A researcher demonstrates that zero-day vulnerability discovery is not exclusive to frontier AI models like Anthropic's Mythos, but can be achieved through orchestration frameworks like IronCurtain using commercial models (Opus, Sonnet) and open-weight models (GLM 5.1). The author replicated Anthropic's discovery of a 27-year-old OpenBSD TCP SACK vulnerability and autonomously found new zero-days, though at significant token costs ($30–$150 per investigation).
Microsoft's August 2026 Patch Tuesday delivers nearly 1,000 security fixes, including two actively exploited zero-day privilege escalation vulnerabilities and a critical remote code execution bug in Windows DNS. LG smart TVs extensively collect user data for ad targeting, tracking viewing habits, device fingerprints, and network information even when disabled, while containing numerous security vulnerabilities that could expose home networks.
Microsoft released 974 security patches in September, its largest single batch ever, with 113 critical flaws including two actively exploited zero-days. AI-assisted vulnerability discovery is accelerating patch volumes across major software vendors, but security experts warn organizations struggle to test and deploy fixes at this scale.
Four espionage-linked threat groups deployed an undisclosed exploit kit called BlueMoon within a week, chaining vulnerabilities in Windows and Chrome to achieve code execution and privilege escalation. APT31 first used BlueMoon on August 28, 2026, targeting NGOs and trading firms via phishing, with other China-aligned actors following days later. The kit exploits patched Chromium flaws and a Windows buffer overflow to inject malware and steal credentials.
Google patched 230 security vulnerabilities in Chrome, including CVE-2026-87491, an out-of-bounds write in V8 that enables arbitrary code execution within the sandbox and has been actively exploited in the wild. Researcher Jihyeon Jeong discovered the flaw and received a $2,500 bug bounty; Google has not disclosed attack details but confirmed exploits exist in the wild.
Microsoft released a record 974 security patches addressing vulnerabilities across Windows, Office, SQL, and Developer Tools, including two actively exploited zero-day flaws in Windows. The update brings the total resolved vulnerabilities to 999 when including non-Microsoft CVEs, with over 110 assigned critical severity ratings.
Google patched 230 vulnerabilities including CVE-2026-87491, a seventh actively exploited Chrome zero-day in 2025. The high-severity flaw in the V8 engine allows remote attackers to execute arbitrary code via crafted HTML. Updates are rolling out across Windows, Mac, and Linux.
Google patched 230 vulnerabilities including CVE-2026-87491, a seventh actively exploited Chrome zero-day this year stemming from an out-of-bounds write in the V8 engine. The high-severity flaw allows remote attackers to execute arbitrary code via crafted HTML pages. Updates rolled out to Windows, Mac, and Linux systems and should reach most users within days or weeks.
Microsoft released 974 CVE patches in its latest Patch Tuesday, setting a new record. The deluge of security updates highlights ongoing vulnerabilities across Microsoft's product portfolio, including critical issues in on-premises SharePoint under active zero-day attack.