Zyxel is the day's clearest thread: CISA has added the GS1900 switch flaw (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch, while SecurityWeek reports a Chinese actor already used the bug to pull data from nearly 1,000 switches, both filed alongside a second actively exploited Veeam flaw per The Hacker News. Alongside it, CISA is separately warning on three exploited Linux kernel flaws, and a fresh ARM64 KVM bug (CVE-2026-89775) gives guest VMs read-write access to host memory, so the pressure on infrastructure-layer patching is not limited to one vendor.
The npm supply chain gets another entry too: The Hacker News and SecurityWeek both track "indexed-btree," a package impersonating sorted-btree that has racked up millions of downloads while hiding its trigger in runtime code rather than install scripts, a shift the researchers flag as a response to existing lifecycle-script defenses. Regulatory news lands separately from all of it: Ireland's Data Protection Commission has fined Google 403 million euros, about 463 million dollars, over location data handling between 2018 and 2020, covered in near-identical detail by SecurityWeek, The Hacker News and BleepingComputer.
Generated from the headlines on this desk and
published under the newsroom's byline. Everything below it is other
publications' reporting, linked back to them.
How Wyre works.