Google patches new Chrome zero-day flaw exploited in the wild

2026-06-09T07:23:36Z2aa27d41c00e2cfc24312710e0b5b21bd46a3d83e4d01251eb3efe1a6da71642
android-malwarebotnetc0xmocheck-point-vpnchromedata-breachdd-wrtgithubgogsinstagram-account-takeovermetanfcsharensophishingprivilege-escalationpypiqilin-ransomwareransomware-targeting-law-firmsremote-code-executionshai-huludsupply-chainthird-party-breachunifi-oswhatsappzero-day

What happened

Multiple high-impact security incidents reported: Google and other vendors released emergency patches for several zero-day vulnerabilities (including a Chrome zero-day and a critical Gogs RCE), and a chained UniFi OS bug enables unauthenticated root RCE. Supply-chain and malware activity includes 19 PyPI packages trojanized by the Shai‑Hulud campaign, NFCShare Android malware pushed as fake banking app updates on GitHub, and a new C0XMO botnet exploiting DD‑WRT router flaws. Several data breaches and account-takeover incidents were disclosed (SoFi Hong Kong third‑party breach, Oxford CareerCon

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
2aa27d41c00e2cfc24312710e0b5b21bd46a3d83e4d01251eb3efe1a6da71642
Enrichment time
2026-06-09T07:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.