A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
In brief

CISA Adds CVE-2026-85046 to KEV as Chrome V8 Zero-Day Exploitation Is Confirmed

CISA’s addition of CVE-2026-85046 to the Known Exploited Vulnerabilities Catalog on September 4, 2026 materially changes how organiza…

Sep 05, 2026

CVE-2026-85046: Google Patches Sixth Chrome Zero-Day Exploited in Attacks This Year

Google has released an emergency Chrome security update addressing CVE-2026-85046, a high-severity type-confusion vulnerability in the V8 J…

Sep 04, 2026

CVE-2026-19490: Citrix NetScaler Authentication Bypass Moves From PoC to Real-World Exploitation Attempts

The targeting of CVE-2026-19490 against Citrix NetScaler ADC and NetScaler Gateway appliances is particularly concerning because the vulner…

Sep 04, 2026

IDScan.net Breach Allegations Expose the Hidden Risk of Centralized Identity Verification

Reports linking IDScan.net to a dark-web marketplace offering access to more than 153 million U.S. and Canadian driver’s-license reco…

Sep 04, 2026

CVE-2026-75925: Critical IXON VPN Client Flaw Enables Root or SYSTEM Command Execution

CISA’s ICSA-26-246-02 advisory covers a critical vulnerability in the IXON VPN Client that could allow an attacker to execute command…

Sep 04, 2026

Attackers Turn Trusted Node.js Into a Malware Runtime, Showing Why Signed Software Alone Cannot Be Trusted

The growing abuse of Node.js in targeted attacks is another example of how threat actors increasingly prefer to operate through trusted sof…

Sep 04, 2026

CVE-2026-78012: Critical NetStaX EtherNet/IP Flaw Exposes Industrial Devices to Memory Corruption and Remote Attack

CISA’s ICSA-26-246-07 advisory highlights a critical vulnerability in Pyramid Solutions’ NetStaX EtherNet/IP Stack that deserve…

Sep 04, 2026

Thomson Reuters C-Track Breach Exposes the Hidden Risk in Centralized Court Technology

The disclosure that an unauthorized party obtained files from Thomson Reuters’ C-Track court case-management environment highlights t…

Sep 04, 2026

BraZetsu Turns Compromised Windows Systems Into Inventory for the Cybercrime Access Economy

The discovery of BraZetsu, a Python-based Windows malware framework linked by Group-IB to an operation tracked as Exilware, highlights an i…

Sep 04, 2026

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco has disclosed a critical vulnerability in certain Silicon One-based Nexus 9000 Series switches that could allow an unauthenticated re…

Sep 04, 2026

Coder Registry Compromise Turns Trusted Terraform Modules Into Credential-Stealing Supply-Chain Payloads

The compromise of Coder’s registry infrastructure is a strong reminder that software supply-chain attacks do not always require compr…

Sep 04, 2026