Technology Intelligence
Threats against technology companies, software vendors, cloud services, and tech infrastructure.
YARA-X 1.21.0 Release, (Sat, Oct 3rd)
YARA-X&#;x26;#;39;s 1.21.0 release brings 5 improvements and 4 bugfixes.
Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
DHS readies major cyber contract
Justin Doubleday reports: The Department of Homeland Security is preparing this year to award a major cloud, cybersecurity and network services contract aimed at further centralizing the management of IT services across DHS. In a notice posted to Sam.gov last month, DHS laid out the notional timeline for award of the Network, Cloud and Cybersecurity... Source
OpenAI faces California DOJ subpoena amid growing cybersecurity incident notices
IAPP reports: Regulator inquiries into major AI companies’ cybersecurity practices are ramping up. A day after reports surfaced about the likely escalation of a U.S. Federal Trade Commission probe into OpenAI and other developers, California Attorney General Rob Bonta advanced his office’s ongoing OpenAI investigation. Bonta announced the company was served an investigative subpoena to
Fed employee repeatedly removed sensitive files, watchdog finds
Matt Bracken reports: A Federal Reserve Board staffer mishandled sensitive classified files and triggered hundreds of data loss prevention alerts leading up to their retirement, the agency’s inspector general revealed in a new report. The security issues with the employee were uncovered by the watchdog during its audit of the Fed’s offboarding process, which began... Source
Senate passes bipartisan bill to bolster hospital cybersecurity
Naomi Diaz reports: The Senate passed the bipartisan Health Care Cybersecurity and Resilience Act by unanimous consent. The legislation aims to help healthcare providers strengthen their cybersecurity defenses and protect patient information, according to an Oct. 1 news release from the Senate Committee on Health, Education, Labor and Pensions. Sens. Bill Cassidy, MD, R-La., Maggie... Source
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Zack Whittaker reports: Epic, the software technology giant that makes the widely used MyChart software for accessing patients’ medical data, has paused most of its product development as the company works to protect its software and systems from cyberattacks. Judy Faulkner, the founder and chief executive of Epic, told Modern Healthcare last month that the... Source
doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek .
Fortra Patches Critical Vulnerabilities in BoKS
The bugs could lead to authentication bypass, shell command execution, and memory corruption. The post Fortra Patches Critical Vulnerabilities in BoKS appeared first on SecurityWeek .
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of
N0n ransomware: what you need to know
N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.
NVD CRITICAL: CVE-2026-92084 — The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for W...
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcode
NVD CRITICAL: CVE-2026-87115 — The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable...
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as
NVD CRITICAL: CVE-2026-82042 — UTMStack before 11.2.16 contains an authentication bypass vulnerability that all...
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtai
NVD CRITICAL: CVE-2026-82041 — UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMInc...
UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, res
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.
Bipartisan backlash to ALPRs grows as two high-profile bills are introduced
Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.
NVD CRITICAL: CVE-2023-54405 — H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud plat...
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token pa
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
The legal questions raised by agentic AI hacks
Experts and policymakers want AI companies to face consequences for agentic hacks. There may not be a clear-cut answer under existing laws and regulations. The post The legal questions raised by agentic AI hacks appeared first on CyberScoop .
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
SWIFT Banking & Government Middleware Enables RCE
Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]
Is Your Organization Ready for 2027's AI Accountability Era?
Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.
Is It Fair to Blame 'Rogue' AI for Security Failures?
"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.
US sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]
YouTuber raises $15m for Brazil's 'Cash App'
NG.Cash, the "Brazilian Cash App" founded by a former YouTuber, has raised $15 million to back its efforts to bring credit and crypto services to the country's young, unbanked population.
Unidentified Flock Cameras in Florida
St. Lucie County in Florida discovered ( alt link ) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted. I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown. My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case
In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-19652 — The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation i...
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowe
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks
Mississippi mayor says ransomware incident led city to shut down systems
Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.
'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]
Vulnerability Backlogs Are an Ownership Problem
Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.
NVD CRITICAL: CVE-2026-104611 — A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown fu...
A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
NVD CRITICAL: CVE-2026-104610 — A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_...
A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek .
City of Vicksburg, Mississippi, shuts down computers after cyberattack
Joseph Topping reports: The City of Vicksburg, Mississippi, has shut down its computer systems after a ransomware attack, potentially delaying in-person utility payments while emergency response and utility service continue. Mayor Willis Thompson told The Vicksburg Post that the city had disconnected its internet operations. “We had to bring our internet operations down, just for... Source
Malicious Linux Implants Mimic Asian Mail Security Products
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.
SMTP is the key: BPFDoor and AVERAT hitting the network edge
Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT , deployed against Taiwanese appliances. Additionally, we provide source code details of the
Dell asks admins to patch max severity CSM flaws as soon as possible
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
Crypto Scammers Hijack Microsoft’s Official X Account
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek .
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is
In Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek .
Lloyds survey reveals 71% of UK FIs believe tokenisation will reshape financial services
Lloyds' 10th annual Financial Institutions Sentiment Survey, conducted between April and May 2026, showed that 71% of the 100 senior leaders surveyed across UK banks, insurers, financial sponsors and asset and wealth managers, expect tokenisation to transform how money and assets move through the financial system.
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them. Candidates’, parties’ and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet abo
Fairchild Medical Center & Boone Health Settle Pixel Lawsuits
Fairchild Medical Center and Boone Health have agreed to settlements to resolve complaints alleging they impermissibly disclosed patient data to […] The post Fairchild Medical Center & Boone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal .
SequenceHash: multihashing for the rest of us
<p>Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a <a href="https://blog.trailofbits.com/2024/08/21/yolo-is-not-a-valid-hash-construction/#yolomultihash">common stumbling point</a> when cryptographers try to use hashes.</p> <p>As part of our goal to “fix software, not bugs,” Trail of Bits is introducing <a hre
NVD CRITICAL: CVE-2026-94541 — The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerabl...
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the p
Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents
AngMar Management Services, a Mansfield, Texas-based home health and hospice management company, has identified unauthorized access to its information technology […] The post Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents appeared first on The HIPAA Journal .
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek .
Microsoft’s X account hacked in crypto pump-and-dump scheme
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]
Police Target KillSec Ransomware Group with Arrests and Seizures
Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects
Rolling the cyber dice with open-source and open-weight AI models
With typical cybersecurity exposure, I can conduct pen testing with deterministic tools. I am able to predict how a piece of software is going to respond. I even stand a decent chance of finding vulnerabilities before they can be exploited against me. What we are dealing with now is a new kind of exposure. For LLMs and AI models, there are invisible risks that are unscannable and virtually undetec
AI Agents Aimed SQL Injection at US and Canadian Government Sites
The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek .
EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage
Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational capacities of technology vendors whose wares compete in those markets. The EU CRA introduces mandatory reporting within 24 hours for any actively exploited vulnerabilities or severe incidents affecting produc
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days
NVD CRITICAL: CVE-2026-97637 — The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass vi...
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()
NVD HIGH: CVE-2026-95670 — The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Sc...
The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only
NVD HIGH: CVE-2026-93756 — The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin fo...
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that wil
NVD HIGH: CVE-2026-102772 — The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an inject
NVD HIGH: CVE-2026-100107 — The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Sit...
The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek .
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a
NVD HIGH: CVE-2026-102565 — The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site S...
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful
NVD HIGH: CVE-2026-92174 — The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File I...
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to by
NVD HIGH: CVE-2026-90438 — The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPr...
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u
NVD HIGH: CVE-2026-15897 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Bec
NVD CRITICAL: CVE-2026-15896 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no au
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
NVD CRITICAL: CVE-2026-19660 — The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass ...
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled
NVD HIGH: CVE-2026-10026 — The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all ver...
The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server.
NVD CRITICAL: CVE-2026-14378 — The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leadi...
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by
NVD HIGH: CVE-2026-104120 — A security vulnerability has been detected in modelcontextprotocol mcp-server-fe...
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be us
NVD CRITICAL: CVE-2026-86345 — A flaw was found in 389-ds-base. The server does not discard plaintext bytes alr...
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a cl
NVD CRITICAL: CVE-2026-103765 — Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in...
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server
NVD CRITICAL: CVE-2026-103764 — Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference...
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory
Monarch acquires HMBradley
Personal finance platform Monarch has acquired MBI, the digital banking fintech formerly known as HMBradley.
Barclays ramps up use of Anthropic's Claude
Barclays is extending its use of Anthropic's Claude in an effort to accelerate software development, modernise its legacy systems and boost operational efficiency.
Australia's WeMoney launches AI and open banking-powered lending assessment service
Australia's WeMoney has launched an AI-powered lending assessment service built on the country's Consumer Data Right.
CISA KEV: Zammad GmbH Zammad — Zammad GmbH Zammad Improper Privilege Management Vulnerability
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
CISA KEV: Zammad GmbH Zammad — Zammad GmbH Zammad Session Fixation Vulnerability
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
NVD HIGH: CVE-2026-103761 — Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulne...
Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
NVD HIGH: CVE-2026-104051 — PictShare before 3.7.1 contains an information disclosure vulnerability that all...
PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
Iranian accused of hacking American universities extradited from Montenegro
An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro.
Walapay raises $4.6m
Walapay, global payments infrastructure for account issuance, collections, FX, and payouts, today announced a $4.6 million seed round led by Generative Ventures, with participation from Commerce Ventures, Polygon, Verda Ventures, NGC Ventures, FGV Capital, AAF, Jsquare, Knollwood, Big Brain Holdings and others.
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
The teenager-run cybercrime group victimized roughly 500 organizations in less than two years. The post Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members appeared first on CyberScoop .
Microsoft says threat actors are ahead in the early AI race
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]
Teenagers suspected of leading KillSec ransom group arrested during international operation
DataBreaches has reported on a group known as KillSec for almost two years. This time, we get to report on their arrest. The European Union Agency for Criminal Justice Cooperation issued this press release today: An international group of authorities from nine countries, coordinated by Eurojust and Europol, has successfully shut down a ransomware group... Source
OpenAI software attempted to secretly scrape data from dozens of prominent websites
The findings, released Thursday by Asymmetric Security, are just the latest example of rogue behavior spurred by OpenAI’s software.
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Sean Cairncross talked about regulations, China, pilot projects and more Thursday. The post National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations appeared first on CyberScoop .
NVD HIGH: CVE-2026-15911 — Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a re...
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
Sibos 2026: What does a successful ESG strategy look like?
How can global financial institutions maintain a coherent sustainability strategy with constantly shifting expectations? This was discussed at Sibos Miami 2026 by a panel of experts.
BMO joins Project Agorá
BMO today announced its participation in Project Agorá, the global public-private collaboration convened by the Bank for International Settlements (BIS) and the Institute of International Finance (IIF) to explore how tokenization and programmability could enhance wholesale cross-border payments.
Bloomberg closes Canoe Intelligence acquisition
Bloomberg today announced the completion of its acquisition of Canoe Intelligence (“Canoe”), a leading AI-powered data management and intelligence platform for automating private markets data collection and delivery.
NVD HIGH: CVE-2023-54404 — Zod schema-validation library through 4.6.5 contains an uncontrolled resource co...
Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early te
Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.
Give yourself room to be human
In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.
Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right. The post Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks appeared first on SecurityWeek .
Sibos 2026: Don't just think tech, think talent to achieve broad AI literacy
It’s not just the tech banks need to think about. The talent that is needed to make most organisational AI aspirations a reality is a huge part of the successful AI adoption — per an expert panel at the 2026 Sibos conference in Miami.
NVD CRITICAL: CVE-2026-96659 — A flaw was found in Foreman. This vulnerability allows an authenticated user wit...
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw
NVD CRITICAL: CVE-2026-96658 — A flaw was found in Foreman. An authenticated attacker with low-level permission...
A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.
Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains
Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains appeared first on SecurityWeek .
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can
‘A treasure trove of information:’ Cybersecurity specialist says sensitive McMinnville records exposed online
KOIN in Oregon reports: Three clicks. That’s all Chuck Dornon said it took to reach private McMinnville records that should never have been public on the dark web. “Anything and everything that the city’s done is out there,” Dornon said. “This is probably the easiest form of information I’ve come across in a breach.” The... Source
OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued guidance for state Medicaid […] The post OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions appeared first on The HIPAA Journal .
Police disrupt KillSec ransomware, arrest suspected teenage leader
European police said raids against the KillSec ransomware-as-a-service operation included the arrest of a high-profile teen suspect.
Nubank rejects Monzo takeover talk
Brazilian digital banking giant Nubank has denied that it is pursuing a $10 billion takeover of Britain's Monzo.
NVD HIGH: CVE-2024-58388 — Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthentica...
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, inclu
Stripe to buy embedded finance platform Parafin
Stripe has agreed to buy embedded financial products platform Parafin. Financial terms of the deal were not disclosed.
Payments Canada welcomes six new members
Payments Canada announced today the approval of six new members: Bounce Finance Inc. (“Bounce Pay”), Everlink Payment Services ULC (“FIS Everlink”), Nium Canada Corporation (“Nium”), Pesapeer Incorporated (“Pesa”), Remitly Canada, Inc. (“Remitly”) and Vancouver City Savings Credit Union (“Vancity”).
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's
Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass appeared first on SecurityWeek .
Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says appeared first on SecurityWeek .
European payments groups join forces to take on US giants
Some of Europe's biggest payments groups - Bancomat, Bizum, Wero, Sibs-MB WAY and Vipps MobilePay - have banded together to create a cross-continent network that can take on Visa and Mastercard.
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
Sardine launches AI research lab
Sardine, the leading agentic risk platform for fighting fraud and financial crime, today launched Sardine AI Labs, an applied research group advancing frontier intelligence to fight financial crime.
Fiserv digital platform goes live with FI clients
Fiserv, Inc. (NASDAQ: FISV), a leading global provider of payments and financial services technology, today announced that its digital asset platform is live with financial institution clients, marking a significant milestone in the commercialization of stablecoin-enabled banking and payments.
Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader
Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek .
Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges
AI policy circles targeted in China-linked phishing operation
Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and legal-sector experts. The post AI policy circles targeted in China-linked phishing operation appeared first on CyberScoop .
The Day-One Hole in Zero Trust Architecture
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]
China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
TA419 posed as AI policymakers and economists to phish US AI policy experts' Microsoft 365 accounts
Kiteworks patches max severity code injection vulnerability
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...]
