Technology Intelligence
Threats against technology companies, software vendors, cloud services, and tech infrastructure.
Westpac to reshape software engineering with Amp Frontier Corporation
Westpac has contracted with San Franciscop-based Amp Frontier Corporation to build a suite of AI agents for software engineering tasks.
Stablecoins offer little cost or speed advantage for remittances - Banca d'Italia
Stablecoins show no systematic cost advantage over traditional remittance channels for cross-border payments, researchers at Banca d'Italia have found.
Mobile wallets gain traction in the UK
Cards continue to dominate UK payments but mobile wallets are increasingly popular, with nearly two thirds of the population registered with at least one provider, according to the latest industry data.
China-Linked APT Uses AI to Optimize Hand-Built Malware
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/china-linked-apt-uses-ai-to-optimize-hand-built-malware-image_small-4-a-32597.jpg" align=right hspace=4><b>SilkParasite Deployed Against Central Asian Governments</b><br>Bitdefender said the China-linked SilkParasite espionage campaign deployed seven modular RATs against Central Asian governments, with coding artifacts indicating
CISA Weighs Outsourcing Its Cyber Software Buying
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cisa-weighs-outsourcing-its-cyber-software-buying-image_small-9-a-32595.jpg" align=right hspace=4><b>CISA Issues Sources Sought Notice Floating $600M a Year, $6B Over Contract Life</b><br>The U.S. Cybersecurity and Infrastructure Security Agency is surveying industry on whether a contractor could take over cybersecurity software b
Perplexity Builds Guardrails to Rein in Rogue AI Agents
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/perplexity-builds-guardrails-to-rein-in-rogue-ai-agents-image_small-9-a-32596.jpg" align=right hspace=4><b>Open-Source Numbat Blocks Agent Actions That Violate Enterprise Security Policies</b><br>Perplexity designed its open-source tool Numbat tool to detect and block AI agents from stepping outside enterprise safety policies. The
FDA Weighing Possible Regs for GenAI Medical Devices
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/fda-weighing-possible-regs-for-generative-ai-medical-devices-image_small-6-a-32593.jpg" align=right hspace=4><b>Agency Seeks Public Input on Risk-Based Oversight Approach Across Product Life Cycle</b><br>The U.S. Food and Drug Administration is seeking public feedback on the varying risks and other considerations involving generat
When AI Risk Becomes a Board Liability
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/when-ai-risk-becomes-board-liability-image_small-9-a-32594.jpg" align=right hspace=4><b>CIOs Can Strengthen Oversight Through Reporting, Records and Insurance Reviews</b><br>AI failures can trigger financial, regulatory and reputational exposure that reaches the boardroom. Reed Smith partners Carolyn Rosenberg and Andy Moss explai
'Living Off the Plant' OT Attacks Pose Physical Safety Risk
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/living-off-plant-ot-attacks-pose-physical-safety-risk-image_small-5-a-32591.jpg" align=right hspace=4><b>Beware Abuse of Native OT Functionality, Says Orange Cyberdefense's Ric Derbyshire</b><br>Attackers can employ "living off the plant" tactics to stealthily access and move laterally inside industrial networks, abusing native fu
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.
NVD CRITICAL: CVE-2026-60995 — Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion ...
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may s
NVD CRITICAL: CVE-2026-60990 — Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion ...
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may s
NVD CRITICAL: CVE-2026-60977 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware ...
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracl
NVD CRITICAL: CVE-2026-60971 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio...
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in take
NVD CRITICAL: CVE-2026-60970 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio...
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in take
NVD CRITICAL: CVE-2026-60958 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio...
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover
NVD CRITICAL: CVE-2026-60947 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio...
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover
NVD CRITICAL: CVE-2026-60946 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio...
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover
NVD CRITICAL: CVE-2026-60921 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio...
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in take
NVD CRITICAL: CVE-2026-60916 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio...
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Captu
NVD CRITICAL: CVE-2026-60905 — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middlewar...
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker a
NVD CRITICAL: CVE-2026-60861 — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middlewa...
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may signi
NVD CRITICAL: CVE-2026-60858 — Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyper...
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calcu
NVD CRITICAL: CVE-2026-60821 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS...
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterpri
NVD CRITICAL: CVE-2026-60782 — Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone...
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Con
NVD CRITICAL: CVE-2026-60754 — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (compo...
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to
NVD CRITICAL: CVE-2026-60737 — Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middle...
