Expand your library with these cybersecurity books
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87491 | Actively Exploited Out-of-Bounds Write in Google Chrome V8 CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown. Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching. | 8.8 | <1% | KEV |
| massbillions of installations (Chrome's install base exceeds 3 billion users) |
Full article292 words · extracted from helpnetsecurity.com · click to collapse
Please turn on your JavaScript for this page to function normally.
April 15, 2024
In this Help Net Security video round-up, authors discuss their cybersecurity books and provide an inside look at each title.
Complete videos
- George Finney, CSO at Southern Methodist University, talks about his book – “Project Zero Trust: A Story about a Strategy for Aligning Security and the Business“.
- Eric Leblond, CTO at Stamus Networks, talks about The Security Analyst’s Guide to Suricata, a book he co-wrote with Peter Manev.
- Adam Shostack, the author of “Threat Modeling: Designing for Security”, and the co-author of “The New School of Information Security”, talks about his book – “Threats: What Every Engineer Should Learn From Star Wars”.
- Mikko Hypponen, Chief Research Officer at WithSecure, talks about his book – If It’s Smart, It’s Vulnerable, which explores the transformative potential of the future of the internet, as well as those things that threaten its continued existence: government surveillance, censorship, organized crime, and more.
- Cybersecurity entrepreneur, founder, innovator, and investor William Lin discusses his book – The VC Field Guide.
- Rick Howard, CSO of N2K, Chief Analyst, and Senior Fellow at the Cyberwire, discusses his book – Cybersecurity First Principles: A Reboot of Strategy and Tactics.
- Thomas Roccia, Senior Security Researcher, discusses his book – Visual Threat Intelligence.
Read more: 10 must-read cybersecurity books for 2024
Don't miss
- Product showcase: GitGuardian Honeytoken catches credential theft as it happens
- September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
- Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
- AI-Infra-Guard: Open-source security scanner for AI systems
- Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/04/15/cybersecurity-books-video/