Iplicit opens Newcastle office
Iplicit, the leading finance system for the UK and Ireland mid-market, has announced today the opening of a new office in Newcastle, a strategic move to strengthen its advantage over incumbent legacy vendors.
Tokenovate appoints William L’Heveder chief revenue officer
Tokenovate, the UK financial technology company providing post-trade workflows-as-a-service and programmable settlement solutions, has appointed William L’Heveder as Chief Revenue Officer.
Google makes Gemini 4 AI model available to a trusted few
Google has unveiled a new frontier AI model after months of delay. Gemini 4 Argon is designed to handle complex, long-horizon workloads spanning software engineering, enterprise knowledge work such as legal and financial analysis, and cybersecurity. But only a few organizations can get their hands on it for now. Argon is “rolling out to a set of trusted cyber defenders through our Fairwind Program
Data Breaches Announced by Saber Healthcare & Buchalter
Data breaches have been announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm that provides services to […] The post Data Breaches Announced by Saber Healthcare & Buchalter appeared first on The HIPAA Journal .
Iliad Solutions adds Micah Kerr to US team
Iliad Solutions, a leading provider of payment testing and certification technology, has appointed Micah Kerr as Lead Technical Sales Consultant as it continues to expand its presence in the US. Micah joins from Capital One's Discover Global Payment Network.
Marex expands digital assets offering with rolling spot crypto
Marex (NASDAQ:MRX), announced the launch of an OTC rolling spot crypto product for institutional clients, marking the latest step in the firm’s continued expansion of its digital assets offering.
Cisco SD-WAN Manager hit by zero-day admin access attack
Cisco’s SD-WAN management software has been letting some attackers walk through an authentication check without having to prove who they are. The company says it has now fixed the flaw that was allowing it. The affected platform, Cisco Catalyst SD-WAN Manager , is used to configure and operate software-defined network deployments. Cisco said in an advisory that improper handling of URI encoding in
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor
StraitsX to bring first SGD-denominated stablecoin to Monad
StraitsX today announced plans to bring XSGD and XUSD to the Monad network in early 2027. XSGD is planned to become the first SGD-denominated stablecoin natively issued on Monad, expanding the currencies available to developers, businesses and institutions across the network.
Jordan FinTech Academy and Mena Fintech Association sign MoU
Reflecting Jordan’s growing role in the regional fintech ecosystem, the Jordan FinTech Academy (Jordan FTA) at the Institute of Banking Studies (IBS) and the MENA Fintech Association (MFTA) have signed a Memorandum of Understanding (MoU) to establish a framework for cooperation, knowledge exchange, professional development, and stronger connections between fintech professionals and institutions in
Gresham ships application to simplify complex reconciliation with AI
Gresham, a global leader in enterprise data automation for the financial services industry, today announces the availability of Control Studio, a new AI-enabled, self-service application for its Control reconciliation product.
AI Has Changed Attack Speed, Not Security Fundamentals
As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. The post AI Has Changed Attack Speed, Not Security Fundamentals appeared first on SecurityWeek .
Revolut expands loyalty programme with hotel transfers
Revolut, the global financial platform with over 80 million customers worldwide, has today expanded its RevPoints loyalty programme, bringing hotel transfers in-app.
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
How AI Is Changing the Roles Required in the Security Operations Center
As AI takes on more of the enrichment, correlation, and initial assessment inside the SOC, roles, skills, and KPIs still require deliberate redesign. Security leaders need to decide where automation is dependable, where human judgment should remain decisive, and how teams should be measured when alert handling is no longer the center of the operating model The Gartner® report, The Roles Required f
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure appeared first on SecurityWeek .
Cyberattack on major Polish invoicing platform exposes customer data
One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners.
Monta monta.app
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.</strong></p> <p>The
Meari IoT Cloud Platform OpenAPI Service
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data w
Sibos 2026: Thoughts from experts at Commerzbank, SMBC, and The Clearing House
At Sibos Miami 2026, Finextra spoke to banking leaders across the industry on what the greatest challenges and opportunities in the global cross-border payments landscape.
Armatura LLC Armatura One
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-contr
Johnson Controls EasyIO Neo Series EC and CW Controllers
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.</strong></p> <p>The following versions of Johnson Controls
ABB Protection and Control IED Manager PCM600
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files.</strong></p> <p>The following versions of ABB Protection and Control IED Manager PCM600 are affected:</p> <ul> <li>Pro
Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.
Datawater reports: Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed. CISA’s deadline is today. Patching alone will not tell you whether you were already breached. Threat level: Critical What: Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, both CVSS 9.5. Status: Explo
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation appeared first on SecurityWeek .
NVD HIGH: CVE-2026-103283 — Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability tha...
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
NVD HIGH: CVE-2026-103271 — Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that...
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.
NVD HIGH: CVE-2026-103266 — Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, w...
Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the injected content may be rendered, resulting in HTML injection or cross-site scri
NVD CRITICAL: CVE-2026-103264 — Fleet versions before 4.87.0 contain an authentication bypass vulnerability in t...
Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migr
NVD HIGH: CVE-2026-103262 — Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerabi...
Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.
NVD CRITICAL: CVE-2026-103255 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security
NVD HIGH: CVE-2026-103250 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that fails to validate the sessionId parameter. Unauthenticated attackers can supply MongoDB query operators in the sessionId field to access conversation histories from other users and perform unauthorized write and delete operations.
NVD CRITICAL: CVE-2026-103248 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.
NVD HIGH: CVE-2026-103246 — n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ...
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and exfiltrate plaintext secrets to attacker-controlled hosts without ownership verification.
NVD CRITICAL: CVE-2026-103244 — ground-station versions before 0.8.0 contain an authentication bypass vulnerabil...
ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.
Microsoft enables Windows settings backup by default for orgs
Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. [...]
Connected Cars Are a Surveillance Platform
Researchers at Northeastern University, in collaboration with Consumer Reports , evaluated how much modern cars spy in their drivers: To determine this, CR dug through thousands of pages of automakers’ privacy policies and asked questions of 15 different automakersBMW, Ford, General Motors, Honda, Hyundai, Kia, Mazda, Mercedes-Benz, Mitsubishi, Nissan, Stellantis, Subaru, Tesla, Toyota, and Volks
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
The FBI has a very simple message for the ShinyHunters gang: give yourselves up. On Tuesday, FBI cyber division assistant director Brett Leatherman released a video, thanking the Dutch police for arresting a 24-year-old man they believe to be a member of the group, and and who is separately suspected of attempting to arrange two murders. Read more in my article on the Hot for Security blog.
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and - in a sinister twist - the 24-year-old suspect is also being investigated for attempting to arrange two murders. Read more in my article on the Hot for Security blog.
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek .
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek .
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with
CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit
CPAP Medical Supplies and Services, a Jacksonville, Florida-based provider of durable medical equipment for treating sleep apnea, has agreed to […] The post CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit appeared first on The HIPAA Journal .
The Fine Art of Frustrating the Adversary
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.
Agents Pick Dependencies, DoWI 8430.01 Holds You Accountable
<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/your-agents-are-choosing-dependencies.-dowi-8430.01-says-you-own-the-result" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/Fed%20-%20Policy.png" alt="Image with hexagon shape at center containing a checkbox icon. The hexagon is surrounded by checkmarks throughout the image" class="hs-
Hackers stole Pentagon personnel records of over 3 million people
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. [...]
500,000 Active Credentials Left Exposed on GitHub
Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default. The post 500,000 Active Credentials Left Exposed on GitHub appeared first on SecurityWeek .
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
PwC finds global security leaders are most concerned about attacks on AI systems
NVD HIGH: CVE-2026-96813 — The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugi...
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute
NVD HIGH: CVE-2026-95687 — The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to...
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrato
NVD HIGH: CVE-2026-15983 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `s
Why AI agents are like the dog that pushed kids into the Seine
There is an interesting story about a French dog on the banks of the Seine river that helps us understand misbehaving AI agents. The dog is trained to save children from drowning. He succeeds and is rewarded, becoming an overnight sensation. He saves another child a week later. Not long after, someone witnesses the dog actually push a child into the river, jumping in to “save” him. The dog did not
Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges. The post Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability appeared first on SecurityWeek .
NVD HIGH: CVE-2026-93882 — The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin ...
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and per
NVD CRITICAL: CVE-2026-75957 — The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for Wor...
The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `check
NVD HIGH: CVE-2026-19807 — The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerabl...
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the ca
NVD CRITICAL: CVE-2026-15989 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role ag
Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide. The post Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders appeared first on SecurityWeek .
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,
MI5 Warns Over 100 Academics Helped China's Espionage Plans
MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute
Metamask discloses security incident affecting its infrastructure
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...]
NVD CRITICAL: CVE-2025-41753 — The object name of a dynamically created BACnet File Object is interpreted as a ...
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
NVD HIGH: CVE-2026-85679 — The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because r
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
NVD CRITICAL: CVE-2026-92966 — The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordP...
The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbit
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets." MetaMask
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
NVD HIGH: CVE-2026-92245 — The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive...
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom form field data — stored in appointment records, as well as per-appointment publ
Why AI Coding Agents Keep Writing Broken Access Control
AI coding agents can produce authorization logic that compiles and passes review while exposing one tenant’s data to another. Learn why broken access control is difficult to detect and how to prevent it.
Capitolis agrees $200m eSecLending acquisition
Capital markets technology provider Capitolis has added securities lending capabilities to its platform through a $200 million all-cash deal to buy eSecLending.
Citi launches multi-market instant payments on Swift scheme
Citi has gone live with multiple markets on the Swift payments scheme, enabling bank clients to access multiple cross-border instant payment markets through a single account structure.
Zilch eyes 2027 London IPO
Zilch is in talks with banks as it prepares to go public, with the UK-based buy now, pay later provider reportedly leaning towards a London listing.
Apple Pay arrives in India
Apple Pay is finally launching in India, entering a huge but competitive market via a partnership with Axis Bank.
Sibos 2026: How can capital be mobilised into climate impact investments?
In this Sibos Miami 2026 panel, experts discussed the need for funding in sustainable action and how financial institutions can invest in infrastructure and communities at risk.
CISA KEV: Fortinet FortiMail — Fortinet FortiMail Path Traversal Vulnerability
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment. The post FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers appeared first on SecurityWeek .
NVD HIGH: CVE-2026-103591 — DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file ...
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
US sanctions 10 over ATM malware scheme tied to Tren de Aragua
Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.
CVE-2026-86950: The Great Glyph Grift
[object Object]
OpenAI reveals ‘novel’ encryption bypass used in distillation attack
The company said individuals associated with Chinese company MoonshotAI were behind parts of the attack, but did not offer hard evidence for the claim. The post OpenAI reveals ‘novel’ encryption bypass used in distillation attack appeared first on CyberScoop .
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
NVD HIGH: CVE-2023-54403 — Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability...
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files cont
NVD HIGH: CVE-2023-54402 — iDocView contains a server-side request forgery vulnerability in its /doc/upload...
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application con
Trump, Tech Giants Strike Voluntary AI Safety Accord
The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.
Russian state hackers use new RedFlick technique to push malware
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]
Automakers routinely share personally identifiable connected-car data with third parties, report says
A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.
NVD HIGH: CVE-2026-102993 — pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a craf...
pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.
NVD HIGH: CVE-2026-101885 — ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path tr...
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
NVD HIGH: CVE-2026-101884 — OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variabl...
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
NVD HIGH: CVE-2026-101880 — OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulner...
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) appeared first on Unit 42 .
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]
After reports on suicide deaths, Pentagon puts Cyber Command on notice
An August 31 memo obtained by Recorded Future News shows that the Pentagon's assistant secretary for cyber policy made specific demands of U.S. Cyber Command leadership after reports of a cluster of suicide deaths.
Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.
UK competition watchdog raises concerns over Brink's-NCR Atleos deal
The UK's competition watchdog says it will undertake an in-depth investigation into cash management giant Brink's' planned $6.6 billion deal to buy ATM operator NCR Atleos - unless the parties take action to address concerns.
NVD CRITICAL: CVE-2026-103475 — yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP a...
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.
NVD HIGH: CVE-2026-103474 — yii2-starter-kit through 4.2.0 fails to validate file types in the backend stora...
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
NVD HIGH: CVE-2026-103473 — Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnera...
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.
NVD HIGH: CVE-2026-103472 — restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up ...
restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]
Radford experiencing outage after potential data incident
WFXR in Virginia reports: The City of Radford announced tonight (9/29) the city is currently dealing with an internet outage due to a potential data breach. City leadership says it reached out to cybersecurity professionals and legal counsel upon becoming aware of the incident. Both state and federal law enforcement have also been notified, and... Source
NVD CRITICAL: CVE-2026-102490 — All versions of Zammad including the latest alpha enable the local zammad user t...
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
NVD CRITICAL: CVE-2026-102489 — Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha...
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol
H1 2026 Healthcare Data Breach Report
There has been a 5.9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026, […] The post H1 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal .
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
NVD HIGH: CVE-2026-103231 — A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up...
A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The proj
NVD HIGH: CVE-2026-103229 — A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7...
A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be u
NVD CRITICAL: CVE-2026-102427 — Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaS...
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that woul
NVD CRITICAL: CVE-2026-100277 — In JetBrains YouTrack before 2026.2.19197 account takeover was possible by repla...
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
NVD HIGH: CVE-2026-100276 — In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow ac...
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
NVD CRITICAL: CVE-2026-100273 — In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts de...
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
NVD HIGH: CVE-2026-100262 — In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users wi...
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
NVD CRITICAL: CVE-2026-100255 — In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account...
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
Sibos 2026: The quantum tipping point
What does the quantum threat mean for financial services?
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. CVE-2026-76504 carries a
NVD CRITICAL: CVE-2026-18782 — Improper neutralization of special elements used in an SQL command ('SQL injecti...
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.
NVD CRITICAL: CVE-2026-103395 — LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC se...
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.
One Inc launches XpressOne to accelerate insurance claims
One Inc, the leading digital payments network for the insurance industry, already connects more than 1.3 million vendors and providers with over 320 carriers.
Lumin Digital appoints Mike Valentine to board of directors
Lumin Digital, the Compounding Growth Platform for banks and credit unions, today announced the appointment of Mike Valentine, outgoing chief executive officer of BCU, to its board of directors, effective October 1, 2026.
Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
NVD CRITICAL: CVE-2026-82307 — Improper neutralization of special elements used in an SQL command ('SQL injecti...
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
Higher education is under siege, and fragmented security is making it harder to respond
Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow. In Q2 2025, universities faced an average of 4,388 cy
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post Google: AI Is Changing the Pace and Profile of Vulnerability Discovery appeared first on SecurityWeek .
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise
Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
Unsloth’s model picker had a code-execution problem
True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines. Pillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the model repository. This could potentially allow attackers to use a speci
Microsoft to block Entra ID script injection attacks starting October
Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]
NVD CRITICAL: CVE-2026-76504 — A vulnerability in the API session-based authentication management of Cisco Cata...
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a spe
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek .
Trading Technologies acquires Trafix
Trading Technologies International, Inc. (TT), a global capital markets technology provider, today announced it has acquired TRAFiX LLC (TRAFiX), a leading provider of equities and equity options order and execution management systems (OEMS) and FIX connectivity solutions.
Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord
Trump and six AI firms sign a voluntary accord on internal controls, audits and board oversight
Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek .
TeamViewer urges users to patch severe flaws “as soon as possible”
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post Chrome, Firefox Updates Patch Over 100 Vulnerabilities appeared first on SecurityWeek .
Robinhood deepens agentic AI offering in push to become go-to place for active traders
At yesterday evening’s HOOD Summit: Engines of Creation, Robinhood chairman and CEO, Vlad Tenev, announced a clutch of new active trading products.
AI Boosts SOC Analyst Capacity but Limits Skill Development
Swimlane finds that AI is reducing repetitive work for SOC teams but some feel their careers may suffer
Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters
The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware.
Know Your Enemy: Browser-Based Attack Techniques in 2026
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1.
The Mental Health Association Data Breach Settlement Agreed
The Mental Health Association, a Chicopee, Massachusetts-based human services agency that provides substance use recovery and support services for developmental […] The post The Mental Health Association Data Breach Settlement Agreed appeared first on The HIPAA Journal .
DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure
Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to […] The post DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure appeared first on The HIPAA Journal .
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts
Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware
Cybersecurity researchers at Huntress identify campaign to deliver potent trojan which targets users searching for ChatGPT via Google
Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do. The post Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit appeared first on SecurityWeek .
FCA opens the gateway to regulated crypto
From today, crypto firms can apply for authorisation from the FCA, marking a landmark moment as the UK takes a step closer towards becoming one of the most trusted places in the world to build and invest in cryptoasset businesses.
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
I Want Better Reporting on AI Genie Behavior
AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “ genie behavior ,” because I think that really gets at the core of what’s happening. I wish the popular press would report on this better. I don’t like the “going rogu
HSBC prepares for the launch of HK$-backed stablecoin, RedCoin
HSBC's forthcoming stablecoin launch in Hong Kong will bare the brand RedCoin.
Sibos 2026: 'ISO 20022 is the Sagrada Familia of the financial industry'
Representatives from Swift, Standard Chartered Bank, Federal Reserve Bank of New York and Deloitte took to the stage at Sibos 2026 in Miami to discuss the decision to postpone the removal of unstructured addresses, despite the push towards the long-term objectives of ISO 20022.
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks appeared first on SecurityWeek .
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
Pentagon personnel database breach exposes personal data of millions
A Pentagon personnel database was breached for nine months without anyone noticing. Over three million people are affected. Read more in my article on the Hot for Security blog.
ShinyHunters Defiant After FBI Calls on Members to Come Forward
In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek .
Brazil's CSD BR to use the XRP Ledger for recording and auditing financial assets and securities
CSD BR, a financial market infrastructure authorized to operate as a registrar, central securities depository and settlement system, today announced the first phase of a strategic partnership with Ripple, the leading provider of blockchain solutions across traditional and digital finance.
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
WaterISAC reckons with range of threats after summer of cyberattacks
Internet-exposed tech, PLCs, outside integrators and inside protections are all factors the water sector’s information sharing and analysis center is watching. The post WaterISAC reckons with range of threats after summer of cyberattacks appeared first on CyberScoop .
The MFA you have isn’t the MFA you think you have
For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they’ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason — adding a second factor to a password login closed off an enormous share of credential-based attacks, and organizations that adopt
MoonPay opens for business in Korea
MoonPay has officially launched MoonPay Korea, its new subsidiary and planned hub for dedicated Asia-Pacific expansion.
Kora debuts One Rail to support Pan-African stablecoin transactions
Pan-African payment infrastructure provider Kora has announced the launch of One Rail, a significant expansion of its payments infrastructure designed to support stablecoins.
Aljazira Bank to grow international remittance services with Thunes
Thunes, the Smart Superhighway to move money around the world, has signed a new agreement with Aljazira Bank, one of Saudi Arabia's leading financial institutions, to modernize and expand its international remittance services.
Visa and Lloyds complete live trials of stablecoin settlement
Visa and Lloyds Banking Group have completed a live pilot exploring how stablecoin-based settlement could support faster, more transparent and flexible cross-border transactions.
Duco clients report 76% time savings in post-trade reconciliation operations with AI platform
Duco, the leading platform for agentic Operations in financial services, today announced the results of its Pacesetters programme, in which an initial group of 12 clients cut the time spent on manual reconciliation operational work by an average of 76% using Duco’s agentic workspace in production trials.
Brits feel overwhelmed by growing sophistication of AI-powered scams
The UK's National Trading Standards body reports that half of Brits struggle to tell what’s genuine online, while a quarter admit to feeling overwhelmed by the sophistication of scams as AI supercharges criminal activity.
NVD HIGH: CVE-2026-102578 — A flaw was found in Moodle. An authenticated attacker with access to the questio...
A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.
NVD CRITICAL: CVE-2026-102458 — EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. U...
EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.
NVD CRITICAL: CVE-2026-102455 — EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability....
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Ant International’s Antom supports Google Gemini push into Asian markets
Google Gemini and Antom, a leading merchant payment and digitisation services provider under Ant International, today announced a strategic partnership to make AI tools for learning, creativity and productivity more accessible to users in Asia.
BMLL and Simudyne to deliver AI market simulation with high-fidelity historical data
BMLL, the leading independent provider of harmonised, continually engineered historical Level 3, 2 and 1 data and analytics for Capital Markets, today announced a partnership with Simudyne, an advanced generative AI and agent-based simulation platform designed to model and replicate market dynamics.
Can we jail a superintelligence?
AI containment is essential, but security leaders should assume every boundary can fail once an agent can communicate, use tools, and act on real systems. On September 17, podcaster Steven Bartlett asked four AI experts an unusual question: Could you build a jail for a digital Einstein? The panel on The Diary of a CEO was debating whether AI could one day threaten humanity, but the question that s
Apple Patches CoreGraphics Zero Day Exploited in Attacks
Apple has patched CVE-2026-86950, a zero-day bug in the iOS CoreGraphics engine
Whatever happened to the 36-month IT security roadmap?
Insight Global’s John Dickson had a problem familiar to many CISOs today. Employees were embracing AI tools faster than his security team could track them, and new AI agents and service integrations spread rapidly across the environment alongside them. Dickson and his security org had plans to build visibility into those non-human identities (NHIs), tracking what they could reach and how they beha
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way
Zumo launches UK Crypto Regulation Tracker
UK digital asset firm Zumo has launcheed a Crypto Regulation Tracker to help firms cut through red tape and conquer the complexities associated with the incoming comprehensive regulatory regime.
This month in security with Tony Anscombe – September 2026 edition
Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep pace
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. The post High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL appeared first on SecurityWeek .
CVE-2026-94545 (CVSS 9.5) affects Next.js apps using next/og on the Node.js runtime with sharp.
[object Object]
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler
NVD HIGH: CVE-2026-102913 — A security flaw has been discovered in SourceCodester Car Driving School Managem...
A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
NVD CRITICAL: CVE-2026-102911 — A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknow...
A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is
NVD HIGH: CVE-2026-102910 — A security flaw has been discovered in SourceCodester Online Reviewer Management...
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
What Is Agentic AppSec?
Learn how Agentic AppSec uses grounded, bounded, and independently verified AI agents to run the application security loop.
Evo ADS Govern Agent Behavior Goes GA: Bringing MCP Usage Under Control
Evo ADS Govern Agent Behavior is now generally available, starting with MCP Governance. Discover, approve, monitor, log, and block MCP server usage across leading AI coding agents.
Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-103056 — AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in ...
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitr
NVD HIGH: CVE-2026-103055 — AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verificatio...
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.
Data breach incident targets prisoner medical records at 2 Mass. jails
Hadley Barndollar of masslive.com reports: A “cybersecurity incident” has occurred involving the electronic health record system for Suffolk County’s two jails, the system provider confirmed Thursday. Computer Systems Integrated Inc., which runs the EHRs-C platform containing prisoner health data and medical records, said it is aware of and investigating an incident involving the Suffolk County...
Microsoft is rolling out Linux container support to WSL
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]
NVD CRITICAL: CVE-2026-102794 — A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects...
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD CRITICAL: CVE-2026-102793 — A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects ...
A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in
Elio Mortgage launches with $5.1m in pre-seed funding
AI-native startup Elio Mortgage has raised $5.1 million in pre-seed funding led by Motive Partners and Social Leverage.
Circle and Volante partner to help banks integrate stablecoins into payment operations
Payments-as-a-Service specialist Volante Technologies is working with USDC-issuer Circle to help financial institutions integrate stablecoin payment and settlement capabilities into their existing operations.
Valley Bank to buy digital SME banking platform Bluevine
Regional lender Valley National Bank has agreed to buy SME digital banking platform Bluevine for around $340 million in cash and stock.
SMEs turn from banks to fintechs for cross-border payments
Most small and medium-sized businesses (SMEs) trading internationally are set to switch their current cross-border payment provider in the next two years, according to a Mastercard report.
Sibos 2026: What does sovereignty look like in a multi-rail payments landscape?
A hot conversation topic at Sibos this year is interoperability with emerging payments rails, which begs the question of what monetary sovereignty means in a multi-rail digital financial system.
CISA KEV: Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
NVD HIGH: CVE-2026-103042 — LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL co...
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.
NVD CRITICAL: CVE-2026-103041 — LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cac...
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.
NVD CRITICAL: CVE-2026-103040 — LightLLM through 1.2.0 contains a remote code execution vulnerability in the rou...
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.
NVD CRITICAL: CVE-2026-102792 — A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the fun...
A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD HIGH: CVE-2026-74222 — U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_r...
U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP input path to access released memory and crash the bootloader.
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come. The post Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected appeared first on CyberScoop .
Signal adds encypted local backup support to iOS, desktop apps
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
US Air Force members given over 6 years in prison for cyber theft of more than $2 million
According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June.
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]
Controversial spyware firm Paragon to go public by end of year
The company plans to close the deal around the end of the year at which point Paragon will begin trading on Nasdaq under the REDLattice umbrella.
NVD CRITICAL: CVE-2026-53988 — Dockhand before 1.0.40 contains an authentication bypass vulnerability in its gi...
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or,
NVD HIGH: CVE-2026-102876 — SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construc...
SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, cr
OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference appeared first on SecurityWeek .
FBI tells ShinyHunters members to turn themselves in after recent arrest
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft says the cyberespionage campaign has hit U.S. and U.K. targets, relying on sheer volume and requiring only a single victim interaction. The post Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond appeared first on CyberScoop .
OpenAI apologizes for agents breaching Australian government websites without authorization
The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Sean Cairncross said CEOs need to be cognizant of how it’s being used, however. The post US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says appeared first on CyberScoop .
Cyberattacks to be insured like accidents: Ministry of Finance discusses new rules for critical infrastructure
Roman Zaharov reports: Cyberattacks may start to be insured according to the principle already in effect for hazardous facilities. The Russian Ministry of Finance is discussing the possibility of making cyber risk insurance mandatory for businesses associated with critical infrastructure. This was stated by Deputy Finance Minister Ivan Chebeskov on the sidelines of the Moscow... Source
BankPro picks Thredd to power card programmes
BankPro, the private digital bank headquartered in The Bahamas, today announced a strategic partnership with Thredd, the AI-first issuer processing platform, to power its physical and virtual debit and credit card programmes.
Shocker: suspected ShinyHunters member charged with attempted incitement to commit two murders
Anyone following the recent arrest of Pepijn van der Stap, the previously convicted hacker known as “Umbreon,” was likely shocked today when the prosecution announced that he was being charged with two counts of attempted incitement to murder. Here’s what we know so far. A 24-year-old Dutch national who previously served time for hacking-related crimes... Source
Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]
Jeeves raises $110m for stablecoin banking platform
Corporate card and expense management platform Jeeves has raised $110 million to scale its stablecoin-native banking platform for global enterprises.
NVD HIGH: CVE-2026-84440 — IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP...
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
NVD CRITICAL: CVE-2026-84436 — IBM Guardium Data Protection 12.2 is vulnerable to command injection in the cert...
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
NVD HIGH: CVE-2026-102811 — Marmite through 0.4.2 contains missing authentication in the development server ...
Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project director
Former US Air Force members sent to prison over BEC attacks
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]
Sibos 2026: Google Cloud reveals banks are moving from AI copilots to autonomous workflows
Held at The National Hotel in Miami during Sibos 2026, Google Cloud hosted a breakfast roundtable that focussed on the future of purpose-built AI for financial institutions, welcoming Georgina Bulkeley, director of financial services solutions, Google Cloud; Kristin Reinke, VP of finance, Google; Jason Allen, assistant treasurer, Google; Sarthak Pattanaik, chief data and AI officer, BNY; Joanne Ha
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak
Windows 11 2026 Update released, here's everything you need to know
Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. [...]
DARPA Selects Xint to Use AI in Securing Military Messaging Apps
The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software. The post DARPA Selects Xint to Use AI in Securing Military Messaging Apps appeared first on SecurityWeek .
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
Automated certificates for everyone, built for today, and hardened for the era of quantum computing.
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek .
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs
NVD CRITICAL: CVE-2023-54400 — Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.a...
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with
Experian deliver Cashback Attributes
Experian today announced Experian Cashflow Attributes for commercial lenders, a new solution that transforms business bank transaction data into analytics-ready attributes to help financial institutions make more informed decisions and gain a deeper understanding of the financial health of the businesses they serve.
