Here are some of the top Cybersecurity news articles for the past week:
π Google released Chrome version 152 updates to address 12 security vulnerabilities, including CVE-2026-85046, an actively exploited high-severity type confusion zero-day flaw in the V8 JavaScript engine.
https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/
π¨ Cybersecurity researchers disclosed “PostGREShell” (CVE-2026-6471), a 12-year-old vulnerability in PostgreSQL’s logical decoding that allows attackers with low-level replication credentials to achieve remote code execution and gain permanent superuser privileges.
https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/
β οΈ CERT Polska warned of active exploitation against internet-exposed SSH services on MikroTik devices running RouterOS via a two-vulnerability chain dubbed “MikroTrick,” granting remote attackers full administrative control without authentication.
https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
π Attackers are actively exploiting an unpatched zero-day vulnerability named “StyleSmuggler” across Magento and Adobe Commerce platforms to inject PHP code via the template system and deploy persistent Linux backdoors.
π₯ Online education platform Mathspace disclosed a data breach impacting over 1.07 million students, staff, and parents after attackers exploited a vulnerability in its self-hosted Metabase reporting system to download internal database records.



