Google shipped fixes for 12 Chrome vulnerabilities, including CVE-2026-85046, which is known to be exploited in the wild. The update rolls out to users over the coming days/weeks across Windows, macOS, and Linux. For defenders, this is another reminder that browser patching remains one of the fastest paths for attackers to gain code execution.
Source: Help Net Security
DPRK-Linked “Ted Backdoor” and curlRAT Trojanized HAProxy for Targeted Web Injection
Rapid7 reports a previously undocumented Linux toolkit targeting organizations in South Korea’s media and automotive sectors, attributing activity with medium confidence to DPRK-linked groups. The campaign uses trojanized HAProxy builds with a custom plugin to intercept HTTP traffic, selectively alter content for chosen visitors, and exfiltrate data—while also trojanizing system daemons and running credential theft. The key defensive takeaway: edge infrastructure (load balancers, traffic gateways, SSL termination points) can be compromised and used as the “application” for long-term infiltration.
Source: Rapid7
VM Escape Flaws Patched: Broadcom Fixes Critical VMware Workstation/Fusion Host Escalation
Broadcom released updates for VMware Workstation and Fusion addressing two VM-escape vulnerabilities, including one rated Critical. The advisory notes there are no workarounds, and administrators are urged to update immediately to the latest version (26H1u1). This matters for incident response planning: even “isolated” virtual environments may not remain safe if guest-to-host escape bugs are present.
Source: Security Affairs
HPE ArubaOS-CX: Critical RCE Fixes for Network Infrastructure
HPE patched 35 ArubaOS-CX flaws, including critical issues that could enable remote code execution. For network and security teams, the immediate priority is identifying affected switches, scheduling controlled updates, and validating that management planes remain reachable only from authorized networks. The broader trend is clear: attackers keep targeting network OSes because compromises there provide privileged footholds.
Source: SCMagazine
PostGREShell (CVE-2026-6471): 12-Year-Old PostgreSQL Logic-Decode Bug Enables Takeover
Researchers highlighted a long-lived PostgreSQL flaw, dubbed PostGREShell (CVE-2026-6471), that allows a low-privileged attacker with replication access to execute code and take over servers. The vulnerability stems from missing authorization controls in logical decoding, with fixes released in recent PostgreSQL versions. Organizations running older PostgreSQL releases should treat database authorization boundaries as critical—attackers are increasingly chaining “legitimate” roles into full host compromise.
Source: Security Affairs
Microsoft Teams Adds Protection Against QR-Code Phishing
Microsoft is developing a Teams feature that will hide QR codes sent by users outside the organization, requiring recipients to explicitly reveal the image before they can view or scan it. Rollout is expected to begin in October 2026 across major platforms (Android, desktop, iOS, and Mac). For security teams, this is a practical move against a fast-growing social engineering technique that often bypasses traditional URL-based filtering.
Source: Help Net Security
G7 and CISA Urge Earlier Post-Quantum Cryptography Migration
The G7 Cyber Security Working Group and U.S. CISA issued guidance urging organizations to begin moving to post-quantum cryptography now rather than waiting. The policy signal is important: quantum readiness is shifting from long-range planning into near-term program execution, affecting crypto agility, vendor roadmaps, and key management lifecycles. Security leaders should inventory where cryptography is used and start building migration paths before deadlines narrow.
Source: The Record
You May Also Be Interested In...
Google Patches 6th Chrome Zero-Day of 2026
Broadcom Patches Critical VMware VM-Escape Vulnerabilities
EU Parliament Urges Slowdown of Serbia’s EU Entry Over Spyware Use