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in unauthorized cr
NVD CRITICAL: CVE-2026-60730 — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware...
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact addit
NVD CRITICAL: CVE-2026-60728 — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware...
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to criti
NVD CRITICAL: CVE-2026-60727 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware...
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Mana
NVD CRITICAL: CVE-2026-60721 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware...
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Mana
NVD CRITICAL: CVE-2026-60720 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware...
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact
NVD CRITICAL: CVE-2026-60702 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware ...
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may signi
NVD CRITICAL: CVE-2026-60698 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware ...
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle
NVD CRITICAL: CVE-2026-60696 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware ...
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Ora
NVD CRITICAL: CVE-2026-60672 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware ...
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Ora
NVD CRITICAL: CVE-2026-60591 — Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beve...
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in una
Fortinet Buys Virtue AI for Agent and Model Runtime Controls
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/fortinet-buys-virtue-ai-for-agent-model-runtime-controls-image_small-8-a-32592.jpg" align=right hspace=4><b>Acquisition Adds Offensive and Defensive Testing for Agents and Models</b><br>Fortinet acquired Virtue AI's technology to extend FortiAIGate with red- and blue-team testing, runtime controls and policy enforcement for AI age
NVD CRITICAL: CVE-2026-75877 — A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affec...
A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.
Comcast turns your Xfinity WiFi into a home motion detector
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]
Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute
The superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others. The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop .
Crypto firm MoonPay adds CashApp Pay as payment method
MoonPay has become the first and only platform to offer Cash App Pay as a payment method for digital asset purchases. Eligible US customers can now use their Cash App balance to purchase digital assets on MoonPay and through select partners across its network.*
PicPay rolls out ChatGPT integration
PicPay (NASDAQ: PICS), one of Brazil’s largest digital banks, today announced that it has introduced a first-of-its-kind integration with ChatGPT that enables customers to access financial information through generative AI.
Personetics partners Plaid to bring open finance intel to FIs
Personetics, the AI Cognitive Banking Platform, today announced a partnership with Plaid, the data network powering the digital financial ecosystem.
Critical GitLab flaw allows attackers to delete and modify public repos
GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF) flaw. The critical vulnerability, tracked as CVE-2026-19478 , is described as a code injection issue through
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42 .
CISOs Break Their Silence in 'Declassified' Docuseries
Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.
CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
<p><b>Bulletin ID:</b> 2026-082-AWS<br> <b>Scope:</b> AWS<br> <b>Content Type:</b> Important (requires attention)<br> <b>Publication Date:</b> 08/18/2026 10:00 AM PDT</p> <p><b>Description:</b></p> <p>OpenSearch Dashboards is the open-source visualization and management UI for OpenSearch, and ships as part of Amazon OpenSearch Service. We identified CVE-2026-75897, an improper input validation in
NVD CRITICAL: CVE-2026-75625 — Kraken agents fail to verify peer-to-peer downloaded blobs against their request...
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32 corrections that passes per-piece checks, poisoning the cache with attacker-chosen containe
NVD CRITICAL: CVE-2026-75130 — Context7 through 2.1.2 contains a prompt injection vulnerability that allows att...
Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destru
NVD CRITICAL: CVE-2026-66780 — A flaw was found in the submariner-operator component. The `submariner-k8s-broke...
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (
CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing [
More than 200 victims of Medusa ransomware identified over the last year, CISA says
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.
Noggin HQ raises £2.3m and secures credit referencing authorisation
British alternative credit scoring technology startup Noggin HQ has raised £2.3 million in an oversubscribed seed round.
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward. The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop .
NVD CRITICAL: CVE-2026-18963 — A flaw was found in the reset-credentials flow of the keycloak-services componen...
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research
Berlin cuts two state ministries off government network after security breach
The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution.
University of Texas forced to take systems offline in San Antonio after cyberattack
The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.
NVD CRITICAL: CVE-2026-75913 — CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an...
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an at
NVD CRITICAL: CVE-2026-12564 — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The ...
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation pri
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
TMX complete acquisition of Rafi Indices
TMX Group Limited (TMX Group) today announced it has completed the acquisition of RAFI Indices, LLC (RAFI Indices) from Research Affiliates Global Holdings, LLC (Research Affiliates), a global index provider and investment advisor. The transaction was announced in June 2026.
NVD CRITICAL: CVE-2026-75784 — A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this ...