Citi expands Token Services to the UAE and Japan
Citi has announced the expansion of Citi Token Services into the UAE and Japan, extending its global footprint and always-on 24/7 capability to support clients’ liquidity, payments, and collateral needs.
Automated AI agent used to breach cybersecurity nonprofit DIVD
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
Throught Machine and AWS to drive AI-powered core migrations
Thought Machine, the cloud-native core banking and payments technology company, today announced an AI-powered migration solution to accelerate banking modernisation with Amazon Web Services, Inc. (AWS) Transform.
Chainlink connects to Swift's blockchain ledger
Chainlink today announced it is working to enable financial institutions to connect their systems and key signing infrastructure to Swift's blockchain ledger through the Chainlink platform.
Alleged ShinyHunters leader arrested in the Netherlands
The arrest of a 24-year-old man in Amsterdam, which occurred a week before ShinyHunters hacked the FBI, marks a major turning point for law enforcement’s push to track down the group’s members. The post Alleged ShinyHunters leader arrested in the Netherlands appeared first on CyberScoop .
Terrabank to streamline cross-border payments with TerraPay and Mozrt
Terrabank, a Miami-based community bank and affiliate of Grupo Promerica, today announced a strategic partnership with TerraPay, a global money movement company, and Mozrt, a payments technology platform, to modernize and streamline cross-border payments.
Nayax and Santander's Getnet collaborate on unattended payments
Getnet, the global merchant payments platform and the leading payment solutions provider in Latin America and Iberia, and Nayax Ltd (NASDAQ: NYAX, TASE: NYAX), a global commerce enablement, payments, and loyalty platform helping merchants scale their business, today announced its partnership aimed at accelerating integrated payment acceptance and commerce services across key markets in Europe and
Center Parc Credit Union streamlines loan payment operations and plans for instant payments
Center Parc Credit Union has streamlined its loan payment operations with Alacriti's Orbipay Loan Payments solution, replacing fragmented payment processes with a unified self-service experience that makes it easier for members to make loan payments.
NVD HIGH: CVE-2026-102566 — CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary mod...
CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.
'NeedyMantis' Provides Long-Term Access to Compromised Networks
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
Autonomous Remediation Is Already Running at Enterprise Scale
The following is a guest blog by ITSPmagazine, based on their interview of Qualys President & CEO Sumedh Thakar at Black Hat USA 2026. Sumedh Thakar has watched the same clock compress for 23 years. He joined Qualys as an early software engineer on the scanner, when organizations scanned once every 90 days and gave […]
OpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing lines
OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company’s safety and alignment standards. GPT-6.1 Astra was being developed as a more autonomous model capable of handling complex tasks with less human assistance, and was expected to be integrated into ChatGPT and Codex. But internal testing found that it could evade oversight
RemoteThreat Launches With $7 Million for Offensive Operations Platform
The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek .
RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
RatHat's C2 panel now builds malware and ranks victims with AI across nearly 100 deployments
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company
Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities
The company said it found and patched a previously unknown critical vulnerability in one product during the weekend shutdown, and has no indication it was exploited. The post Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities appeared first on CyberScoop .
Catch threats before they escalate with real-time Identity Telemetry
Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity before it escalates. [...]
Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials
AWS AgentCore SDK flaws could let attackers run commands in AI sandboxes and reach AWS credentials
Bradesco completes pilot transaction using BofA cross-border payments tech
Bank of America today announced that Bradesco, one of Brazil’s largest private-sector banks, has completed the first pilot transaction using the bank’s Cross-Border Real-Time Payments solution.
WPM Pathology Laboratory; Salina Regional Health Center Settle Class Action Litigation
A settlement has been agreed to resolve class action litigation over a November 2024 targeted cyberattack on the information systems […] The post WPM Pathology Laboratory; Salina Regional Health Center Settle Class Action Litigation appeared first on The HIPAA Journal .
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
[object Object]
Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities
Two critical zero-day vulnerabilities in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are under […] The post Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities appeared first on The HIPAA Journal .
Astrana Health Notifies SEC About Social Engineering Incident
Astrana Health, a managed services organization that helps healthcare providers deliver value-based, coordinated care to patients, has notified the U.S. […] The post Astrana Health Notifies SEC About Social Engineering Incident appeared first on The HIPAA Journal .
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical
Thai remittance fintech DeeMoney selects SEON as its fraud and compliance partner
SEON, the AI Command Center for Fraud Prevention and AML Compliance, today announced that DeeMoney, Thailand’s leading fintech for international money transfers, has selected SEON as its fraud and compliance partner.
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
Microsoft Threat Intelligence warns that NeedyMantis threat actor from China has targeted organizations across a range of industries
AAIB deploys IBM's Safer Payments platform
Arab African International Bank (AAIB) achieved further progress in strengthening its digital payments security and fraud prevention capabilities through its collaboration with IBM and TECH-HUB.
Scans for Wordfence Protected Websites, (Tue, Sep 29th)
Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-waf.php file will be created in the site&#;x26;#;39;s root directory [1].
DTCC appoints Samir Pandiri as chief client officer
The Depository Trust & Clearing Corporation (DTCC), the premier post-trade market infrastructure for the global financial services industry, today announced the appointment of Samir Pandiri as Managing Director and Chief Client Officer, effective September 28.
Reco Raises $55 Million for Agentic Security
The company will use the funds to expand its sales, partnerships, channels, and customer support teams. The post Reco Raises $55 Million for Agentic Security appeared first on SecurityWeek .
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands. The post Hackers Use ChatGPT Custom GPTs in ClickFix Attacks appeared first on SecurityWeek .
Swedish fintech Froda expands to France
Froda, the Swedish embedded financing platform serving Europe's smallest businesses, today announced its launch in France in partnership with Shine.
FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data
Joseph Cox reports: The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical addresses, job roles, names of spouses, and medical records, represents a significant national security and... Source
Russian pizza restaurant chain confirms cyberattack: Hackers claim 68 million users exposed
Andrey Mihayloff reports: Dodo Pizza has confirmed a cyberattack on its IT systems, admitting that attackers may have accessed personal data of a portion of its customer base. The company reported the breach to Roskomnadzor and stated that access to the system has since been blocked. According to the company, the exposed data may include:... Source
Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims
According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details.
Arizona Supreme Court says hackers stole residents’ personal data
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
Pentagon Personnel Agency Data Breach Impacts 3 Million People
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on SecurityWeek .
Baicells Nova 430H
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition.</strong></p> <p>The following versions of Baicells Nova 430H are affected:</p> <ul> <l
VIVOTEK Camera Firmware
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system.</strong></p> <p>The followin
Viidure Dashcam Android Application
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform.</strong></p> <p>The foll
Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on SecurityWeek .
Finastra unveils AI-powered repair recommendations to support banks with smarter decision-making
Today at Sibos 2026 in Miami, Finastra announced the launch of Repair Recommendations – a new AI-powered capability within AI OperatorAssist. This move will help banks respond more quickly to growing payment activity by adding smarter decision-making into their existing workflows.
Anjvision YSSD-RTMP-H5
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device.</strong></p> <p>The following versions of
Lantronix G520 Series Cellular Gateway
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges.</strong></p> <p>The following versions of Lantronix G520 Series Cellular Gateway are affecte
Toptech TMS7 and TopHAT
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.</strong></p> <p>The following versions of Toptech TMS7 and TopHAT are affected:</p> <ul> <li>TMS7 7.6.3 (CVE-2
Vietnamese man charged in $16 million 'pig butchering' crypto scam
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]
Four Cyber Threats Harboring Big Plans for the Future
- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek .
OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations. The post OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training appeared first on SecurityWeek .
HSBC rolls out new digital transaction banking platform
HSBC has vowed to reduce complexity for corporate clients with the roll out of a new digital transaction banking platform.
Using Device Linking to Eavesdrop on WhatsApp and Signal
Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them. The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek .
Anthropic prospectus warns of 'existential threat to humanity'
Anthropic is inviting stock pickers to invest in no future, as its long-awaited IPO prospectus warns that its models could pose a 'catastrophic or existential risks to humanity'.
OperTraitors: How Kubernetes Operators Betray Your Security Posture
We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray Your Security Posture appeared first on Unit 42 .
Securing the keys to the kingdom: Announcing Executive Threat Detection
This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most high-value IT assets.
How AI Changes the SDLC Beyond Faster Coding
<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/how-ai-changes-the-sdlc-beyond-faster-coding" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/AI%20SDLC.png" alt="Image with concentric hexagon shapes at the center, with the innermost containing "AI" text with network nodes protruding out." class="hs-featured-image" style="width:auto !
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
The malware framework uses a modular architecture and a custom executable file format for long-term persistence. The post Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek .
Japanese Railway Operators Hit with Weekend Cyber Attacks
Tokyo Metro and Keio have revealed separate cyber-attacks
Broadridge appoints Theo Golden as head of tokenized products, international
Broadridge, (NYSE: BR) today announced the appointment of Theo Golden, CFA as Head of Tokenized Product, International, a newly created role.
Icma examines the role of smart contracts in distributed ledger technology in fixed income markets
The International Capital Market Association (ICMA) has today published a new discussion paper, "Smart contracts and DLT-based fixed income markets: What’s next?", examining the growing role of smart contracts in distributed ledger technology (DLT)-based fixed income markets and the challenges that will need to be addressed as the market develops.
Doconomy and Swedbank initiate climate research initiative
Doconomy and Swedbank have entered into a research collaboration as part of an international initiative exploring how consumers can better understand the climate and social impacts of their spending.
Kiteworks Urges Customers to Restart Systems After Shutdown Notice
Kiteworks has lifted a temporary shutdown recommendation which was issued on the back of federal intelligence
mambu connects with Mastercard Move
Mambu and Mastercard have today announced a strategic collaboration that will make it easier for financial institutions using Mambu to offer fast, secure and transparent cross-border payments.
Zopa brings in targeted support for investment customers
Zopa, the British digital bank pioneer with 2 million customers, has launched targeted support for its investment customers.
EPSG publishes version 11 of its SEPA Payments Standardisation Volume
The European Payments Stakeholders Group (EPSG), the industry association for payments harmonisation in the Single Euro Payments Area (SEPA), published version 11 of its SEPA Payments Standardisation Volume.
Walletdoc introduces Visa Payment Passkeys
South African shoppers can now skip the frustrating redirect to their bank and the one-time PINs that slow down online card payments and instead approve a purchase with a simple biometric check on their phone.
EU backs spotixx
Frankfurt-based fintech spotixx has been awarded funding from the EU's Eurostars program. Germany’s Federal Ministry of Research, Technology and Space (BMFTR) is funding a joint project between spotixx and Dutch company Roseman Labs.
Abhi and NymCard combine on SME credit provision for financial institutions in UAE
Abhi, an embedded finance platform providing Earned Wage Access (EWA) and financial technology solutions, , and NymCard, the leading payments infrastructure provider in the Middle East, today announced a strategic partnership to enable financial institutions to deliver more efficient credit solutions to small and medium-sized enterprises (SMEs) in the UAE.
Kiteworks patches critical flaw, brings customer systems online
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]
Sibos 2026: BofA expands payments capabilities with new intelligence and real-time services
At Sibos 2026, held in Miami, Bank of America announced numerous updates across its banking services that tap into the opportunities offered by advanced analytics, AI and real-time networks.
Brite Payments brings international Pay-by-Bank network to the UK
Swedish Pay-by-Bank network Brite Payments is launching in the UK after securing an Electronic Money Institution (EMI) licence from the Financial Conduct Authority (FCA)
Timeshare exit scams: From fake buyers to recovery fraud
Con artists are targeting timeshare owners who want out – and some victims are hit twice
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the
Lessons from Microsoft Patch KB5002907: Two Layers of Patch Control in Qualys TruRisk Eliminate
How reliability scoring keeps risky patches out of zero-touch jobs, and how one blocking rule stops a paused update across your environment. Executive Summary Microsoft has paused the rollout of KB5002907, an optional Microsoft 365 Apps update that left some Office 2016 and Office 2019 installations unlicensed or removed. When an update runs into trouble […]
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]
Marble raises €6.5m to automate compliance
French open-source infrastructure platform for fraud detection and AML/CFT compliance Marble has raised €6.5 million in a Series A funding round.
Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple has released iOS and macOS updates to patch the zero-day vulnerability tracked as CVE-2026-86950. The post Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ appeared first on SecurityWeek .
Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team. The post Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ appeared first on SecurityWeek .
NVD HIGH: CVE-2026-102293 — A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the ...
A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said.
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:
NVD HIGH: CVE-2026-102249 — A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability ...
A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did n
NVD HIGH: CVE-2026-102245 — A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected ...
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The
NVD CRITICAL: CVE-2026-102240 — A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the ...
A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not res
NVD CRITICAL: CVE-2026-101354 — A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affecte...
A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early ab
NVD HIGH: CVE-2026-101281 — A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected ...
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c75
Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI
Nvidia on Monday rolled out an agentic governance system called the Open Agent Safety Platform that combines software with out-of-band DPU-based silicon in a reference system design that it says will secure agents “from testing to deployment.” But while the Nvidia design’s silicon-based component provides some cybersecurity advantages, analysts argued that it cannot help with the vast majority of
Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
The vendor’s products are a common, recurring target for attackers, yet the official warning for some Citrix NetScaler customers was too late. The post Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings appeared first on CyberScoop .
NVD CRITICAL: CVE-2026-102361 — mall4j through 4.0 contains a missing authentication vulnerability in the PUT /u...
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
NVD CRITICAL: CVE-2026-101264 — A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unk...
A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
NVD CRITICAL: CVE-2026-101263 — A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some...
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
ECB invites expressions of interest for digital euro innovation workstreams
The European central Bank is inviting private companies and organisations to join the digital euro innovation platform to collaborate on experiments with new value-added services and explore future technological developments.
Sibos 2026: Keynote speakers explore interoperability, digital assets, and AI
Sibos 2026 in Miami kicked off with an introduction to the annual conference by Graeme Munro, chair of the board at Swift.
CISA KEV: Apple Multiple Products — Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
NVD CRITICAL: CVE-2026-101262 — A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability...
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any wa
NVD CRITICAL: CVE-2026-101261 — A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown par...
A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD CRITICAL: CVE-2026-101260 — A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this iss...
A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument firstLogin results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respon
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today&#;x26;#;39;s update for the current "27" branch does not address security issues, but fixes some functional
NVD HIGH: CVE-2026-101188 — A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638....
