allowed for remote code execution Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch Patch Tuesday update makes Windows PCs refuse to shut down Cisco finally fixes max-severity bug under active attack for weeks Cisco finally fixes max-severity bug under attack for weeks Windows info-disclosure 0-day bug gets a fix as CISA sounds alarm Python libraries in AI/ML models can be poisoned w metadata Popular Python libraries used in Hugging Face models subject to poisoned metadata attack Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit CISA flags actively exploited Office relic alongside fresh HPE flaw Maximum-severity n8n flaw lets randos run your automation server Critical n8n bug allows unauthenticated server takeover Logitech macOS mouse mayhem traced to expired dev certificate Logitech macOS mouse mayhem traced to expired dev certificate An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit Microsoft rushes an out-of-band update for Message Queuing bug Microsoft rushes an out-of-band update for Message Queuing bug WatchGuard sounds alarm as critical Firebox flaw comes under active attack HPE tells customers to patch fast as OneView RCE bug scores a perfect 10 HPE OneView RCE bug scores a perfect 10 Apple, Google forced to issue emergency 0-day patches Apple, Google forced to issue emergency 0-day patches Microsoft RasMan DoS 0-day gets unofficial patch - and a working exploit Microsoft RasMan 0-day gets an unofficial patch and exploit New React vulns leak secrets, invite DoS attacks New React vulns leak secrets, invite DoS attacks Google fixes super-secret 8th Chrome 0-day Google fixes super-secret 8th Chrome 0-day Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse Microsoft fixes Windows shortcut flaw exploited for years Two Android 0-day bugs disclosed and fixed, plus 105 more to patch Two Android 0-day bugs disclosed and fixed, plus 105 more to patch Fortinet finally cops to critical make-me-admin bug under active exploitation Fortinet finally cops to critical make-me-admin bug under active exploitation Cisco warns of 'new attack variant' battering firewalls Docker Compose vulnerability opens door to host-level writes – patch pronto
Google fixes exploited Chrome CSS zero-day
2026-02-16 · via The Register - Security: Patches

Security

Google patches Chrome zero-day as in-the-wild exploits surface

High-severity CSS flaw let malicious webpages run code inside the sandbox

Google has quietly pushed out an emergency Chrome fix after attackers were caught exploiting the browser's first reported zero-day of 2026.

The flaw, tracked as CVE-2026-2441 and assigned a "high" CVSS score of 8.8, stems from a use-after-free bug in Chrome's CSS handling that could allow a remote attacker to execute arbitrary code inside the browser's sandbox using a specially crafted HTML page. In other words, a dodgy webpage could be all an attacker needs to get malicious code running inside a victim's browser.

Unsurprisingly, Google has rushed out fixes for Chrome with version 145.0.7632.75 for Windows and Mac, and 144.0.7559.75 for Linux, which the Chocolate Factory says will "roll out in the coming days/weeks."

REG AD

Security researcher Shaheen Fazim reported the flaw on February 11, and Google acknowledged that attackers were already exploiting it just two days later – though it's staying tight-lipped on the specifics. The company has not said whether the attacks were targeted or part of a broader exploitation campaign, only that the vulnerability was being abused before a fix was ready.

REG AD

"Google is aware that an exploit for CVE-2026-2441 exists in the wild," its security advisory stated.

Google said access to further details about the bug will remain under wraps until most users are patched, and potentially longer if third-party dependencies are involved, a standard move aimed at stopping others from quickly weaponizing the bug.

If this all feels a bit familiar, that's because it is. Google spent much of last year playing Whac-A-Mole with actively exploited Chrome bugs, ultimately patching eight zero-days across 2025.

The fix also lands days after researchers revealed that at least 287 Chrome extensions, with tens of millions of installs between them, were quietly siphoning off users' browsing histories to a long list of outside recipients – a handy reminder that data can leak not just through software flaws but through the sprawling ecosystem bolted onto the browser. ®