Aggregator
US Cracks Down on Anthropic AI Models Amid Abuse Concerns
SearchJack Campaign Uses 23 Chrome Extensions to Hijack Searches of 758,000 Users
A coordinated campaign of 23 deceptive Chrome browser extensions has been quietly stealing users’ search queries and routing them through hidden revenue systems. The operation, now dubbed SearchJack, has affected roughly 758,000 Chrome users worldwide without any of them realizing their searches were being hijacked. Each extension presents itself as a useful tool, from satellite […]
The post SearchJack Campaign Uses 23 Chrome Extensions to Hijack Searches of 758,000 Users appeared first on Cyber Security News.
CVE-2026-44188 | Red Hat Ansible Automation Platform 2/2.7 session expiration (RHSA-2026:25928 / WID-SEC-2026-1923)
Webinar: How behavioral AI stops phishing and account takeovers
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
- CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating BOD 22-01. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV catalog? Submit for potential addition: KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
CVE-2026-50012 | squid-cache Squid Cache Digest heap-based overflow (Nessus ID 320883 / WID-SEC-2026-1920)
CVE-2026-47729 | squid-cache Squid FTP Gateway out-of-bounds (Nessus ID 320881 / WID-SEC-2026-1920)
CVE-2026-43964 | Postfix up to 3.8.15/3.9.9/3.10.8 off-by-one (EUVD-2026-27115 / Nessus ID 312107)
CVE-2026-25588 | RedisTimeSeries up to 1.12.13 heap-based overflow (GHSA-7jwr-g5qv-w3gw / WID-SEC-2026-1370)
CVE-2026-25589 | RedisBloom up to 2.8.19 heap-based overflow (GHSA-7862-34pw-44wv / WID-SEC-2026-1370)
CVE-2026-23479 | Redis up to 8.6.2 Data Structure processCommandAndResetClient use after free (EUVD-2026-27396 / Nessus ID 315122)
CVE-2026-23631 | Redis up to 8.6.2 Data Structure use after free (EUVD-2026-27398 / Nessus ID 315122)
CVE-2026-25243 | Redis up to 8.6.2 heap-based overflow (GHSA-c8h9-259x-jff4 / Nessus ID 315122)
CVE-2026-46243 | Linux Kernel up to 7.1-rc4 smb upcall_target input validation (Nessus ID 319568 / WID-SEC-2026-1771)
CVE-2026-48526 | jpadilla pyjwt up to 2.12.x JSON Web Token improper authentication (GHSA-xgmm-8j9v-c9wx / WID-SEC-2026-1923)
CVE-2026-44432 | urllib3 up to 2.6.x on Python HTTPResponse.drain_conn data amplification (WID-SEC-2026-1923)
CVE-2026-44431 | urllib3 up to 2.6.x on Python ProxyManager.connection_from_url.urlopen information disclosure (WID-SEC-2026-1923)
Арендовал виртуалку – получил root на хосте. Уязвимость в ядре Linux, которую два года никто не замечал
PromptSnatcher Ad Blocker Extensions Steal AI Chats From ChatGPT, Claude, and Gemini
Two browser extensions masquerading as ad blockers have been caught secretly recording private conversations from ChatGPT, Claude, Gemini, and five other major AI platforms. The extensions, named “Smart Adblocker” and “Adblock for Browser,” were installed by roughly 90,000 users before the scheme was uncovered. Users genuinely received ad-blocking functionality while their most sensitive AI conversations […]
The post PromptSnatcher Ad Blocker Extensions Steal AI Chats From ChatGPT, Claude, and Gemini appeared first on Cyber Security News.