Google accidentally exposed details of unfixed Chromium flaw
2026-05-21T19:23:30Z•f54ad02a0647030bc2d2c65647ccff43d652eb0c192d7e27f4be245f091b3b3d
chromiumcisco secure workloadcrypto-drainerdrupalfirst-vpngithubgrafanainfostealerjfmbackdoormfa-bypassmicrosoft defendernx-consolepin theftremote code executionshowboatsonicwallsupply-chaintanstackvpn-seizurezero-day
What happened
Multiple high-impact security stories: Google accidentally leaked details of an unfixed Chromium flaw that can keep JavaScript running after the browser is closed and enable remote code execution; Microsoft disclosed two Defender zero-days being actively exploited; Cisco published a maximum-severity Secure Workload vulnerability that grants Site Admin privileges. Also reported: a TanStack/npm supply-chain compromise that led to GitHub and Grafana incidents (missed token rotation), SonicWall Gen6 VPN MFA bypasses due to incomplete patching, new Chinese espionage malware targeting telcos (Showbo
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- f54ad02a0647030bc2d2c65647ccff43d652eb0c192d7e27f4be245f091b3b3d
- Enrichment time
- 2026-05-21T19:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.