A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities
The Open Agent Safety Platform relies on both hardware and software components to monitor agent activities and quarantine unruly agents before they cause harm.
NVD CRITICAL: CVE-2026-101187 — A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability...
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used f
One Packet Can Crash OT Servers in Industrial Sectors
A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.
Japan's Keio confirms ransomware attack disrupted business systems
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]
Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
Dutch police confirm arrest in ShinyHunters hacking investigation
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. [...]
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the
Misconfigured Supabase apps expose data in over 16,000 databases
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]
Over 16,000 Supabase databases expose PII, passwords, auth tokens
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]
AI Agents Are Privileged Users; Who Is Auditing Their Access?
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least
As AI world debates security, NVIDIA releases open source tools for agents
One expert told CyberScoop that the announcement reflects industry recognition that after years of training models to behave safely or ethically, more outside controls are needed. The post As AI world debates security, NVIDIA releases open source tools for agents appeared first on CyberScoop .
IAM for AI agents: A Practical Enterprise Framework
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended.
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,
Modulate Raises $25 Million to Advance Deepfake Detection
The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention. The post Modulate Raises $25 Million to Advance Deepfake Detection appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-101081 — A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability ...
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
New Mexico jury finds Meta deceived consumers about data privacy practices
A New Mexico jury found Facebook violated the law nearly 44 million times by lying to consumers about its data privacy practices.
Hogan Lovells Cadwalader hacked by Silent Ransom Group; re-attacked after they wouldn’t pay
Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG’s recent attacks on Hogan Lovells Cadwalader. Yes, that’s “attacks,” plural. When New York City’s oldest law firm, Cadwalader, Wickersham & Taft, merged with Hogan Lovells in 2022, it combined two powerhouse firms. Yet despite... Sourc
OpenAI pauses AI model training after another agent bypasses network restrictions
OpenAI has paused training, evaluation, and inference involving tool use for its most-capable AI models after an agent bypassed network restrictions to communicate with an external chatbot during reinforcement-learning training of an internal research model. “Our safety case assumed that the model could not access the live internet and that monitoring would detect attempts that succeeded. The inci
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information, and benefits from having Google's stamp of approval despite researcher warnings.
US, UK warn of exploited Citrix NetScaler zero-day bugs
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
NVD CRITICAL: CVE-2026-101077 — A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function pr...
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD CRITICAL: CVE-2026-101076 — A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the func...
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Still on probation from previous arrest for hacking and extortion, Dutch national is arrested again (1)
In June 2023, DataBreaches reported on the arrest of a young Dutch national who was a highly respected “white hat” by day but also a prolific “black hat.” History seems to have repeated itself. Pepijn van der S. has been arrested once again for criminal activities. The Past Predicted the Present Pepijn van der Stap,... Source
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official
September 25 – U.S. Department of Justice: Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to... Source
NVD CRITICAL: CVE-2026-101075 — A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The imp...
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi
NVD CRITICAL: CVE-2026-101074 — A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected elemen...
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted
NVD HIGH: CVE-2026-101073 — A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an...
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in
Call for Presentations Open for 2026 CISO Forum Virtual Summit
SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs. The post Call for Presentations Open for 2026 CISO Forum Virtual Summit appeared first on SecurityWeek .
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42 .
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach
Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets
The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches
A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.
Swift provdes cross-border gateway to Bizum, PayID and Pix users
Swift has launched an initiative to bring the pay-by-alias experience of domestic national payment systems, Bizum, PayID and Pix, to cross-border transactions, enabling consumers to send money internationally using a mobile number or email address, rather than account details.
Swift provides cross-border gateway to Bizum, PayID and Pix users
Swift has launched an initiative to bring the pay-by-alias experience of domestic national payment systems, Bizum, PayID and Pix, to cross-border transactions, enabling consumers to send money internationally using a mobile number or email address, rather than account details.
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Cybercrime experts are stunned as ShinyHunters risks agent safety and intense federal heat in a bizarre attempt to force the retraction of an agency advisory. The post ShinyHunters trades financial extortion for a reckless war of ego with the FBI appeared first on CyberScoop .
Autonomous agents attack Azure using compromised identities and destroying resources
Jadepuffer, an autonomous AI attacker first identified in July, has expanded into Azure environments, using compromised digital identities to enumerate resources, delete cloud assets and collect other credentials, according to Microsoft. The activity includes “extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be us
Autonomous agents attack Azure using compromised identities, destroying resources
Jadepuffer, an autonomous AI attacker first identified in July, has expanded into Azure environments, using compromised digital identities to enumerate resources, delete cloud assets and collect other credentials, according to Microsoft. The activity includes “extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be us
BNY unveils Pay-to-Wallet technology option for banks
BNY has unveiled a Pay-to-Wallet capability, making it possible for banks to send cross-border payments from bank accounts to participating retail digital wallets, using existing Swift payment messages and correspondent banking infrastructure.
NVD CRITICAL: CVE-2026-90924 — Use of default credentials vulnerability in Innotim Software, Telecommunications...
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
NVD CRITICAL: CVE-2026-101072 — A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects ...
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
US banks invited to join Apple Pay class lawsuit
US banks have been given the green light to pursue a class action lawsuit against Apple over historical fees paid for access to the firm's mobile wallet.
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. [...]
Cyberattack on Polish medical software provider exposes patient data
Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.
NVIDIA Launches Open Platform to Secure Autonomous AI Agents
NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents
NVD HIGH: CVE-2026-86330 — An OS command injection flaw was found in the set_hostname_internal function of ...
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can p
NVD HIGH: CVE-2026-101067 — A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. Th...
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this dis
NVD HIGH: CVE-2026-101066 — A vulnerability was determined in dbgate up to 7.3.1. The impacted element is th...
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about
Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns
A quarter of victims of deepfake attacks have lost over $1m. CISOs worry that boardrooms don’t understand the threat
Former US soldier gets nearly six-year sentence for hacking, extorting telecoms
A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records.
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers. The post Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon appeared first on SecurityWeek .
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through
DC Health Agency Exposes 400,000 Beneficiary Records
The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed. The post DC Health Agency Exposes 400,000 Beneficiary Records appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-101039 — A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this...
A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD CRITICAL: CVE-2026-101038 — A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by ...
A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond i
New forms of intelligent money set to hit traditional bank B2B revenue streams
Stablecoins, tokenized deposits, and central bank digital currencies are projected to account for approximately four percent of global payments volume by 2030, diverting vast chunks of income from traditional bank revenue pools.
New Attack Against RSA
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007 . What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key. Third, the attack only works against pure signatures. T
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
[object Object]
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek .
New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections
A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform. The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek .
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
The platform combines open source software and a reference system design to keep AI agents within set boundaries. The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-101037 — A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the f...
A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
Overview On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772 . Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
[object Object]
NetScaler admins told to patch critical zero-days in ADC and Gateway now
Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “ Monday will be too late ,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirme
MCP Is Creating Major Governance Gaps, Researchers Warn
Ox Security found security shortcomings in analysis of over 15,000 MCP servers
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek .
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]
NVD HIGH: CVE-2026-101015 — A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected ...
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclo
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations
The devil is still in the email – but wearing a new mask
When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack
The devil is still in the email – but wears a new mask
When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack
Nubank in talks to take over Monzo
Brazilian neobank Nubank is reportedly eyeing a takeover of UK digital bank Monzo, in a deal that would value the British challenger at $10 billion.
Citrix Patches Critical Zero Days Under Active Exploitation
Citrix has confirmed exploitation of two critical zero-day RCE bugs
Stolen AI credentials feed growing LLM proxy economy
Cyber threat groups have increasingly targeted enterprise AI assets, such as credentials, cloud environments, and research, as a means for operationalizing their own use of AI . Now, another sophisticated means for obfuscating illegitimate use of AI resources is coming more clearly to light. According to a report last week from security firm Team Cymru, malicious actors are employing proxy servers
NVD HIGH: CVE-2026-101012 — A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to ...
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling re
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek .
Weekly Update 523: Live From a Norwegian Fjord
How's that view?! With NDC Oslo now done, it's a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott's and my "Cyber-broken" talk. In the meantime, this week is mostly about the ShinyHunters trajectory targeting both
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to
NVD HIGH: CVE-2026-101009 — A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected eleme...
A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendo
NVD CRITICAL: CVE-2026-101008 — A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the functio...
A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted ear
California Critical Access Hospital Announces Cybersecurity Incident
Data breaches have been announced by Modoc Medical Center and Vista Del Mar Child and Family Services in California, Park […] The post California Critical Access Hospital Announces Cybersecurity Incident appeared first on The HIPAA Journal .
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]
NVD CRITICAL: CVE-2026-101002 — A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affec...
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early
NVD CRITICAL: CVE-2026-101001 — A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impac...
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi
NVD CRITICAL: CVE-2026-101000 — A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affec...
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted ear
NVD CRITICAL: CVE-2026-100896 — A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected ...
A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
NVD HIGH: CVE-2026-100891 — A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. ...
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used
NVD HIGH: CVE-2026-100888 — A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. ...
A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for
Revolut gets green light to buy Argentinian bank
Revolut has received the regulatory go-ahead to acquire small Argentinian lender Banco Cetelem from BNP Paribas.
Singapore to train 80,000 FS sector employees in AI skills
Singapore's financial services sector has moved to prepare itself for the artificial intelligence era through the launch of an AI workforce co-lab and a commitment to train 80,000 employees in the technology.
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]
NVD CRITICAL: CVE-2026-100886 — A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4...
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa
NVD HIGH: CVE-2026-100885 — A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unk...
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this is
NVD CRITICAL: CVE-2026-101090 — Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect e...
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to b
NVD CRITICAL: CVE-2026-101084 — obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-co...
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
NVD CRITICAL: CVE-2026-101065 — Obot is an open-source AI agent/MCP platform. In all versions up to and includin...
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca
NVD HIGH: CVE-2026-101062 — Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENAB...
Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own dom
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
[object Object]
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
[object Object]
NVD HIGH: CVE-2026-88778 — Predictable exact value from previous values vulnerability in Citrix NetScaler A...
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
NVD CRITICAL: CVE-2026-88777 — Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N...
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service
NVD CRITICAL: CVE-2026-88776 — Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N...
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service
NVD CRITICAL: CVE-2026-88775 — Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gatew...
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
NVD HIGH: CVE-2026-88774 — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue ...
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
NVD CRITICAL: CVE-2026-88773 — Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')...
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
NVD HIGH: CVE-2026-88772 — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue ...
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
NVD CRITICAL: CVE-2026-88771 — Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc...
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]
Citrix confirms two NetScaler RCE zero-days exploited in attacks
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. [...]
Wireshark 4.6.9 Released, (Sun, Sep 27th)
Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]
OpenAI’s Systems Meddled With U.S. Government Sites
Kate Conger, Ana Swanson, and Cecilia Kang report that OpenAI was behaving somewhat badly again- unless you just view it as a curious child exploring without evil intent? OpenAI’s artificial intelligence went rogue and meddled with the websites for the Education Department, the Commerce Department and the Securities and Exchange Commission this summer without the... Source
UK: Ten NHS staff removed over Noah Woods data breach
Tom McArthur and Louise Parry report: Ten NHS staff have been removed from duty or suspended after a data breach involving the digital medical records of three-year-old Noah Woods. Launching an “urgent” investigation, Dr Martin Mansfield, deputy chief medical officer at East Suffolk and North Essex NHS Foundation Trust, said that any unauthorised access of... Source
Personal information of over 23,500 Simba customers leaked in data breach
Rhea Yasmine reports: Personal information of more than 23,500 Simba customers has been compromised in a data breach, the telco said in a statement on Sept 25. The data involved included names, identity card numbers, dates of birth, mobile numbers, and e-mail addresses belonging to 23,549 people, who had registered for Simba’s services. No credit... Source
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
<p>CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: <a href="https://www.cve.org/CVERecord?id=CVE-2026-88771">CVE-2026-88771</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-88772">CVE-2026-88772</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-88773">CVE-2026-88773</a>, <a href="https://www.cve.
NVD HIGH: CVE-2026-93302 — MatchTrustedPeer ignores the public key used, leading to forged CA clones passin...
MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The peer must know the certificates being loaded to either of those APIs to take advantage of the issue. When OPENSSL_COMPATIBLE_DEFAULTS is als
NVD CRITICAL: CVE-2026-89134 — A certificate with no dNSName SAN but another SAN type present (e.g. registeredI...
A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL && !cert->isCA instead of "no dNSName SAN", so an out-of-scope CN was accepted. This incomplete fix from CVE-2026-6731, leading to the name-constraint check issue,
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek .
NVD HIGH: CVE-2026-94418 — Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate sig...
Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse returned 0, so any parse error hid it. ParseCertRelative() reaches its validity-date, name-constraint and critical-extension checks only after ConfirmSignature() has
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26. Citrix has not confirmed the flaws or published a fix. Some administrators say they have taken appliances offline rather than wait for one to be available. NetScaler ADC and
NVD HIGH: CVE-2026-100846 — MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in...
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserializati
NVD HIGH: CVE-2026-100844 — MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner c...
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ';' on
NVD HIGH: CVE-2026-100842 — MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatia...
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(
NVD HIGH: CVE-2026-100838 — Contrast is a confidential-computing runtime for Kubernetes. In versions before ...
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critic
NVD HIGH: CVE-2026-100723 — vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (b...
vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is
NVD CRITICAL: CVE-2026-100721 — vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module...
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-str
NVD HIGH: CVE-2025-71426 — Contrast is a confidential-computing runtime for Kubernetes. In versions before ...
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator,
NVD HIGH: CVE-2025-71425 — Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and...
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initi
NVD CRITICAL: CVE-2026-100740 — A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the funct...
A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
CISA KEV: Citrix NetScaler — Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
CISA KEV: Citrix NetScaler — Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
NVD CRITICAL: CVE-2026-82901 — The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitr...
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
NVD CRITICAL: CVE-2026-85984 — The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPres...
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents. The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek .
Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]
Microsoft pauses KB5002907 update after Office license deactivations
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]
NVD CRITICAL: CVE-2026-100717 — froxlor is a server administration panel. In versions 2.3.10 and earlier, Valida...
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan
NVD CRITICAL: CVE-2026-100716 — Froxlor is a server administration panel. In versions 2.3.10 and earlier, the cu...
