View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Multiple Google Chrome vulnerabilities could allow arbitrary code

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Multiple Google Chrome vulnerabilities could allow arbitrary code execution
    Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow arbitrary code execution.

    • Affects users of the Google Chrome web browser.
    • Multiple vulnerabilities were discovered in Chrome; the most severe could allow arbitrary code execution.
    • Successful exploitation could let attackers install programs; view, change, or delete data; or create new accounts with full user rights.
    • Impact depends on the privileges of the logged-on user; accounts with fewer rights are less affected than those with administrative rights.
      πŸ“Ž Coverage: cisecurity.org Β· πŸ‘ via CIS Advisories
  • Dropbox: ~5,000 accounts compromised via Lenovo ID sign-in flaw in August
    Dropbox disclosed that attackers compromised about 5,000 user accounts in August by abusing its Lenovo ID sign-in integration.

    • Dropbox users who sign in via the Lenovo ID third-party identity integration were affected.
    • Approximately 5,000 accounts were compromised in August; Dropbox notified affected users.
    • Attackers exploited weak account-level verification when Dropbox trusted the third-party identity provider to grant access.
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Ransomware protection for MSPs: A 6-point checklist for faster recovery β€” BleepingComputer

  • UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure β€” SecurityWeek

  • A16z Says You Actually Love Social Media, Enshittification Isn’t Real β€” 404 Media

  • Texas Police Used AI to Write Report About Using Flock to Search for Woman Who Had Abortion β€” 404 Media

  • The Republican Nominee for New York Governor Made a Creepy, AI-Generated Video of Mamdani and Hochul β€” 404 Media

  • Cops Are Asking Axon to Make Their Cameras Look Different From Flock So People Don't Destroy Them β€” 404 Media

  • Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code β€” The Hacker News

  • Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages β€” The Hacker News

  • CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks β€” CrowdStrike Blog

  • CrowdStrike Delivers the Next Evolution of the Agentic SOC β€” CrowdStrike Blog

  • CrowdStrike Announces Agentic Identity Provider β€” CrowdStrike Blog

  • Pegasus, NoviSpy variant spyware found on devices of Serbian activists β€” CyberScoop

  • Wyden seeks upgraded NSA security guidance on commercial VPN use β€” CyberScoop

  • Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided val... β€” CVE ThreatInt

  • Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens u... β€” CVE ThreatInt

  • OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlie... β€” CVE ThreatInt

  • Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and ea... β€” CVE ThreatInt

  • Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows ov... β€” CVE ThreatInt

  • Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 an... β€” CVE ThreatInt

  • NGINX ngx_http_js_module vulnerabilityA vulnerability exists in NGINX JavaScr... β€” CVE ThreatInt

  • Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing ... β€” CVE ThreatInt

  • NGINX ngx_http_js_module vulnerablilityDescription NGINX JavaScript (njs) has... β€” CVE ThreatInt

  • NGINX Ingress Controller vulnerabilityWhen NGINX Ingress Controller is config... β€” CVE ThreatInt

  • Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict... β€” CVE ThreatInt

  • NGF vulnerabilityDescription: When NGINX Plus is configured as the data plane... β€” CVE ThreatInt

  • NGINX ngx_http_js_module vulnerabilityDescription NGINX JavaScript (njs) and ... β€” CVE ThreatInt

  • A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier al... β€” CVE ThreatInt

  • BIG-IP and BIG-IQ Configuration utility vulnerabilityBIG-IP has a vulnerabili... β€” CVE ThreatInt

  • BIG-IP Configuration utility vulnerabilityA vulnerability exists in an undisc... β€” CVE ThreatInt

  • Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the ... β€” CVE ThreatInt

  • Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's b... β€” CVE ThreatInt

  • Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier all... β€” CVE ThreatInt

  • Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL scheme... β€” CVE ThreatInt

  • Your DNS Is Hiding in HTTPS β€” This Is Why It Matters β€” Akamai Blog

  • GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok β€” Cyber Security News

  • Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse β€” Cyber Security News

  • Russian Hacker Indicted for Using Excel Malware to Target 80,000 Freelancers With TVRAT and DarkVNC β€” Cyber Security News

  • Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools β€” Cyber Security News

  • OWASP Top 10 CI/CD Security Risks Explained: Why Credential Hygiene Decides the Outcome β€” securityboulevard.com (discovered)

  • Palo Alto Acquires Console to Expand Cortex Agentic Security β€” securityboulevard.com (discovered)

  • What a 14-Day Federal Patch Clock Costs a Team That Isn’t a Federal Agency β€” securityboulevard.com (discovered)

  • Capsule Security Partners with NVIDIA to Secure AI Agents β€” <https://securityboulevard.com/2026/09/capsule-security-partners-with-nvidia-to-secure-ai-agents/|securityboulevard

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check