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
NVD HIGH: CVE-2026-66046 — Expat through 2.8.3 contains a denial of service vulnerability caused by quadrat...
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes
Visa and Mastercard back new Agentic Payments Alliance
Visa, Mastercard, Fiserv, Circle, Solana, and Remitly have joined the Agentic Payments Alliance (APA), a coalition of organisations working together to help guide the development of AI commerce.
PPRO partners with Blik to enable agentic commerce for local payments in Poland
PPRO is partnering with BLIK to develop agentic commerce capabilities for local payments in Poland, with the aim of connecting BLIK with the emerging agentic ecosystem.
Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds
Hackers target Ukrainian agency managing assets seized from sanctioned Russians
The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.
CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
With no formal training and no career plan, Waisman built a path from Argentina's early hacking scene to leading security at an AI-powered offensive security firm. The post CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW appeared first on SecurityWeek .
NASA Ground Control Software Flaw Enables Unauthenticated Commands
Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers
Citi introduces Custody+
As institutional investors navigate compressed settlement cycles, continuous markets and AI-driven decision making, Citi Investor Services has launched Custody+, a comprehensive suite of near- and real-time solutions to meet always-on industry demand.
Lloyds customers suffer online and mobile outage
Lloyds, Halifax and Bank of Scotland customers reported problems accessing online and mobile services on Tuesday.
Your Controls Block Known Attacks. What About the Behavior?
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. [...]
NVD CRITICAL: CVE-2026-75783 — A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Aff...
A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.
NVD HIGH: CVE-2026-75778 — A vulnerability was identified in code-projects Task Management System 1.0. This...
A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Trading Technologies expands prediction markets and crypto derivatives access
Trading Technologies International, Inc. (TT), a global capital markets technology provider, and Crypto com, global digital asset and financial services platform, today announced TT will support connectivity to OG.com, Crypto.com’s CFTC-regulated exchange and clearinghouse, on the TT® platform.
'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.
AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores. The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first on SecurityWeek .
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence.
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers. The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volu
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file
CVE-2026-6837: Root Command Injection Affecting 18 Zyxel Access Point Models with full firmware emulation guide
[object Object]
Xpander Raises $7.5 Million for AI Management and Governance
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek .
NVD HIGH: CVE-2026-75855 — ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api...
ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configured database directory. Attackers can supply database names containing ../ sequences to create databases at arbitrary filesystem paths or recursively delete director
NVD CRITICAL: CVE-2026-75854 — ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability i...
ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on the server without providing credentials, bypassing all security gates.
NVD CRITICAL: CVE-2026-75852 — ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data comm...
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
NVD CRITICAL: CVE-2026-75851 — ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fa...
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext has no bound user, causing the scripting authorization gate to become a no-op. A user with only read access to a single da
NVD CRITICAL: CVE-2026-75843 — ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC tra...
ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a transaction ID to run unrestricted JavaScript that creates server-wide administrator accounts.
NVD HIGH: CVE-2026-75842 — ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in ...
ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges, exfiltrating sensitive data directly in query responses.
NVD CRITICAL: CVE-2026-75837 — Grav before 2.0.14 fails to guard the access field in the core group blueprint w...
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.
NVD HIGH: CVE-2026-75827 — Grav before 2.0.15 contains an arbitrary file write vulnerability in the Bluepri...
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.
NVD HIGH: CVE-2026-74905 — SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability...
SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeDialer to enforce SSRF protection in SafeMode. The function only checks for loopback, link-local unicast, private, and unspecified addresses and does not recognize IPv6 transition addresses (NAT64 64:ff9b::/96, 6to4 2002::/16, Teredo 2001::/32) that em
Fortinet Acquires AI Security Company Virtue AI
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek .
CISA Malcolm
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-230-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.</strong></p> <p>The following versions of CISA Malcolm are affected:</p> <ul> <li>Malcolm <26.0
Siemens Simcenter Nastran
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-230-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a ma
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a
Cyber Incident Disrupts Student Services at UT San Antonio
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume
NVD CRITICAL: CVE-2026-75627 — Bastillion fails to properly validate request URI paths in its controller dispat...
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
NVD CRITICAL: CVE-2026-75626 — SpiderFoot fails to HTML-escape correlation titles built from external scan data...
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
Financial data startup Quatr raises $18 million
Quartr, the world's leading first-party data layer for institutional finance and AI, today announced it has closed a $18 million funding round, led by existing investor Altos Ventures with participation from new investor SEB (publ.)
