Google has released an emergency security update for the Chrome browser to address two high-severity zero-day vulnerabilities, CVE-2026-3909 and CVE-2026-3910, which are confirmed to be under active exploitation.
Vulnerability Details
Affected Product: Google Chrome versions prior to 146.0.7680.75/76
Identifier: CVE-2026-3909, CVE-2026-3910
CVSS Score: 8.8 (High)
Exploitation Status: Actively Exploited
Risk & Impact
Triage: Immediate update is required due to active exploitation.
Attack Vector: A remote attacker can exploit these vulnerabilities by tricking a user into visiting a specially crafted HTML page. This could lead to memory corruption, sandbox escape, or arbitrary code execution.
Ease of Exploit: The vulnerabilities are being actively used in the wild, indicating that a viable exploit exists.
Action Plan
Immediate Action: Update to Google Chrome version 146.0.7680.75/76 for Windows/macOS and 146.0.7680.75 for Linux. Users should relaunch the browser to apply the update.
Workaround: No specific workarounds have been provided; updating the browser is the only recommended mitigation.
Detection: Google has not released technical details about the exploits or specific Indicators of Compromise (IOCs) to prevent further abuse.
Relevant professional terms
Zero-Day Vulnerability
A flaw in software or hardware that is unknown to the party responsible for patching it. In this case, the vulnerabilities were being exploited before Google could release a fix.
Out-of-Bounds Write
A type of memory corruption bug where a program writes data past the end, or before the beginning, of an intended buffer. This can lead to crashes, incorrect behavior, or code execution, as seen in CVE-2026-3909.
Researchers have disclosed nine critical "confused deputy" vulnerabilities in the Linux kernel's AppArmor module, collectively named "CrackArmor".
These flaws, which have existed since 2017, can be exploited by unprivileged local users to bypass kernel protections, escalate privileges to root, and escape container isolation.
As of publication, no CVE identifiers have been assigned, but immediate patching is recommended.
Vulnerability Details
Affected Product: Linux kernel versions since v4.11 (released in 2017) on distributions that integrate AppArmor, including Ubuntu, Debian, and SUSE.
Identifier: None assigned. The upstream Linux kernel team is the assigning authority.
Exploitation Status: Proof of Concept (PoC) exploits exist but have not been publicly released.
Risk & Impact
Triage: Urgent. These vulnerabilities allow for a full local privilege escalation (LPE) to root, undermining fundamental system and container security.
Attack Vector: An unprivileged local user can exploit a "confused deputy" flaw by manipulating a privileged process (like Sudo or Postfix) to modify AppArmor security profiles via pseudo-files in `/sys/kernel/security/apparmor/`. This allows the attacker to bypass user-namespace restrictions and execute arbitrary code within the kernel.
Ease of Exploit: Researchers have developed a full attack chain PoC, indicating that exploitation is practical, though the exact complexity is not public.
Action Plan
Immediate Action: Apply the latest kernel patches provided by your Linux distribution vendor immediately.
Workaround: There is no effective workaround besides patching.
Detection: Monitor for unauthorized or unexpected changes to AppArmor profiles located in `/sys/kernel/security/apparmor/`.
Relevant professional terms
AppArmor
A Linux Security Module (LSM) that provides Mandatory Access Control (MAC) by confining programs to a limited set of resources. It works by applying security profiles to individual applications to restrict their capabilities.
Confused Deputy Vulnerability
A type of security flaw where a program with elevated privileges is tricked by a less-privileged entity into misusing its authority to perform actions the user is not authorized to perform.
The Iran-linked group Void Manticore, operating as Handala Hack, is increasing destructive wiper attacks against organizations in the US and Israel. The group uses phishing to gain initial access and misuses Microsoft Intune to deploy malware designed to erase data and disrupt operations.
Key TTPs
Initial Access: Phishing campaigns are used to steal credentials and gain entry into target networks.
Execution: The group uses custom PowerShell scripts and off-the-shelf tools to execute wiper malware, which permanently deletes data.
Defense Evasion: Attackers misuse Microsoft Intune to remotely wipe devices and servers, appearing as legitimate administrative activity.
Campaign Analysis
Void Manticore's operations represent a hybrid approach, combining data-wiping attacks with psychological warfare and public information leaks to maximize impact. This escalation indicates a strategic shift to cause significant disruption for entities in the US, Israel, and Albania.
Targeting & Infrastructure
Target Profile: The group primarily targets government, defense, telecom, and medical technology sectors in Israel and the United States.
Infrastructure: Operations leverage commercial VPN services and have been observed using Starlink IP ranges to obscure their origin.
Wiper Attack: A type of cyberattack that permanently erases data from targeted systems, with the primary goal of disruption rather than financial gain.
Microsoft Intune: A cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM), allowing organizations to control how their devices are used.