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component
NVD CRITICAL: CVE-2026-100715 — Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink foll...
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because mak
NVD CRITICAL: CVE-2026-100714 — Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchalleng...
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only bla
NVD CRITICAL: CVE-2026-100706 — kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Po...
kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc
NVD HIGH: CVE-2026-100697 — Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins...
Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST contain
NVD HIGH: CVE-2026-100693 — Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation ...
Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.
NVD HIGH: CVE-2026-100690 — Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css...
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox.
NVD HIGH: CVE-2026-100686 — Budibase versions before 3.45.0 fail to validate per-app authorization in the PO...
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
NVD HIGH: CVE-2026-100685 — Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint ...
Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to acces
NVD HIGH: CVE-2026-100682 — Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in ...
Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.
NVD HIGH: CVE-2026-100670 — Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in ...
Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() an
NVD HIGH: CVE-2026-100669 — Grav before 2.0.25 ships web server configuration samples whose access-control d...
Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, system, vendor, ignore_folders) sets ignoreCase="false" on its URL Rewrite <match> element, overriding the IIS default of ignoreCase="true";
NVD HIGH: CVE-2026-100646 — SiYuan is a self-hosted personal knowledge management system. In versions up to ...
SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cr
NVD HIGH: CVE-2026-100645 — SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnera...
SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.
NVD HIGH: CVE-2026-100642 — SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery v...
SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative a
NVD HIGH: CVE-2026-100641 — SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before ...
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as <img src=invalid onerror=...> becomes an executable event-handler attribute. Because the SiYua
NVD HIGH: CVE-2026-100638 — SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setN...
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessibl
NVD HIGH: CVE-2026-100637 — SiYuan versions before v3.8.4 contain a path traversal vulnerability in the chec...
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.
NVD HIGH: CVE-2026-100625 — Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_b...
Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and validates only that job's stored upload_path, but then forwards the user-controlled TUS resource suffix taken from /build/upload/:jobId/* to the builder service while injecting Capgo's privil
NVD HIGH: CVE-2026-100617 — Cap-go capgo.app fails to validate that principals in channel_permission_overrid...
Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization.
NVD HIGH: CVE-2026-100612 — Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control...
Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs a BEFORE UPDATE guard (enforce_sso_provider_client_update_guard()) that freezes only the dns_verified_at, domain, status and enforce_sso columns; provider_id (as well as metadata_url and attribute_map
NVD HIGH: CVE-2026-100608 — Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboa...
Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASHBOARD=true, and !isCloud()), the /admin/queues mount is protected only by the verifyTokenForBullMQDashboard middleware, which validates the JWT but performs no role, permission, or workspace/organizati
NVD HIGH: CVE-2026-100605 — Flowise through 3.1.4 contains missing route-level RBAC checks on chat message e...
Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts, model responses, and delete messages.
NVD HIGH: CVE-2026-100315 — A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5d...
A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file mydetailsfaculty.php. The manipulation of the argument myfid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about a
Poland reports a second medical data cyberattack in recent weeks
Polish healthcare entities have been the victims of cyberattacks recently. First, it was the MyDr system. Now it’s a software manufacturer that markets the Medyc software used by Polish healthcare providers. Stanisław Kaleta reports: Poland has been hit by another medical data cyberattack, weeks after an unprecedented breach exposed the personal information of almost 19... Source
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek .
Pentagon data breach of military personnel raises national security concerns
Sean Lyngaas and Davis Winkie report: A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts. “Unauthorized users” gained access to a vulnerable computer server belonging to the Defense Manpower Data Center (DMDC) beginning... Sou
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day
Some Supabase customers are publicly exposing reams of people’s data to the web
Zack Whittaker reports today’s nominee for the “No need to hack when it’s leaking” honors: Thousands of databases hosted by development platform Supabase are exposing people’s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found. UpGuard told TechCrunch that it found around 16,000 databases on which some degree of... Source
Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeared first on SecurityWeek .
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions
NVD HIGH: CVE-2026-98163 — In the Linux kernel, the following vulnerability has been resolved: cgroup: Avo...
In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()") extended the lifetime of tasks on the dying_tasks list. The iterators have provision to go through dying_tasks because of dying threadgroup leaders or explicit C
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief
NVD CRITICAL: CVE-2026-18143 — The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitr...
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it p
NVD HIGH: CVE-2026-100597 — OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-che...
OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path is changed concurrently. An attacker able to win the race can cause a sandboxed
NVD HIGH: CVE-2026-100596 — OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users exe...
OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.
NVD HIGH: CVE-2026-100589 — OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the ...
OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated s
NVD HIGH: CVE-2026-100588 — OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administr...
OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can insp
NVD HIGH: CVE-2026-100585 — OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-onl...
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner, causing the requested action to proceed without owner consent. The practica
NVD HIGH: CVE-2026-100580 — OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensit...
OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw proce
NVD HIGH: CVE-2026-100568 — OpenClaw versions before 2026.8.1 fail to properly restrict access to operator c...
OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.
NVD HIGH: CVE-2026-100561 — OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain a...
OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it w
NVD HIGH: CVE-2026-100560 — OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability ...
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.
NVD HIGH: CVE-2026-100559 — OpenClaw versions before 2026.8.1 contain a command parser vulnerability where e...
OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.
NVD HIGH: CVE-2026-100558 — OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in...
OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener resources and cause denial of service without consuming the WebSocket pre-auth co
NVD HIGH: CVE-2026-100557 — OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability ...
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.
NVD HIGH: CVE-2026-100555 — OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and ...
OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostname to the Synology NAS, where it could resolve to a different destination. When attachment delivery accepted a remotely influenced hostname, an attac
NVD HIGH: CVE-2026-100552 — OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per...
OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist,
NVD HIGH: CVE-2026-100551 — OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gatew...
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by
NVD HIGH: CVE-2026-100544 — openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured ...
openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a dep
NVD HIGH: CVE-2026-100543 — OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hash...
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config
NVD HIGH: CVE-2026-100541 — OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2....
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a c
NVD HIGH: CVE-2026-100535 — OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose t...
OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to
NVD HIGH: CVE-2026-100532 — @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through...
@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and ca
NVD HIGH: CVE-2026-100530 — OpenClaw versions before 2026.8.1 fail to bind working directory context to reus...
OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially different effects.
NVD HIGH: CVE-2026-100520 — Laranode versions before 1.2.1 contain a path traversal vulnerability in the POS...
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.
NVD HIGH: CVE-2026-100504 — Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnera...
Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution.
3 Consulting Myths Debunked by Unit 42 Experts
Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by Unit 42 Experts appeared first on Unit 42 .
NVD HIGH: CVE-2026-100419 — gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in...
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
Cameron Wagenius was involved in some of the most high-profile attacks of 2024 while on active duty. The post Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies appeared first on CyberScoop .
NVD HIGH: CVE-2026-10758 — Esri LERC is an open-source image or raster format which supports rapid encoding...
Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an application that uses LERC to crash the application, leading to a denial of service.
NVD HIGH: CVE-2026-100391 — MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerabili...
MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.
NVD HIGH: CVE-2026-100390 — Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the...
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
NVD HIGH: CVE-2026-100389 — GestSup versions before 3.2.61 contain a remote code execution vulnerability in ...
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
NVD HIGH: CVE-2026-100387 — pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in d...
pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
I feel like someone who reads this blog will want to go to this : Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]
How the CISO CFO Relationship is a Key to Cybersecurity Success
Building a financial bridge: Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk and enable business growth are better prepared to face today's threat landscape.
Why the CISO-CFO Relationship Is a Key to Cybersecurity Success
Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk, and enable business growth are better prepared to face today's threat landscape.
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
NVD HIGH: CVE-2026-100372 — ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the a...
ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web
NVD HIGH: CVE-2026-100310 — GNU libextractor before 1.16 loads plugins from an untrusted search path specifi...
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.
NVD HIGH: CVE-2026-100208 — Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorize...
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
NVD CRITICAL: CVE-2026-97064 — X-SpringBoot through 6.0 ships with a hardcoded static master login verification...
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.
NVD CRITICAL: CVE-2026-97063 — X-SpringBoot through 6.0 returns login verification codes in HTTP responses from...
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.
NVD HIGH: CVE-2026-97060 — X-SpringBoot through 6.0 lacks object-level authorization in user management end...
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users via POST /sys/user/update and POST /sys/user/delete endpoints.
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.
Bitget hit by $387.5 billion hack
Bitget has halted customer withdrawals after hackers that the crypto exchange suspects are linked to North Korea stole more than $380 million.
Bitget hit by $387.5 million hack
Bitget has halted customer withdrawals after hackers that the crypto exchange suspects are linked to North Korea stole more than $380 million.
NVD HIGH: CVE-2026-97885 — A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098...
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument fid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a
NVD HIGH: CVE-2026-97883 — A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Pr...
A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the argument gid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is use
NVD HIGH: CVE-2026-97882 — A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to ...
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component Faculty Authentication. Executing a manipulation of the argument fid/pass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available t
Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]
What We Missed: Google Gemini Joins the AI Escape Party
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.
Supreme Court permits states to use SAVE database for citizenship checks
Three justices wrote in a dissent that longstanding privacy laws protecting sensitive personal data held by the government should prevent the use of the database. The post Supreme Court permits states to use SAVE database for citizenship checks appeared first on CyberScoop .
AI tools help hacker break in for $25 per target
It’s cheap to set yourself up as a hacker these days using AI. Someone attacked 105 online retailers over a period of five days, compromising 27 of them — all for an average of $25 per attack, according to research by Israeli security company Gambit . But the attacks have been going on for much longer. Whoever is responsible used open-source AI harnesses to mount the attack. Gambit has identified
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]
NVD HIGH: CVE-2026-97878 — A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted ...
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD HIGH: CVE-2026-97877 — A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issu...
A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The
NVD HIGH: CVE-2026-97871 — A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue a...
A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclos
NVD HIGH: CVE-2026-89032 — BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerabi...
BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes su
Documentation placeholder domain used in ClickFix attacks
The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according to Manifold Security, which discovered the problem.
Labcorp Settles Multistate Data Breach Investigation for $2.3 Million
A coalition of 44 state attorneys general has agreed to settle a multistate investigation of Laboratory Corporation of America (Labcorp) […] The post Labcorp Settles Multistate Data Breach Investigation for $2.3 Million appeared first on The HIPAA Journal .
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]
NatWest unveils AI-powered audio-visual spending insights tool
NatWest is set to trial a fully generative audio-visual AI spending insights tool that lets customers explore their finances through natural voice and text conversations.
NVD HIGH: CVE-2026-93306 — IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW...
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web int
NVD HIGH: CVE-2026-84882 — IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Univers...
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
NVD HIGH: CVE-2026-84862 — IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in t...
IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.
In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek .
GitLab issue email’s only security is obscurity
It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor security defaults and a long-lived token embedded in the address mean that anyone who knows the address can potentially modify protected repositories. If project owners publish or leak these addresses, as some have, then they become vulnerable. The
Socure brings identity verification and fraud prevention to Circle Arc mainnnet
Socure, the leading AI-native trust infrastructure for global identity and risk intelligence, today announced that RiskOS is being used for identity verification and fraud prevention on Arc, the open Layer 1 blockchain built by Circle and now live on public mainnet.
NFU Mutual selects Bloomberg and Clearwater Analytics for investment management workflow
Bloomberg and Clearwater Analytics ('Clearwater') today announced that NFU Mutual ('NFUM'), the UK's leading rural insurer, has selected Bloomberg Buy-side Solutions together with the Clearwater platform to modernize its investment operating model.
Cyberattack hits Welsh police force, may have affected staff data
Dyfed-Powys Police in Wales said a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information.
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]
CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
[object Object]
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. [...]
Stopping IT Worker Scams Requires Revamped HR Process
Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to this
US prosecutors seize Tether-linked payment firm's bank accounts - FT
US federal prosecutors have seized bank accounts belonging Capstone, a payments business working on behalf of stablecoin issuer Tether and its sister exchange Bitfinex, according to the Financial Times.
NVD HIGH: CVE-2026-97865 — A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected ...
A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to address this issue. The patch is named 78c1222ec0e2119d84684032da1541120a2cdd23. The
NVD HIGH: CVE-2026-93834 — A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condit...
A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and
NVD HIGH: CVE-2026-85542 — IBM Guardium Data Protection 12.2 is affected by a command injection vulnerabili...
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.
NVD HIGH: CVE-2026-85029 — IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensit...
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
NVD HIGH: CVE-2026-84893 — IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI ser...
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
NVD HIGH: CVE-2026-84884 — IBM Guardium Data Protection 12.2 stores internal REST service-account passwords...
IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
North Korea Suspected in $351 Million Bitget Crypto Heist
Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen. The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek .
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration
PayComplete gets new owners
PayComplete, a global provider of cash automation software, devices, and services, today announced that it has successfully completed a value-enhancing transaction with new investors, which now own a controlling interest in the company and have provided significant new capital to support its growth.
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
DBS and Avaloq target wealth management across Asia
DBS and Avaloq have signed a memorandum of understanding (MoU) to expand their 18-year partnership and jointly develop the next generation of wealth management capabilities for clients and advisers across Asia.
Microsoft plans to deprecate Windows Deployment Services
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]
CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek .
CISA Unveils Election Security Plan Ahead of 2026 Midterms
The CISA plan provides guidance and resources for election officials to secure systems such as voter registration databases and voting machines
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek .
Doubts grow over claims OpenAI agent hacked Australian Medicare portal
Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]
The SOC Doesn't Need to Start Over with Every Alert
Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading,
On Anthropic’s AI Misuse Report
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings. A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.
Don't let TEEs break your MPC
<p>Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs). The combination is intended to amplify security for sensitive computations: MPC distributes trust across multiple independent parties, while TEEs root trust in the hardware m
AI breach puts cyber insurance notification rules under scrutiny
Roxanne Libatique writes: An OpenAI agent accessed Australian government health data in June 2026. The government was not told until September. That gap – nearly three months between breach and disclosure – is not just a political problem. It is a cyber insurance problem, and one that brokers with public sector and health sector clients... Source
Windows, Linux, Android File Notification Systems Leak User Activity
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events. The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek .
Bluwhale announces trading agents for tokenised stocks and real-world assets
Bluwhale, the AI financial operating system connecting millions of users to traditional and blockchain financial services managed by AI, today announced trading agents for tokenized stocks and real-world assets, including gold, silver and oil. The broader tokenized-stock market already includes instruments linked to widely held companies such as Apple, Microsoft and Tesla, although availability va
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain
Microsoft: Recent Windows updates cause desktop loading issues
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]
DIVD Dutch Institute for Vulnerability Disclosure investigating agentic AI-powered attack
A Dutch non-profit that has helped so many over the years has discovered it become the victim of what appears to be an agentic AI-powered attack. DIVD, the Dutch Institute for Vulnerability Disclosure, announced the attack on LinkedIn. Consistent with their ethics and history, they didn’t try to minimize the problem: Security people always say... Source
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash
Online scams agreement signed between UK and Cambodian governments
The UK and Cambodia will work together to tackle networks of illegal scam centres, locations where sophisticated fraud techniques are deployed and scaled to target thousands of victims.
Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems
Notification letters are being mailed to individuals affected by data breaches at the pharmacy benefit management service provider MedImpact Healthcare […] The post Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems appeared first on The HIPAA Journal .
Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits
Settlements have been agreed to resolve class action complaints against Wayne Memorial Hospital in Georgia and Regional Urology in Louisiana […] The post Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits appeared first on The HIPAA Journal .
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
The newly-discovered trojan abuses the Android Accessibility Service to gain control over victim devices and collect sensitive banking credentials
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration appeared first on SecurityWeek .
Is that vibe coded app safe? 5 checks before you download
As AI lets anyone build software, here’s how to vet that shiny new app before it exposes your data
Nature-related financing and assessments increases worldwide - TNFD
Financial institutions have increased nature-related assessments and reporting across markets in the last year according to a Taskforce for Nature-related Financial Disclosures (TNFD) report.
Hackers steal $351.6 million in Bitget crypto exchange hack
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]
Researchers Identify AliExpress Phishing Domains Before Registration
EfficientIP says it flagged AliExpress phishing domains before they were registered
Fixing Flock: The controls needed now that misuse patterns are clear
Flock Safety has stirred widespread debate of late. Flock builds interconnected networks of automated license-plate readers and other public safety cameras. Those systems can help police solve serious crimes, but they also log sensitive personal location data and make it searchable across agencies and jurisdictions. The question is no longer whether the technology has value. It is what controls Fl
NVD HIGH: CVE-2026-95866 — The User Profile Builder – Beautiful User Registration Forms, User Profiles & Us...
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenev
NVD HIGH: CVE-2026-95864 — The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required to reach
NVD HIGH: CVE-2026-93901 — The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalatio...
The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp_ajax_nopriv_ihf_clear_cache` AJAX action — through the call chain `iHomefinderAjaxHandler::clearCache()` → `activateAuthenticationToken()` → `getAuthenticationInf
NVD HIGH: CVE-2026-93654 — The Premium Packages – Sell Digital Products Securely plugin for WordPress is vu...
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acces
NVD HIGH: CVE-2026-92713 — The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vu...
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server. The path restriction to wp-content/uploa
NVD HIGH: CVE-2026-89426 — The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPre...
The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the target role directly from an attacker-controlled Gravity Forms entry field — configured via the feed's `user_role_field_id` — and passing it to `WP_User::set_role()`
NVD HIGH: CVE-2026-89406 — The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vu...
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via get_post( $_GET['modula_gallery_id'] ) without verifying the gallery's post_status o
NVD HIGH: CVE-2026-84280 — The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Si...
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
NVD HIGH: CVE-2026-19804 — The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywa...
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_name' parameter parameter. This is due to insufficient sanitization of the first_name parameter via esc_refs(), which strips only regex backreferences and not PHP tag
NVD HIGH: CVE-2026-13456 — The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory &...
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the executio
NVD HIGH: CVE-2026-96039 — The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site S...
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacke
NVD CRITICAL: CVE-2026-93399 — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Referenc...
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the attacker-controlled 'order_id' from the submitted form_data into a new booking session,
NVD HIGH: CVE-2026-93303 — The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPres...
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume in all versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will
NVD CRITICAL: CVE-2026-89055 — The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to autho...
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product
NVD HIGH: CVE-2026-84281 — The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Si...
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page
NVD HIGH: CVE-2026-84279 — The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Si...
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires
NVD HIGH: CVE-2026-83591 — The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to ...
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all versions up to, and including, 1.1.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in
NVD CRITICAL: CVE-2026-14281 — The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Co...
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which
Russia's Hybrid Cyber-Physical War in Europe Heats Up
A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide material support to Ukraine.
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)
[object Object]
NVD HIGH: CVE-2026-97646 — A weakness has been identified in ningzichun student-management-system up to 987...
A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes authorization bypass. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project
Swift and Wells Fargo join Linux Foundation Decentralized Trust
Swift and Wells Fargo are among the latest members to join the Linux Foundation Decentralized Trust.
FedNow to enable cross-border payments
The US Federal Reserve is pushing ahead with plans to enable participants in its FedNow real-time payments system to make cross-border transfers.
BNP Paribas forges agentic AI partnership with Google Cloud
BNP Paribas has inked a five-year to expand its access to Google Cloud’s infrastructure and AI capabilities, including Gemini Enterprise and Gemini models.
CISA KEV: MikroTik RouterOS — Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
CISA KEV: Microsoft SharePoint — Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
CISA KEV: WordPress Core — WordPress Core Remote File Inclusion Vulnerability
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it. The post House and Senate members propose legislation for CISA to step up cyber defenses for biotech appeared first on CyberScoop .
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden. The post Autonomous AI Hacks Raise Thorny Questions of Legal Accountability appeared first on SecurityWeek .
SectopRAT Returns, Hiding Inside a Legitimate Application
The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.
Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges
Two executives at a data extraction and digital forensics company that sold several U.S. agencies its software were arrested for allegedly lying about the fact that its technology is made in Russia.
WordPress patches a critical severity security vulnerability
WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild. Given its popularity, WordPress has frequently been under attack , and patched another maximum severity bug allowing RCE in July. WordPress said the current hole, tra
CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018
[object Object]
NVD HIGH: CVE-2026-97326 — A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4b...
A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the
NVD HIGH: CVE-2026-97324 — A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026....
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated
NVD HIGH: CVE-2026-93354 — Taskview Community before 1.56.0 contains a missing authentication vulnerability...
Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and cl
Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks
U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S.
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]
Revolut customers impacted by new data breach
Revolut has found itself embroiled in a second data breach in a matter of days after some its customers were impacted by a security incident at US broker DriveWealth.
New York sues Polymarket for 'illegal gambling operation'
New York State has filed a lawsuit against Polymarket, alleging that the prediction market is running an "illegal gambling operation".
Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illicit platform used by cybercriminals to sell stolen personal information, illegal access to devices and other tools for carrying out fraud.
Tax compliance platform Numeral raises $100m
Numeral, the AI-powered sales tax compliance platform, today announced a $100 million Series C led by Insight Partners, with participation from Salesforce Ventures, Geodesic, Benchmark, Mayfield, FCVC, Y Combinator and Uncork.
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not
New bill would create federal investigative body for AI-driven hacks
A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI agents, following recent hacks by models run at companies like Anthropic, OpenAI, Meta and others. The bill, introduced by Sen. Ed Markey, D-Mass., would attempt to establish a […] The post New bill would create
Trust and the enticing consultancy offer
In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]
Stevens Point servers go offline, city officials not sure if caused by a cyberattack
Brandi Makuski reports: Stevens Point officials are investigating a possible cyberattack after several city computer servers went offline early Wednesday, disrupting municipal phone and email services and leaving employees unable to access some city systems. District 4 Councilwoman Andrea Olson said city IT employees notified staff and council members of a cyberattack in a 6:51... Source
Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to Cybercriminals
From the DOJ: Ardit Kutleshi, 28, a Kosovar national, pleaded guilty to charges related to his creation and operation of Rydox, an illicit website and marketplace for cybercriminals to buy, sell and trade stolen personal information, and to access devices and other tools for carrying out cybercrime and fraud. “The guilty plea of Ardit Kutleshi... Source
NVD HIGH: CVE-2026-97231 — A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is ...
A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missing authentication. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD HIGH: CVE-2026-63493 — Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-au...
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced in the web middleware group but not the API middleware group. The advisory states that the resulting persistent API token
NVD HIGH: CVE-2026-62368 — Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with t...
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session.
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
The Justice Department said two leaders of the company have been arrested and face conspiracy to commit wire fraud. The post Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges appeared first on CyberScoop .
Two Maryland hospitals still dealing with system issues after cyberattack
On September 22, WYPR reported: Luminis Health says it’s making considerable progress on restoring systems at two Maryland hospitals after they were hit by a cyberattack earlier this month. The company said in an online update that its telephone capabilities at Anne Arundel Medical Center and Doctors Community Medical Center in Lanham have been restored... Source
Wyoming courts investigate extent of personal data exposed in cybersecurity breach
Maggie Mullen reports: The Wyoming Judicial Branch says it’s awaiting more details regarding the scope of a cybersecurity breach of a third-party software company that may have included a decade’s worth of data from the state’s court system. West Publishing Corporation, which the Wyoming Supreme Court and Wyoming district courts previously used for case management,... Source
Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more
Kudos to WBTV for following up on an astute observer’s vulnerability report. David Hodges reports: North Carolina residents summoned for jury duty received notice through a letter in the mail but to request an exemption from jury duty in North Carolina, a person can go online and fill out a jury excuse form. Zach Duda... Source
Cleverbridge completes France's first Passkey-authenticated agentic purchase, on a Revolut card
Cleverbridge, a managed global commerce platform for software and technology companies, today announced that it completed France's first Passkey-authenticated agentic payment in a live checkout, in a pilot with Visa and Revolut announced earlier this month.
Citi and HSBC back IPID Series A
IPID, the payment intelligence company that helps institutions know who they are paying, has secured investment from Citi and HSBC as part of a $16 million Series A funding round.
Microsoft integrates SOC capabilities with Defender for enterprises
Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost. Microsoft is delivering the capability through the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with Defender’s existing XDR, threat intelligence, automation and AI tools in a single portal. “Security cannot op
AI communications app Ando raises $20 million
Ando, a new messaging platform built for teams working alongside AI agents, today announced $20 million in funding from Accel, Index Ventures and Emergence Capital.
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions. The post Kontext Security Emerges With $4 Million for AI Agent Runtime Controls appeared first on SecurityWeek .
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com
NVD HIGH: CVE-2026-97362 — HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that a...
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the ser
NVD HIGH: CVE-2026-90959 — A path traversal vulnerability was found in pulpcore. The content upload API acc...
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double sl
NVD HIGH: CVE-2026-82094 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
NVD HIGH: CVE-2026-82093 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.
NVD HIGH: CVE-2026-81552 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.
NVD CRITICAL: CVE-2026-81549 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.
NVD HIGH: CVE-2026-81548 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-81547 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.
NVD HIGH: CVE-2026-81545 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-81539 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-77874 — IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3....
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Narmi open AI marketplace for community banks
Narmi, a leading provider of digital banking technology, today announced the launch of the Narmi AI Marketplace, a centralized destination for practical and innovative AI capabilities built for community financial institutions.
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims
3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information. The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data appeared first on SecurityWeek .
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the
IBM integrates digital asset platform with Swift shared ledger
IBM is now letting its digital asset platform clients connect to permissioned blockchain networks, including Swift’s shared ledger.
NVD CRITICAL: CVE-2026-97360 — HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access...
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to
NVD CRITICAL: CVE-2026-97359 — HFS2 version 2.4.0 and earlier contains a template injection vulnerability in th...
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to exe
NVD HIGH: CVE-2026-97059 — DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoad...
DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declaring more frames than the buffer contains to trigger heap over-reads that crash the application or leak adjacent heap memory.
NVD HIGH: CVE-2026-97057 — redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP...
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.
NVD HIGH: CVE-2026-95521 — A command injection flaw was found in rpm. Installing or rebuilding a source RPM...
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an
NVD HIGH: CVE-2026-95519 — A flaw was found in rpm. An attacker can supply a crafted manifest file that, wh...
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitat
How to Build A SASE Framework for Modern Cybersecurity
Keeping edge computing safe requires organizations to fundamentally rethink security governance. Here is a path forward: a step-by-step guide to building a SASE framework.
FedRAMP VDR & VER: Daily Scans Are Only the Beginning
FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]
The Clearing House taps Quant for tokenised deposit network
The Clearing House has picked UK-based programmable money infrastructure provider Quant to power a new interoperable payments network that will enable US financial institutions of all sizes to clear and settle tokenised deposit transactions.
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chairman Ted Cruz, R-Tex., would create a government-industry group to write voluntary best practices. The post Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks appeared first on CyberScoop .
Community banks and credit unions back Crux Analytics to the tune of $2.2 million
Crux Analytics, the fintech fixing the relationship between financial services companies and the small businesses they serve, has raised $2.2 million in seed funding to help institutions engage, acquire and retain high-potential business relationships, bringing its total funding to $3.2 million.
On-prem VeloCloud Orchestrator under attack, only some versions patched
A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls. Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access “privileged internal functionali
Ghost Service Accounts Enable M365 Data Theft in Chile
Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization's entire M365 environment.
Kyiv internet providers report major outages after Russian attacks damage data centers
At least four internet providers serving Kyiv and other parts of Ukraine suffered partial connectivity losses following Wednesday’s drone attack, according to internet monitoring group NetBlocks.
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]
NVD HIGH: CVE-2026-97182 — A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1....
A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the component SpEL Handler. Such manipulation leads to improper neutralization. The attack may be performed from remote. The exploit has been disclosed publicly and may be used
NVD HIGH: CVE-2026-88907 — Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authenti...
Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakPDF: through 09092026.
Astrana latest healthcare tech firm to report data breach to SEC
The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel.
Solaris goes live on ACI Worldwide platform for Sepa instant payments
ACI Worldwide (NASDAQ: ACIW), an original innovator in global payments technology, today announced that Solaris, Europe’s leading embedded finance platform, has gone live on schedule on ACI Connetic, ACI’s unified cloud-native platform for intelligent payments orchestration.
Sports prediction market Underdog rolls out Eventus surveillance tech
Eventus, a leading provider of comprehensive, at-scale trade surveillance and financial risk solutions, and Underdog, the sports prediction market and fantasy sports pioneer, today announced that Underdog is using the Eventus Validus platform for trade surveillance on its designated contract market (DCM).
Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage.
When Business Email Compromise Starts Rewriting Reality
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details a
CVS Health; Criteo Agree to Pay $20.5 Million to Resolve Website Tracking Litigation
Settlements have been agreed to resolve class action litigation against CVS Health & Criteo and American Wellness Corp. The lawsuits […] The post CVS Health; Criteo Agree to Pay $20.5 Million to Resolve Website Tracking Litigation appeared first on The HIPAA Journal .
CVS Health; Criteo Agree to Pay Combined $20.5 Million to Resolve Website Tracking Litigation
Settlements have been agreed to resolve class action litigation against CVS Health & Criteo and American Wellness Corp. The lawsuits […] The post CVS Health; Criteo Agree to Pay Combined $20.5 Million to Resolve Website Tracking Litigation appeared first on The HIPAA Journal .
CISA Charts New "Quality Era" for Global CVE Program
CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise
AI-Powered Campaign Targets Hundreds of Online Retailers
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration. The post AI-Powered Campaign Targets Hundreds of Online Retailers appeared first on SecurityWeek .
Ukrainian ransomware developer jailed for nearly 13 years
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world. Read more in my article on the Hot for Security blog.
OpenAI agent breached Australian government health website, Albanese says
An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said.
Windows 11 KB5124010 update released with 46 changes and fixes
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]
Kredete acquires Gravv to build stablecoin infrastructure
Kredete, the financial technology platform serving emerging-market and diaspora communities, today announced its acquisition of Gravv, an agentic stablecoin infrastructure platform that connects banks, blockchain networks, and local payment rails for real-time global money movement.
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM
Eufy Omni C20, Omni X10 Pro
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code.</strong></p> <p>The following versions of Eufy Omni C20, Omni X10 Pro are affected:</p> <ul> <li>Omni C20
Siemens Mendix Runtime (Update A)
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.</strong></p> <p>The following versions of Siemens Mendix Runtime are affected:<
Botslab G980H Dashcams
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device op
Data Breaches Announced by Gastroenterology Practice and Hospice Companies
Data breaches have been announced by Gastroenterology & Hepatology of Central New York, Three Oaks Hospice, and Doctor’s Choice Home […] The post Data Breaches Announced by Gastroenterology Practice and Hospice Companies appeared first on The HIPAA Journal .
Island Raises $400 Million at $6.4 Billion Valuation
The enterprise security firm has raised more than $1 billion since its launch in 2020; Evolution Equity Partners led the latest funding round. The post Island Raises $400 Million at $6.4 Billion Valuation appeared first on SecurityWeek .
Malicious npm Packages That Evade Defenses
This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
Revision 4 of NIST’s operational technology security guide is open for public comments until November 30. The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek .
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy
Begin at the End: How to Enable Agentic Remediation
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. The post Begin at the End: How to Enable Agentic Remediation appeared first on SecurityWeek .
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI
CISA: Ransomware gangs now exploiting critical TeamCity flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication. The post SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted appeared first on SecurityWeek .
Ripjar ramps up AI in customer screening to disrupt global economy of crime
Ripjar, the provider of smarter screening and risk intelligence solutions, has introduced new AI innovations within ULTRA, the real intelligence engine that powers screening operations at financial institutions and enterprises, including 25% of the Global Systemically Important Banks and 35+ of the Global Fortune 500.
MindBridge advances financial oversight for the Agentic era
MindBridge Analytics Inc. announced the next evolution of its platform and unveiled new capabilities designed to strengthen financial oversight as AI and automation take on more work across finance and audit.
NVD CRITICAL: CVE-2026-12227 — The Visual Composer Website Builder plugin for WordPress is vulnerable to Local ...
The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive da
Asic strengthens AI safeguards
ASIC is strengthening safeguards for automated and AI-enabled trading while streamlining regulatory requirements for securities and futures market participants under incoming changes to its Market Integrity Rules (MIRs).
OpenAI Agent Hacks Australian Medicare Portal
Australian PM Anthony Albanese criticized OpenAI’s response to the incident, which occurred in June 2026
Iress joins the ASX Australian Liquidity Centre
Iress is joining the ASX Australian Liquidity Centre (ALC), the exchange-operated data centre that serves as the core connectivity hub for Australia’s financial markets ecosystem.
CMC Markets arrives on ChatGPT
CMC Markets ("CMC"), a FTSE 250 company and global multi-asset financial services firm, is launching a new ChatGPT integration, enabling UK CFD clients to access and explore supported account and market information through conversational prompts.
Pine Labs to roll out soundboxes to rural India to drive digital payments
As digital payments move beyond small ticket transactions, Pine Labs today announced a strategic investment to deploy 10 lakh Soundboxes across India.
KB Securities signs MoU with Securitize
KB Securities announced today that they’ve signed an MOU with Securitize and Optimism to bring tokenized securities to institutional investors in Korea.
Oman unveils national Fintech Strategy
The Central Bank of Oman (CBO), in strategic partnership with the Financial Services Authority (FSA) and the National Programme for Fiscal Sustainability and Financial Sector Development “Estidama" under the Ministry of Finance, today launched the National FinTech Strategy and the Oman FinTech Gate - two landmark national initiatives designed to accelerate responsible financial innovation, attract
MacSync under the microscope: new delivery methods and a new payload
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
The New Engineering Problem: Managing What AI Decides to Import
<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/the-new-engineering-problem-managing-what-ai-decides-to-import" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/Dependencies.png" alt="Image with a square at center containing two gear icons" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15p
How tax policy can stop threat actors from breaching US water systems
New federal programs take years to launch and fund. State and local governments need cybersecurity software now. The One Big Beautiful Bill already enables tax incentives. Congress should clarify and deploy them. The post How tax policy can stop threat actors from breaching US water systems appeared first on CyberScoop .
Financial crime compliance fintech Footprint raises $25 million
Footprint, the AI operating system for risk, today announced it has raised $25 million in Series B funding led by QED Investors, with participation from MUFG, Commerce Ventures, LightBank, and Alumni Ventures, and continued backing from existing investors Index Ventures, Lerer Hippeau, BoxGroup, Operator Partners, and Animal Capital.
Astrana Health Data Breach Impacts Private, Confidential Information
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek .
Oculus Pathology Notifies 20,000 Patients About April 2026 Security Incident
Texas-based Oculus Pathology has disclosed a data breach affecting more than 20,000 patients. Data breaches have also been announced by […] The post Oculus Pathology Notifies 20,000 Patients About April 2026 Security Incident appeared first on The HIPAA Journal .
Amazon introduces CloudWatch Omni console to track and remediate agent behaviour
Today, Amazon CloudWatch introduces CloudWatch Omni, a unified observability experience for application and AI workloads that is app-centric, AI-powered, built on open standards, and delivered off-console.
OpenAI hacked Australian Medicare govt site, probed data providers
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]
UK banks pilot tokenised deposit transactions
UK banks have collaborated to complete the first live customer transactions using tokenised sterling deposits.
Over 75% of Organizations Experience Microsoft 365 Governance Issues
ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows
NVD HIGH: CVE-2026-85682 — The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in al...
The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email a
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read
Revolut trials Pay with Smile
Revolut customers can now pay for coffee with their face at three Kiss the Hippo cafés in Bloomsbury, Chelsea and Soho.
Ebanx expands to Pakistan
At its annual Payments Summit, EBANX, a global technology company specialising in payment services for emerging markets, unveiled a new wave of product launches and geographic roadmap expansions, doubling down on its drive to solve payment complexity and unlock merchant growth.
Silverflow connects to Hypergate
Cloud-native payment processing company Silverflow and payment gateway provider Hypergate have partnered to deliver an integrated payment infrastructure offering, aimed at acquirers, payment providers and modern financial institutions.
Aviation solved the vigilance problem. AI just gave security a worse one
An air traffic controller watching a busy scope will, sooner or later, miss the one aircraft that matters. Sustained attention decays under load, a limit aviation named the vigilance decrement and has spent seventy years designing around. AI has moved every knowledge worker into that chair. You now work a dozen aircraft at once: six open conversations, an agent drafting in the background, three mo
Been told to pay at a Bitcoin ATM? Read this first
Crypto ATM scams often follow a predictable script – here’s how to recognize it and what to do if you’ve already been caught out
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek .
Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds
SANS Institute report claims data rather than skills is now the main hurdle for threat hunters
58 hardware vulnerabilities: A guide to the threats
In January 2018, the entire computer industry was put on alert by two new processor vulnerabilities dubbed Meltdown and Spectre that defeated the fundamental OS security boundaries separating kernel and user space memory. The flaws stemmed from a performance feature of modern CPUs known as speculative execution and mitigating them required one of the biggest patch coordination efforts in history,
Microsoft fixes bug that broke Windows File History backup feature
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek .
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –
One URL, Three Different Tricks, (Thu, Sep 24th)
Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file
NVD HIGH: CVE-2026-96898 — A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this v...
A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type results in path traversal. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early
Your Vulnerability Backlog Is No Longer Technical Debt, It’s an Attack Surface
A growing vulnerability backlog is more than technical debt: it is an attack surface. Learn why outdated risk assumptions, automated attackers, and chained findings demand a new approach.
NVD CRITICAL: CVE-2026-96891 — A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the functi...
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely.
NVD CRITICAL: CVE-2026-18467 — The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable...
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(), registered on the pt_meta_values hook after the signed builder — that copies every $_POST['pt_for
Check Point hacked: The security software protecting your network has become a prime attack target
A firewall is supposed to be the barrier between attackers and the enterprise network, but that barrier can itself become a threat actors’ tool. Check Point has revealed that attackers are actively exploiting two vulnerabilities in its Security Gateway and Security Management products. The security software provider has warned that attackers are targeting CVE-2026-85102 , a remote code execution (
CISA outlines improvement plan for CVE program
The white paper is the latest step in trying to create a “Quality Era” for the Common Vulnerabilities and Exposures (CVE) program as the number of CVEs surges. The post CISA outlines improvement plan for CVE program appeared first on CyberScoop .
NVD HIGH: CVE-2026-96762 — A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1....
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosur
NVD HIGH: CVE-2026-96751 — A vulnerability has been found in pmTicket Project-Management-Software up to 078...
A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are
Trustly slashes 200 jobs
Swedish open banking outfit Trustly is cutting a quarter of its staff as part of an effort to cut costs and prioritise profitable growth markets.
Former Visa crypto lead launches open payments network
Atum, an open payments network founded by former Visa crypto product team lead Pete Cooling, has emerged from stealth with $13.5 million in funding.
MyComplianceOffice lands over $100m strategic investment
MyComplianceOffice (MCO), a provider of compliance management software for the financial services industry, has secured over $100 million in strategic growth financing from Accel-KKR Credit Partners.
CISA KEV: WSO2 Multiple Products — WSO2 Multiple Products Path Traversal Vulnerability
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
CISA KEV: Adobe Commerce and Magento — Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
FBI Hack Exposed FBI’s Own Hacking Unit
Joseph Cox reports: The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found. The findings further highlight how sensitive the stolen data is, and... Source
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs
[object Object]
NVD HIGH: CVE-2026-70125 — Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
Placeholder domain used in dev docs now serves ClickFix attacks
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]
SASE Converges Network & Security Into One Cloud Solution
Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls.
NVD HIGH: CVE-2026-96604 — A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. Thi...
A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did n
NVD HIGH: CVE-2026-96603 — A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the...
A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release syst
NVD HIGH: CVE-2026-96602 — A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown ...
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continu
NVD HIGH: CVE-2026-96601 — A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an u...
A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version informati
NVD CRITICAL: CVE-2026-93352 — Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49...
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file tha
NVD HIGH: CVE-2026-86583 — The Import and export users and customers plugin for WordPress is vulnerable to ...
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with o
NVD HIGH: CVE-2026-81537 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.
NVD HIGH: CVE-2026-81536 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
NVD HIGH: CVE-2026-81208 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.
NVD HIGH: CVE-2026-80423 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.
NVD HIGH: CVE-2026-75887 — A flaw was found in the OpenShift console. An unauthenticated attacker can explo...
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against
NVD HIGH: CVE-2026-19125 — The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication B...
The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executi
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]
NVD HIGH: CVE-2026-96556 — A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerabil...
A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role/status can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not res
NVD HIGH: CVE-2026-80425 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-80412 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.
NVD HIGH: CVE-2026-80379 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-75886 — A flaw was found in openshift/console. An unauthenticated remote attacker can ex...
A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send requests to the in-cluster catalogd service, leading to the disclosure of the internal operator-catalog index and providing a relay into the op
NVD HIGH: CVE-2026-6935 — IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully ...
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
NVD CRITICAL: CVE-2026-6928 — IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been ...
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.
NVD HIGH: CVE-2026-6794 — IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due ...
IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.
NVD CRITICAL: CVE-2026-6730 — IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by im...
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
NVD CRITICAL: CVE-2026-6721 — IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can su...
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.
EDR Evasion Stack Helps Process Injection Slip Past Defenses
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
Canva hacked via vendor’s Salesforce instance; Other customers affected as well
A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked... Source
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
F5 fixes actively exploited zero-day flaw in BIG-IP APM
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available. BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control
CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch
[object Object]
NVD HIGH: CVE-2026-96889 — A flaw was found in librsvg. When processing an SVG document containing nested X...
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
NVD HIGH: CVE-2026-85475 — A flaw was found in the Ansible Automation Platform automation controller. The e...
A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE — into an rsyslog RainerScript config file without neutralizing RainerScript syntax. A privileged (superuser) user can injec
NVD CRITICAL: CVE-2026-84719 — A flaw was found in the Ansible Automation Platform automation-controller. When ...
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permiss
NVD HIGH: CVE-2026-84714 — A flaw was found in the automation-controller input-validation ...
A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accep
NVD HIGH: CVE-2026-84706 — A flaw was found in Ansible Automation Platform's automation-controller. The cus...
A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file inj
NVD HIGH: CVE-2026-84691 — A flaw was found in Red Hat Ansible Automation Platform's automation- controller...
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that w
NVD HIGH: CVE-2026-84683 — A flaw was found in Red Hat Ansible Automation Platform's automation- controller...
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the output is expanded into an HTML anchor whose href is not scheme- filtered or esca
NVD CRITICAL: CVE-2026-75884 — A flaw was found in AWX. The container group pod_spec_override field uses an inc...
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.