Microsoft tests faster Windows File Explorer, new context menu
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
New Malware turns Microsoft cloud into its control center
Security researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see. The Ontinue Cyber Defense Center discovered the implant while investigating an active campaign in July and has since tracked it as TWINLOOT. It was seen using SharePoint Online as a file-based dead
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek .
LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “ CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs “: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However, this
CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
Confluence adds AI-enabled automation to its product suite.
Confluence Technologies, Inc. (“Confluence”), a global leader in regulatory, analytics, and investor communications solutions for the investment management industry, today announced the launch of Confluence POINT, AI-enabled automation that optimizes workflows across its solutions.
American Addiction Centers & Oculus Pathology Disclose Hacking Incidents
Hacking incidents have been announced by American Addiction Centers in Tennessee and Oculus Pathology in Texas. Regional Center of Orange […] The post American Addiction Centers & Oculus Pathology Disclose Hacking Incidents appeared first on The HIPAA Journal .
Securing Software at the Speed of AI: What Four Years of Data Reveal
<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/securing-software-at-the-speed-of-ai-what-four-years-of-data-reveal" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/AI%20ERA%20SOFTWARE%20ASSEMBLY%20BLOG.png" alt="Image with statistics and text regarding AI software assembly" class="hs-featured-image" style="width:auto !important; max
Three-quarters of Ransomware Attacks Target Mid-Market Firms
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit
Would I lie to you? ANZ warns of troubling ‘scam-coaching’ trend
ANZ is warning customers about a troubling rise in 'scam‑coaching' – a tactic where criminals train victims to bypass bank security by giving them scripts, cover stories, and instructions on how to respond to bank staff.
Korea's Jeonbuk Bank to deploy Ripple Payments for cross-border remittances
Ripple, the leading provider of blockchain-based enterprise solutions across traditional and digital finance, today announced a partnership with Jeonbuk Bank, making it the first regional bank in Korea to deploy Ripple Payments for cross-border remittances, bringing near real-time settlement to businesses that have historically relied on transfers taking days to complete.
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
Xceptor extends SaaS offering to Switzerland and Japan
Xceptor, a global leader in data automation for capital markets, today announced it has launched sovereign-grade SaaS in Switzerland and Japan, two of the world’s most demanding markets.
Unlimit granted crypto asset service provider licence
Unlimit, a global financial infrastructure company, today announced that Unlimit Crypto has been granted a Crypto-Asset Service Provider licence by the Cyprus Securities and Exchange Commission under the EU's Markets in Crypto-Assets Regulation (MiCA).
Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform. The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on SecurityWeek .
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line "[Important] Your SafePal Order
What you say during a cyber breach can — and will — be used against you
The first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that doesn’t always age well. Months and sometimes years later, when the dust is settled, CISOs often find out that those early co
Bjoern Doehrer joins FE fundinfo as chief product officer
FE fundinfo has appointed Bjoern Doehrer as Chief Product Officer.
GitLab Patches Critical Code Injection Vulnerability
The security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek .
AI can find zero-days but still can’t reliably write secure code
In recent months, LLMs have gone from flooding open-source projects and bug bounty programs with questionable security reports that wasted developers’ time, to routinely finding zero-day flaws that humans and traditional security audit tools had missed for years — a rapid evolution in cyber capabilities that scares even their own creators . But despite these advances in vulnerability discovery and
UK Legal Regulator Raises AI Misuse Concerns
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
We Reviewed 80,300 Healthcare Review Replies. The HIPAA Risk Was Hiding in Plain Sight
A two-stage review of 4,019 medical and dental practices found an estimated 21,117 public replies that met a conservative patient-information […] The post We Reviewed 80,300 Healthcare Review Replies. The HIPAA Risk Was Hiding in Plain Sight appeared first on The HIPAA Journal .
Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data. The post Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates appeared first on SecurityWeek .
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than
CareCloud Data Breach Affects 3.3 Million Individuals
When we last reported on the CareCloud data breach in early August, it was starting to become clear from breach […] The post CareCloud Data Breach Affects 3.3 Million Individuals appeared first on The HIPAA Journal .
NVD HIGH: CVE-2026-75091 — The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for ...
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
NVD CRITICAL: CVE-2026-15748 — The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload...
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler th
Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14%
A benchmark of secure, functional vulnerability fixes across JavaScript, Java, and Python shows Snyk Intelligence helps frontier models break past a 72–75% performance plateau.
