VMTech
Discuss a project

Chrome Patches 370 Flaws as AI Agents and Credential Attacks Accelerate

Chrome Patches 370 Flaws as AI Agents and Credential Attacks Accelerate

Google released fixes for 370 Chrome vulnerabilities on July 29, 2026, including seven critical flaws tracked from CVE-2026-17650 through CVE-2026-17656. The same week brought AI-orchestrated exploitation, successful SonicWall credential stuffing, DNS hijacking and several campaigns abusing trusted access.

Attackers are compressing the response window

VulnCheck found that 23.43% of known exploited vulnerabilities showed signs of exploitation on or before their CVE publication date. The median interval between publication and inclusion in the known-exploited category fell from 120 days in 2025 to 80 days in the first half of 2026.

This pressure extends beyond software defects. ShinyHunters has been using voice phishing and helpdesk manipulation to reset MFA, take over SSO accounts and pivot into connected SaaS platforms. The incidents also show why borrowed trust as a recurring attack pattern matters when suppliers, administrators and familiar services become entry points.

Browsers, edge systems and AI agents converge

The Chrome fixes are available in versions 151.0.7922.71 and .72 for Windows and macOS, and 151.0.7922.71 for Linux. Google reported 349 of the 370 flaws internally and said none had been flagged as actively exploited. More than 1,800 Chrome vulnerabilities have been addressed since the start of 2026.

Separately, Huntress recorded unauthorized access to 92 SonicWall accounts across 30 organizations in a credential-stuffing campaign active since July 25. CubePilot disclosed that attackers had controlled its DNS settings and obtained TLS certificates for every subdomain, potentially exposing credentials entered on July 24.

Unit 42 also observed a Chinese-speaking actor using DeepSeek through Hermes Agent to select targets, find exploit code and attack infrastructure involving Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, PAN-OS and Windows IKE Extensions.

“Hermes Agent provided orchestration while DeepSeek served as the reasoning engine for code generation, vulnerability assessment, target selection and decision-making,” Unit 42 said.

For businesses, the practical response is to shorten patch deadlines for browsers and internet-facing systems, enforce phishing-resistant MFA, audit third-party access and prepare rapid credential and certificate revocation. Trust must be continuously verified rather than inherited from a familiar interface, partner network or valid session.

#cybersecurity#infosec#chromesecurity#aithreats#sonicwall
Open analytics
On the site 0 views
min read 3 31.07.2026
Instagram

Chrome Patches 370 Flaws as AI Agents and Credential Attacks Accelerate

Open the post on Instagram ↗