Google accidentally exposed details of unfixed Chromium flaw
2026-05-22T07:23:26Z•fe8893b06fe912b36c231072674cc08bd3076facf63e84e08f7d635e5cabcca6
Arch LinuxChinese cyber-espionageChromiumCisco Secure WorkloadDrupalFirst VPNGoogleJFMBackdoorMFA bypassMicrosoft DefenderNx Console VS Code extensionPinTheftPoC releasedShowboatSonicWall Gen6 SSL‑VPNTanStackcritical updatelaw enforcement takedownlocal root escalationnpmprivilege escalationransomwareremote code executionsupply-chain attackzero-day
What happened
A collection of security news highlighting multiple high-impact incidents and active threats: Google accidentally disclosed details of an unfixed Chromium bug that could allow background JS and remote code execution; Microsoft disclosed two exploited Defender zero-days; Cisco fixed a maximum-severity Secure Workload vulnerability that grants Site Admin privileges; Drupal pushed a critical core update with rapid exploitation risk; an Arch Linux PinTheft local root escalation PoC was published; SonicWall Gen6 SSL‑VPN MFA was bypassed due to incomplete patching and used in ransomware operations;"
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- fe8893b06fe912b36c231072674cc08bd3076facf63e84e08f7d635e5cabcca6
- Enrichment time
- 2026-05-22T07:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.