All newsletters
2026-06-16
3 min read
SecurityBrowserDevOpsDatabasesOpen SourceDev Tools

Chrome V8 Zero-Day Exploited & Microsoft Patches 206 Flaws & AWS WAF AI Traffic Monetization & ClickHouse 10-Year Milestone

Google patches actively exploited Chrome zero-day CVE-2026-11645, Microsoft addresses record 206 vulnerabilities including three zero-days, AWS adds AI traffic monetization to WAF, and ClickHouse celebrates 10 years as leading open-source analytics database.

Security


  • Google Chrome V8 Zero-Day CVE-2026-11645 — Out-of-bounds memory access in Chrome's JavaScript/WebAssembly engine is actively exploited in the wild (CVSS 8.8). Patch immediately in Chrome 150+. This is the fifth actively exploited Chrome zero-day since the year started. Read more
  • Microsoft Patches Record 206 Flaws — Including three zero-days and critical RCE bugs. The batch addresses vulnerabilities across Windows, Defender, and other products. Critical fixes include CVE-2026-28252 through CVE-2026-28256 for Trane Tracer SC+ HVAC systems and multiple SAP NetWeaver flaws. Read more
  • Microsoft 365 Copilot SearchLeak — Vulnerability chain (CVE-2026-42824, critical) turned Copilot into a 1-click data theft tool via specially crafted URLs. Attackers could exfiltrate emails, passwords, calendar events, and documents from mailbox/OneDrive/SharePoint. Microsoft has already patched this—no user action required. Read more
  • ShinyHunters Exploits Oracle PeopleSoft Zero-Day — CVE-2026-35273 (CVSS 9.8, missing authentication) allowed unauthenticated PeopleSoft Enterprise takeover. Active exploitation observed May 27–June 9, 2026 with lateral movement and data exfiltration. CISA added it to Known Exploited Vulnerabilities list. Read more

Browser & Web Platform


  • Safari 27 Brings Customizable Select Elements — Developers can now fully control the appearance of