Threat Brief — 2026-09-25 — Chrome criticals, vintage TACACS+ root, forensics supply chain
Executive summary: Google shipped a major Chrome update closing 108 vulnerabilities including 11 rated critical. A decades-old flaw in TACACS+ server software was disclosed that can grant root on central AAA infrastructure. Researchers demonstrated 11 zero-click vulnerabilities across Google and Apple flagship devices. Separately, the CEO of Oxygen Forensics—a supplier of forensic software used by US agencies including the Secret Service—was arrested, raising supply-chain trust questions for law enforcement tooling.
Top items
- Google Chrome patches 108 vulnerabilities, 11 critical. A major browser update shipped today closing 108 flaws, 11 of them rated critical. No specific CVEs or exploit details were provided in the source beyond the aggregate counts. Browser updates at this scale warrant immediate deployment given Chrome's attack surface and the frequency of in-the-wild exploitation of V8 and renderer bugs. (src: SecurityLab)
- 1990s-era TACACS+ server bug enables root on central AAA systems. A vulnerability surviving from the 1990s was disclosed that allows an attacker to gain root on a TACACS+ server. Compromise of a central AAA system exposes network equipment management access and administrator credentials, making this a high-impact target for environments relying on TACACS+ for network authentication. (src: SecurityLab)
- 11 zero-click vulnerabilities found across Google and Apple flagship devices. Positive Technologies researchers disclosed 11 hidden vulnerabilities that required no user interaction or permissions to exploit on Google and Apple devices. The findings undermine assumptions about flagship device security and suggest a broad attack surface across mobile platforms. No CVE identifiers or patch status were provided in the source. (src: SecurityLab)
- Oxygen Forensics CEO arrested — Russian-controlled software reached US Secret Service. The CEO of Oxygen Forencics, a supplier of digital forensic software used by US agencies including the Secret Service, was arrested. American agencies reportedly did not know for years who actually controlled the vendor. This raises significant supply-chain and operational-security concerns for any organisation using the tooling for sensitive investigations. (src: SecurityLab)
- LLM watermarks may increase susceptibility to prompt injection. A Lasso Security researcher found that SynthID-Text watermarks can alter LLM sampling behaviour, in some cases causing models to comply with malicious prompt-injection instructions they would otherwise reject. This is relevant for organisations deploying watermarked models in agentic or automated workflows where prompt-injection resistance is critical. (src: Xakep)
- Rydox marketplace admin pleads guilty, faces up to 22 years. A Kosovar national pleaded guilty to operating Rydox, a criminal marketplace that sold stolen PII, credentials, credit card data, and cybercrime tools. The takedown removes a persistent enabler of credential and financial-data trafficking. (src: BleepingComputer)
Themes
AI security trade-offs are multiplying. The LLM watermarking research (id 14650) is the latest signal that AI safety controls can introduce new attack surfaces — watermark-induced sampling drift making models more compliant with injected instructions. This aligns with the broader pattern this week of AI agents being weaponised, bypassed, or inadvertently widening attack surfaces.
Long-lived vulnerabilities keep surfacing. The TACACS+ flaw persisting since the 1990s (id 14653) echoes the recurring theme of legacy protocol and infrastructure code accumulating critical bugs that go undetected for decades, particularly in network authentication and management systems.
