ITSECURITY.GURU

Daily Briefing

Today's outlook

Google names fixed Chrome releases for six critical flaws as CISA flags active exploitation in Linux and Zyxel gear

Good morning. Google's Chrome stable channel advisories list six vulnerabilities, each carrying a CVSS 3.1 base score of 9.6 (vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). CVE-2026-93374, CVE-2026-93373 and CVE-2026-93372 affect Chrome up to the fix in 153.0.8010.52 (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html). CVE-2026-91738, CVE-2026-91729 and CVE-2026-91728 affect Chrome up to the fix in 153.0.8010.47 (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html). Google names those fixed releases; update Chrome across your estate to at least 153.0.8010.52 and restart the browser to apply it.

BleepingComputer reported that CISA is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. Separately, CISA's own catalog update added one vulnerability based on evidence of active exploitation: a stack-based buffer overflow in Zyxel GS1900 Series switches. CISA states this type of vulnerability is a frequent attack vector for malicious cyber actors, and its Binding Operational Directive 26-04 sets remediation priorities for federal agencies. If you run Zyxel GS1900 switches or Linux hosts, prioritise the vendor updates for these and check exposure.

The Hacker News reported that a fake LastPass Authenticator installer offered on GitHub installs a Microsoft-signed Windows kernel driver that shuts off antivirus and other security software before a password stealer runs; researchers at LastPass and Delphos Labs said on September 17. Treat unofficial LastPass Authenticator downloads as hostile and hunt for unexpected kernel driver installs.

Read the full briefing →

Vulnerability in focus

CVE-2026-93374 — Google. CVSS 9.6

Affected: chrome.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

What we're tracking

  • The Register: Anthropic-linked CVEs pile up, attackers mostly shrug Read it
  • BleepingComputer: BigCommerce alerts merchants of data breach linked to Ribon apps Read it
  • The Record: EU data regulator fines Google more than $460 million for location data violations Read it
  • The Hacker News: Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them and link back to them.

All editions from ITsecurityNews