Critical Security Alerts: NGINX Overflow, BitLocker Zero-Day, and Chrome Supply Chain Attack
This week's cybersecurity landscape is marked by three significant threats affecting major technology platforms. First, a critical heap buffer overflow vulnerability, identified as CVE-2026-42945, was disclosed in NGINX's rewrite module. Accompanied by a proof-of-concept exploit, this flaw allows potential remote code execution or denial of service through improper bounds checking. Second, the 'WaSteal' supply chain attack was uncovered, involving 126 malicious Chrome extensions with 148,000 installations. Controlled by a Brazilian entity, these extensions exfiltrated WhatsApp session data and advertising cookies, highlighting risks in browser add-on ecosystems. Finally, a new zero-day exploit named 'YellowKey' reportedly bypasses Microsoft BitLocker encryption using only a USB stick, posing a severe threat to data protection on Windows devices. These incidents underscore the urgent need for administrators to patch NGINX servers, users to audit browser extensions, and organizations to reassess physical security measures for encrypted drives. The convergence of server-side vulnerabilities, client-side supply chain compromises, and hardware-level exploits demonstrates the multifaceted nature of modern cyber threats requiring immediate attention and mitigation strategies across diverse technical environments.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection