The Canadian Centre for Cyber Security published three security advisories on 2026-07-17 covering critical vulnerabilities in FreePBX (unauthenticated RCE and SQL injection), VMware Avi Load Balancer (seven CVEs under VMSA-2026-0005), and Google Chrome for Desktop. All advisories urge immediate patching to the latest versions.
Google Chrome
16 posts
Cyber Centre Daily Advisory Digest — 2026-07-17 (3 advisories) Cyber Centre Daily Advisory Digest — 2026-07-09 (3 advisories) The Canadian Centre for Cyber Security published three security advisories on 2026-07-09 covering Google Chrome, FreePBX, and Django vulnerabilities. The most critical item is CVE-2026-1207 affecting Django, which is reportedly being actively exploited. FreePBX 17 modules contain command injection and SSH key injection flaws. Google Chrome desktop versions prior to 150.0.7871.114/115 also require patching.
Q2 2026 Vulnerability Trends Report AhnLab's Q2 2026 vulnerability trends report identifies 20,701 new CVEs, with Critical-severity vulnerabilities rising 62.5% from Q1 to 2,317. CISA's KEV catalog added 75 new entries, 87% of which were Critical or High severity. Attackers concentrated on externally exposed infrastructure (firewalls, VPNs, management panels) and supply chain compromises. The report highlights ten major CVEs across Ivanti, Fortinet, Palo Alto, Splunk, Google Chrome, Microsoft Exchange, cPanel, Ubiquiti, and DAEMON Tools, with RCE and privilege escalation being the dominant impact categories.
ToddyCat: your hidden email assistant. Part 2 ToddyCat APT developed a tool called Umbrij that automates the theft of Google OAuth authorization codes by launching Chromium-based browsers in headless mode with remote debugging ports enabled. The tool copies the victim's browser profile to a backup directory, launches the browser invisibly with the stolen session, and uses Puppeteer Sharp to automate the Google OAuth consent flow using legitimate Google Workspace Migration/Sync client IDs. The resulting authorization code is exfiltrated and exchanged for an access token, enabling API-level access to the victim's Gmail, Drive, Calendar, and Contacts without traditional credential theft.
Cyber Centre Daily Advisory Digest — 2026-06-26 (1 advisories) The Canadian Centre for Cyber Security issued advisory AV26-634 referencing a Google Chrome security advisory published on June 25, 2026. The advisory addresses vulnerabilities in Chrome for Desktop Stable Channel on Windows, Mac, and Linux. No specific CVE IDs, exploit details, or threat actor attribution were included in the digest; the primary action is to apply Chrome updates when available.
Cyber Centre Daily Advisory Digest — 2026-06-09 (2 advisories) The Canadian Centre for Cyber Security issued advisories for actively exploited vulnerabilities in Check Point VPN/Firewall products (CVE-2026-50751, an authentication bypass) and Google Chrome (CVE-2026-11645). Both vulnerabilities have known exploits in the wild, with the Check Point flaw added to the CISA KEV database, necessitating immediate patching.
Cyber Centre Daily Advisory Digest — 2026-06-03 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting vulnerabilities in Google Chrome, ABB T-MAC Plus control systems, and Phoenix Contact CHARX SEC-3xxx charging controllers. Organizations are advised to apply the latest patches and firmware updates to mitigate potential exploitation, particularly concerning an unauthenticated log download vulnerability in Phoenix Contact devices.
Cyber Centre Daily Advisory Digest — 2026-05-20 (5 advisories) The Canadian Centre for Cyber Security released a daily digest of five security advisories on May 20, 2026. The advisories highlight critical and high-severity vulnerabilities across FreePBX, F5 NGINX, Google Chrome, HPE Aruba Networking products, and cPanel, urging administrators to apply vendor-supplied patches immediately to prevent potential exploitation.
Cyber Centre Daily Advisory Digest — 2026-05-06 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting three security advisories. The most critical is an actively exploited, unauthenticated buffer overflow vulnerability (CVE-2026-0300) affecting the Palo Alto Networks PAN-OS User-ID Authentication Portal. Additional routine security updates were announced for Google Chrome and VMware Tanzu GemFire Management Console.
Cyber Centre Daily Advisory Digest — 2026-04-29 (1 advisories) The Canadian Centre for Cyber Security issued an advisory highlighting unspecified vulnerabilities in Google Chrome for Desktop. Administrators are urged to update Windows, Mac, and Linux clients to the latest stable channel releases to mitigate potential exploitation.
Cyber Centre Daily Advisory Digest — 2026-04-23 (2 advisories) The Canadian Centre for Cyber Security published a daily digest highlighting recent security advisories for Google Chrome and GitHub Enterprise Server. Organizations are advised to patch these products to their latest versions to mitigate undisclosed vulnerabilities.
Cyber Centre Daily Advisory Digest — 2026-04-10 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding vulnerabilities in Google Chrome for Desktop. Organizations must update Chrome to version 147.0.7727.55/56 for Windows/Mac and 147.0.7727.55 for Linux to mitigate potential security risks.
Cyber Centre Daily Advisory Digest — 2026-04-01 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding a critical vulnerability in Google Chrome (CVE-2026-5281) that is currently being exploited in the wild. Organizations are urged to update Chrome for Desktop to the latest stable versions to mitigate this active threat.
Google Authenticator: The Hidden Mechanisms of Passwordless Authentication This architectural analysis details the hidden mechanisms behind Google's synced passkeys, revealing a hybrid model that leverages a cloud-based authenticator (enclave.ua5v[.]com) for sensitive cryptographic operations while anchoring trust to local hardware keys. Understanding this infrastructure is critical for defenders to anticipate emerging attack vectors in passwordless authentication environments.
Cyber Centre Daily Advisory Digest — 2026-03-24 (2 advisories) The Canadian Centre for Cyber Security issued a daily digest highlighting recent security updates for Google Chrome and Mozilla Firefox. Administrators are advised to update Chrome to version 146.0.7680.164/165 and Firefox to version 149 (or the respective ESR versions) to address unspecified vulnerabilities.
NICKEL ALLEY strategy: Fake it ‘til you make it North Korean threat group NICKEL ALLEY is targeting technology professionals and Web3 developers through fake job interviews and malicious code repositories. The group employs social engineering, the ClickFix tactic, and malicious VS Code tasks to deliver remote access trojans like PyLangGhost RAT and BeaverTail, primarily aiming for cryptocurrency theft and potential supply chain compromise.