This day 02:08 06:08 10:08 14:09 18:10 22:00
Info  2026-10-03 10:08Z · last 4h · 13 findings · glm-5.2:cloud

Threat Brief — 2026-10-03: Chromium ANGLE flaw, MI5 academic exposure

Executive summary: A heap buffer overflow in Chromium's ANGLE graphics layer (CVE-2025-10502) has been disclosed via Microsoft's security update portal, warranting attention for browser-dependent environments. Separately, MI5 has revealed that British university professors unknowingly developed software for Chinese state security over several years, covering AI, cybersecurity, and covert communications — a first-time disclosure that underscores supply-chain and academic targeting risks.

Top items

Themes

Academic and research-sector targeting. The MI5 disclosure highlights a persistent pattern of state actors using front organisations to channel sensitive research through unwitting academics. This reinforces the need for due diligence on research collaborations and funding provenance, particularly in dual-use fields such as AI and communications security.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db