Weekly Update 517: Cyber Ransoms
The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "ware", it's just extortion) is carried out by kids who successfully make a truckload of money but can't spend it without
NVD HIGH: CVE-2026-11801 — The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authori...
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including register
NVD CRITICAL: CVE-2026-75094 — A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_...
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
OpenAI president’s blog pushing agentic AI most notable for what it did not say
OpenAI president Greg Brockman on Sunday warned enterprise CISOs that they need to more aggressively embrace agents if they want to survive upcoming cyberattacks. Brockman said in a blog post that it has become “increasingly clear” that company systems are hiding “significant flaws, and defenders need to find and fix them before attackers do.” He added: “The Hugging Face incident showed that we un
Synchrony unveils ChatGPT plugin
Consumer financial services firm Synchrony is launching a ChatGPT plugin that lets shoppers find savings and offers from the firm's marketplace.
Stripe agrees $7bn takeover of AI firm OpenRouter - Bloomberg
Payments giant Stripe has struck a $7 billion deal to acquire AI gateway keeper OpenRouter, according to Bloomberg.
Clop Claims Data Theft From More Than 40 Companies
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/clop-claims-data-theft-from-more-than-40-companies-image_small-2-a-32581.jpg" align=right hspace=4><b>Victims Are Assessing Claims of Stolen Databases, CAD Files and Backups</b><br>Russia-linked Clop claims it stole databases, engineering files, backups and other sensitive corporate data from more than 40 organizations in a breach
Unleashing Hackers to Be the US Government's Bounty Hunters
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/unleashing-hackers-to-be-us-governments-bounty-hunters-image_small-9-a-32585.jpg" align=right hspace=4><b>Trump Presidential Memo a Risky Proposition for Corporations and the Internet</b><br>Even those who support a White House push to involve the private sector in offensive cyber operations against foreign online crime groups adm
US FCC Weighs Chinese Transceiver Supply-Chain Crackdown
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/us-fcc-weighs-chinese-transceiver-supply-chain-crackdown-image_small-2-a-32584.jpg" align=right hspace=4><b>Draft Covered List Expansion Would Reach Components Inside AI Data Center Switches</b><br>The U.S. FCC reportedly may restrict imports of new-model optical transceivers made in China, a move that would reach AI data center i
CISA KEV: Ray-Project Ray — Ray-Project Ray Code Injection Vulnerability
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
CISA KEV: Microsoft Internet Key Exchange (IKE) Service Extensions — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
CISA KEV: Broadcom VMware vCenter — Broadcom VMware vCenter Path Traversal Vulnerability
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
CISA KEV: Microsoft SharePoint — Microsoft SharePoint Weak Authentication Vulnerability
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
CISA KEV: Apple macOS — Apple macOS Improper Authentication Vulnerability
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
OpenAI President Urges Enterprises to Deploy AI Agents
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/openai-president-urges-enterprises-to-deploy-ai-agents-image_small-8-a-32583.jpg" align=right hspace=4><b>Greg Brockman Says Defenders Must Automate Security Before Attackers Gain Ground</b><br>OpenAI president Greg Brockman believes every enterprise should bring agents to its security teams as urgently as possible to combat sophi
Hack on Med Software Firm Hits Half of Poland's Population
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/hack-on-polish-medical-software-firm-affects-nearly-19m-image_small-3-a-32580.jpg" align=right hspace=4><b>19M Patients Affected by Data Theft Including National ID Numbers</b><br>A hack into IT systems of MyDr, a Polish provider of electronic medical documentation software, has affected more than 12,000 healthcare facilities and
Ukrainian software developer faces 12 years in Swiss ransomware trial
The unnamed 52-year-old is accused of attacking Swiss train manufacturer Stadler Rail alongside other enterprises as part of an international ransomware operation.
Video Call Exploit Chains Two Flaws in Unisoc Modems
Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.
NVD HIGH: CVE-2026-75111 — Evidently UI fails to properly validate the filename parameter in the dataset ma...
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to access system files, which are then materialized into datasets and retrieved through the download endpoint.
NVD CRITICAL: CVE-2026-75110 — MemOS is a memory operating system for LLMs and AI agents. In deployments where ...
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check in src/memos/api/middleware/auth.py fails open: os.getenv("INTERNAL_SERVICE_SECRET") returns None and a request omitting the X-Internal-Service header al
NVD CRITICAL: CVE-2026-75106 — OpnForm derives editable-submission secrets from sequential row identifiers usin...