A suspected China-based espionage group is targeting military organizations across Southeast Asia with custom backdoors for intelligence collection. The campaign, active since at least 2020, demonstrates strategic patience, focusing on specific military and strategic data rather than bulk theft.
Key TTPs
Execution: Deploys custom backdoors named AppleChris and MemFun.
Defense Evasion: Employs a Dead Drop Resolver (DDR) technique using a shared Pastebin account to fetch C2 server addresses.
Campaign Analysis
This long-running campaign is notable for its use of custom-developed tools and highly stable operational infrastructure. The attackers maintain dormant access for months, focusing on precision intelligence gathering and implementing robust security to ensure campaign longevity.
Targeting & Infrastructure
Target Profile: Military organizations throughout Southeast Asia.
Infrastructure: Utilizes China-based cloud networks for Command and Control (C2) servers.
Relevant Terms
Backdoor: A type of malware that bypasses normal authentication procedures to grant a remote attacker unauthorized access to a system.
Dead Drop Resolver (DDR): An evasion technique where malware retrieves its command-and-control (C2) server address from a legitimate public web service, like a social media site or a pastebin, making it harder to block.
A campaign is using a fake Temu cryptocurrency airdrop to entice users into executing malware. The attack uses a social engineering technique known as "ClickFix" to trick victims into running malicious commands, ultimately installing a stealthy remote-access backdoor.
Key TTPs
Initial Access: Lures victims with a fake website promoting a cryptocurrency airdrop for the Temu brand.
Execution: The "ClickFix" technique tricks the user into pasting and running a malicious command in their own system via the Run dialog (Win+R).
Defense Evasion: The malware runs instructions streamed from a command-and-control server instead of storing them locally, making it harder for antivirus tools to detect.
Campaign Analysis
This campaign leverages a popular brand and a deceptive social engineering trick to have users bypass their own security. The remote access backdoor allows attackers to steal credentials, capture keystrokes, and potentially move to other machines on the network.
Targeting & Infrastructure
Target Profile: Users interested in cryptocurrency airdrops and customers of the popular shopping platform Temu.
Actionable Intelligence
Domains: temucoin[.]lat
Relevant Terms
Remote Access Backdoor: Malware that gives an attacker hidden, remote control over a victim's computer, allowing them to steal data, install other software, or monitor activity.
ClickFix: A social engineering technique that tricks a user into executing malicious code by convincing them they are applying a necessary fix or passing a security check, often by copying and pasting commands.
Threat actor Storm-2561 is distributing trojanized enterprise VPN clients to steal corporate credentials. The campaign impersonates popular brands like Ivanti, Cisco, and Fortinet, using SEO poisoning to lure unsuspecting users into downloading the malware.
Key TTPs
Initial Access: Uses SEO poisoning to rank malicious sites in search results for enterprise VPN software queries.
Execution: A user downloads a ZIP file containing a trojanized MSI installer that side-loads malicious DLLs.
Defense Evasion: The malicious installer is digitally signed with a legitimate (now revoked) certificate to appear trustworthy.
Campaign Analysis
This financially motivated campaign highlights a trend of exploiting user trust in search engines and legitimate software brands. After stealing credentials, the malware displays a fake error and directs the user to the real vendor site to reduce suspicion.
Targeting & Infrastructure
Target Profile: Enterprise users searching for corporate VPN clients from vendors like Fortinet, Cisco, Ivanti, and Sophos.
Infrastructure: Malicious ZIP files were hosted on GitHub and distributed via a network of spoofed vendor websites.
Actionable Intelligence
IPs:194.76.226.93:8080
Domains:vpn-fortinet.com, ivanti-vpn.org
Relevant Terms
SEO Poisoning: A technique where attackers create malicious websites and use search engine optimization (SEO) tactics to make them appear high up in search results for specific terms.
DLL Side-Loading: An attack where a legitimate application is tricked into loading a malicious Dynamic-Link Library (DLL) file, allowing the attacker's code to be executed.
A new Google report reveals a major shift in cloud attack vectors, with third-party software exploits now being the primary method for initial access, surpassing weak credentials for the first time.
Key Findings
Software vulnerability exploits are the top initial access vector, accounting for 44.5% of intrusions.
Compromised credentials have dropped to the second position, responsible for 27.2% of breaches.
Misconfigurations now account for 21% of initial access incidents.
The time between vulnerability disclosure and active exploitation has shrunk from weeks to just days.
The Bottom Line
This trend indicates that enhanced identity security is successfully raising the barrier to entry for attackers. For technical leaders, this signals a critical need to pivot resources toward more aggressive and rapid patch management cycles and robust vulnerability detection programs, as the window to prevent exploitation is now dramatically smaller.
Relevant Terms
Initial Access Vector: The specific method or pathway an attacker uses to gain an initial foothold within a network or system.
Patching Cycle: The recurring process by which organizations identify, acquire, test, and apply software updates (patches) to systems to correct security vulnerabilities and other bugs.