Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerability discovery and exploit generation.
The activity is said to be the work of cybercrime threat actors who appear to
Education technology giant Instructure has confirmed that a security vulnerability allowed hackers to modify Canvas login portals and leave an extortion message. [...]
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. Impacted is the function x86_pmu_enable of the component PMU NMI Handler. Performing a manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2026-23435. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 7.0-rc4 and classified as critical. Affected by this vulnerability is the function nand_lock of the component mtd. Performing a manipulation results in deserialization.
This vulnerability was named CVE-2026-23434. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
A vulnerability classified as critical was found in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. This affects the function aml_spisg_probe of the component amlogic-spisg. The manipulation results in memory leak.
This vulnerability is known as CVE-2026-23431. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.19.9/7.0-rc4. This impacts the function mshv_map_user_memory of the component mshv. This manipulation causes use after free.
This vulnerability is handled as CVE-2026-23432. The attack can only be done within the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.19.9/7.0-rc4. It has been classified as critical. This affects the function mpam_restore_mbwu_state of the component arm_mpam. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-23433. The attack can only be performed from a local environment. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability described as critical has been identified in Linux Kernel up to 7.0-rc4. The affected element is the function smb2_get_ksmbd_tcon of the component ksmbd. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-23428. The physical device can be targeted for the attack. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. The impacted element is an unknown function of the component vmwgfx. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2026-23430. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.