2026-04-29
2026-04-29 12:16Z
CRIT

CVE-2026-42248 — Ollama Ollama: for Windows does not perform integrity or authenticity verification of downloaded update executables.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42248

Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust validation is performed before staging or executing update payloads, enabling attacker‑supplied executables to be accepted and later executed by the application. Critically, Ollama for Windows performs silent automatic CVSSv3.1 9.8 (CRITICAL) · EPSS 1th percentile

CWECWE 494VNDOllamaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-29
2026-04-29 11:00Z
INFO

Extending Ruzzy with LibAFL

Trail of Bits·blog.trailofbits.com

Trail of Bits documents the integration of LibAFL fuzzing engine into Ruzzy, their coverage-guided fuzzer for Ruby code and C extensions. The post details technical challenges encountered during integration, including ELF binary constraints around .preinit_array sections in shared objects and SanitizerCoverage initialization timing differences between LibAFL and libFuzzer, with solutions provided via linker selection and initialization ordering patches.

SRFApplicationSWLibaflSWLibfuzzerSWRuzzyTYPResearchSTGDiscoveryTECT1592
68
Edit Score
2026-04-29
2026-04-29 00:00Z
CRIT

CI/CD pipeline abuse: the problem no one is watching

Elastic Security Labs·elastic.coCVE-2025-30066in the wild

Elastic Security Labs released cicd-abuse-detector, an open-source detection tool that uses regex signal extraction and LLM analysis to catch CI/CD pipeline abuse across GitHub Actions, GitLab CI, and Azure DevOps. The tool detects six attack categories: credential harvesting, privileged trigger exploitation, permission escalation, runner targeting, supply chain manipulation, and defense evasion. Detection patterns were validated against real-world incidents (GhostAction, Shai-Hulud, HackerBot-Claw, ArtiPACKED, Contagious Interview) and offensive toolkits (Nord Stream, Gato-X).

TACTA0005TACTA0001TACTA0002TACTA0006TACTA0008SRFSupply ChainSWAzure DevopsSWGithub Actions
92
Edit Score
2026-04-29
2026-04-29 00:00Z
HIGH

Kuse Web App Abused to Host Phishing Document

Trend Micro Research·trendmicro.comin the wild

Trend Micro documented a phishing campaign exploiting Kuse.ai, a legitimate AI workplace platform, to host credential-harvesting attacks. Attackers abused Kuse's document-sharing feature to generate URLs under the trusted app.kuse.ai domain, combined with vendor email compromise (VEC) to deliver phishing links that redirected users to fake Microsoft login pages. The attack leveraged Markdown (.md) file extensions and blurred document previews to evade email filters and social-engineer victims into credential disclosure.

TACTA0001TACTA0006SRFWebSRFCloudSRFAiTYPThreat IntelSTGInitial AccessSTGCred Access
68
Edit Score
2026-04-29
2026-04-29 00:00Z
CRIT

'Mini Shai-Hulud' supply chain attack targets SAP npm packages

Sophos X-Ops·news.sophos.comin the wild

Sophos researchers disclosed 'Mini Shai-Hulud', a supply chain attack targeting SAP's Cloud Application Programming Model (CAP) npm packages. Compromised packages contained credential-stealing malware that exfiltrated sensitive data via GitHub repositories; maintainers have released patched versions.

TACTA0001SRFSupply ChainVNDSapTYPVulnerabilityTYPThreat IntelSTGInitial AccessEXPSupply ChainSTAitw exploited
78
Edit Score
2026-04-29
2026-04-29 00:00Z
CRIT

CI/CD pipeline abuse: the problem no one is watching

Elastic Security Labs·elastic.coCVE-2025-30066in the wild

Elastic Security Labs released cicd-abuse-detector, an open-source detection tool that uses regex signal extraction and LLM analysis to identify malicious CI/CD pipeline modifications across GitHub Actions, GitLab CI, and Azure DevOps. The tool addresses a critical attack surface where compromised developer credentials enable secret harvesting, supply-chain poisoning, and lateral movement to cloud infrastructure, validated against real-world incidents including GhostAction, Shai-Hulud, HackerBot-Claw, and ArtiPACKED.

TACTA0005TACTA0001TACTA0002TACTA0006TACTA0008SRFSupply ChainSWAzure DevopsSWGithub Actions
87
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7363 — Use: after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7363

Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7361 — Use: after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7361

Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7359 — Use: after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7359

Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7358 — Use: after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7358

Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7357 — Use: after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7357

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7356 — Use: after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7356

Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7355 — Use: after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7355

Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7354 — Out: of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7354

Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7353 — Heap: buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7353

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7352 — Use: after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7352

Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7350 — Use: after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7350

Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7348 — Use: after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7348

Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7347 — Use: after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7347

Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7346 — Inappropriate: implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7346

Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 119VNDInappropriateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7345 — Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7345

Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7344 — Use: after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7344

Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
CRIT

CVE-2026-7343 — Use: after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7343

Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH

CVE-2026-7342 — Use: after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7342

Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
CRIT

CVE-2026-7341 — Use: after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7341

Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score