BlueMoon chains Chrome V8 flaws with a Windows kernel exploit to deploy GemStone, ShadowPad, and Rust-based malware in ...
CVE-2026-61500 is a critical authentication bypass in Rejetto HTTP File Server, discovered by Anthropic Mythos AI and exploited within 24 hours of public disclosure by a China-linked actor targeting ...
Google released a Chrome Stable update fixing 32 vulnerabilities, including one critical and multiple high-severity flaws ...
Fresh Chrome and Firefox updates resolve over 100 vulnerabilities, including flaws leading to code execution and sandbox escape.
Google confirmed on September 8 that attackers were already exploiting a flaw in Chrome’s V8 engine when it shipped the fix, ...
The attack targets streamers using OBS Studio version 32.2.2 or older, exploiting a cross-site scripting (XSS) flaw in custom Twitch chat overlays that insert viewer messages directly into the page as ...
A single piece of attack code, quietly built to chain three unpatched flaws in Chrome and Windows, has ended up in the hands of at least four separate hacking crews within days of each other.
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code.
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point ...
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency services.
Cybersecurity researchers have unpacked JSCeal , a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are ...
Google confirmed Thursday that attackers were already exploiting a type confusion flaw in Chrome's V8 JavaScript engine before a patch existed, marking the sixth zero-day of 2026 — and the third to ...