A Chrome Zero-Day and 440,000 Exploit Attempts (09/04/2026)
Google patched an actively exploited V8 flaw, Wordfence counted 440,000 attempts against two WordPress plugins, and Cisco bundled so many IOS XR bugs it shipped a release for them.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
Google patched an actively exploited V8 flaw, Wordfence counted 440,000 attempts against two WordPress plugins, and Cisco bundled so many IOS XR bugs it shipped a release for them.
A judge approved $147 million in fees from Google's $425 million tracking verdict while class members get $5, and attackers watched an ID verification feed for a year.
The SEC proposed rescinding its pay-to-play rule for investment advisers, the G7 told organizations to start the post-quantum migration now, and another vendor breach hit four practices.
Cisco patched an unauthenticated root execution flaw in Nexus 9000 switches, the Shai-Hulud worm now scans 469 credential locations, and Coder's registry served malicious Terraform modules.
Five federal agencies clarified SAR confidentiality for customer communications, the NBA found the Clippers arranged sham endorsements, and MCNA settled its 2023 breach litigation.
A Flock webinar walked police through surveilling protests and parades, 170 million ID scans surfaced on a Russian forum, and Pegasus reached a Serbian student activist's iPhone.
A search site claimed more than 150 million license photos taken from an ID verification service, Texas police used AI to write up a Flock search, and Austria cleared a credit data class action.
Two SonicWall SMA 1000 zero-days are chained in live attacks, a BGP hijack poisoned a Virtualizor update, and a repo's own Git config can make AI coding agents run attacker code.
Texas declared price optimization unfairly discriminatory, Colorado proposed AI Act rules that reach deployers, and two more healthcare vendors put patient records in breach notices.
Two healthcare settlements land the same day, counsel question whether a forensic audit is a real thing, and CIPA gets rewritten by SB 690.
Lawmakers gutted private enforcement under a key state privacy law, the FTC and states sued Amazon over a secret ad surcharge, and Austria cleared a class action.
A 9.8 in JFrog Artifactory lets an unauthenticated attacker mint admin tokens, and exploitation began four days after the fix shipped.
Critical security news, threat briefs, and company updates from The Axe Report, delivered straight to your inbox. No spam, unsubscribe anytime.
Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.