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint.
NVD HIGH: CVE-2026-75105 — phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the...
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database primary key to fetch an address without confirming the address belongs to the authorized subnet. An unauthenticated party ho
NVD CRITICAL: CVE-2026-66795 — A flaw was found in the managedcluster-import-controller. The Certificate Signin...
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enab
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on
AI Gives Defenders an Edge in the Vulnerability Race
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-gives-defenders-edge-in-vulnerability-race-image_small-6-a-32577.jpg" align=right hspace=4><b>Mandiant Consulting's Charles Carmakal on AI, Social Engineering and Extortion</b><br>Attackers are using AI to find vulnerabilities, build exploit tools and analyze stolen data, but defenders still hold an advantage. The greater risks
Details emerge on BlackFile’s recent attacks on financial companies
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. The post Details emerge on BlackFile’s recent attacks on financial companies appeared first on CyberScoop .
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop .
Apple Patches iOS and macOS, (Mon, Aug 17th)
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic.
NVD HIGH: CVE-2026-75014 — A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Th...
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
NVD HIGH: CVE-2026-74234 — Legora before 2026-08-14 contains a cross-site scripting vulnerability that allo...
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive, causing the front-matter parser to invoke eval() before any SVG sanitization occurs. Attackers can exploit this flaw through influenced Mermaid diagram
NVD CRITICAL: CVE-2026-71472 — A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authentica...
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
Adam Shostack Talks Hugging Face & PHANTOM-B
World-class threat modeler Adam Shostack shared he was "blown away" by OpenAI's revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both "lightweight yet still usable."
Adam Shostack Talks Hugging Face Breach & PHANTOM-B
The security expert talks with the Dark Reading News Desk about why he "blown away" by OpenAI's revelations regarding the Hugging Face attack, and also discussed his new threat model for LLMs.
Hugging Face Breach Raises Big Questions About AI Security Controls
Adam Shostack, president of Shostack & Associates and an affiliate professor at the University of Washington, talks with the Dark Reading News Desk about why he was "blown away" by OpenAI's revelations regarding the Hugging Face attack.
NVD HIGH: CVE-2026-74238 — TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the...
TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can send a malformed datagram to the Velodyne UDP sensor port, which lacks sender-address restrictions pre
NVD CRITICAL: CVE-2026-66792 — A flaw was found in the multicloud-operators-subscription component. This vulner...
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
Azure Breach Campaign Claims McDonald's, Vodafone as Victims
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/azure-breach-campaign-claims-mcdonalds-vodafone-as-victims-image_small-1-a-32578.jpg" align=right hspace=4><b>Darknet Forums List Employee and Service Records Allegedly Stolen From Major Firms</b><br>Forums selling stolen data are featuring advertisements for massive quantities of employee and service information exfiltrated from
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "
235 GB of PHI and internal documents dumped; Chaos claims it comes from Healthcare Highways
“Chaos” is a Ransomware-as-a-Service (RaaS) group first found online in March, 2025. On August 5, 2026, they added Healthcare Highways to their dedicated leak site, with a 24-hour countdown clock. Healthcare Highways describes itself as a medical provider network company that offers solutions to businesses and their employees built around high-quality hospital systems, physicians, and.
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.
Monzo chairman Hoffman steps down
The chairman of UK digital bank Monzo, Gary Hoffman, is standing down months after facing a shareholder revolt following the departure of CEO TS Anil.
Irregular faces criticism over ‘spin’ in AI hacking postmortem
The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.
VastAdvisor closes $1 million Safe round
VastAdvisor, the AI-powered Organic Growth OS for wealth management firms, today announced the close of its $1 million SAFE round led by investments from fintech industry titans.
Poland probes MyDr healthcare software breach potentially affecting 19 million people
MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.
UNISOC Modem Flaw Enables Remote Code Execution via Video Calls
UNISOC modem flaw enabled kernel-level code execution through video calls
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]
Thunes to support payouts for Fiserv's merchant ecosystem
Thunes, the Smart Superhighway to move money around the world, and Fiserv, a leading global provider of payments and financial services technology, today announced a strategic collaboration to transform how global platforms and marketplaces handle international payouts.
Lithic and Monavate team to build card programmes using fiat and digital services
Lithic, the card issuer processing platform powering next-generation financial experiences, today announced a partnership with Monavate, the regulated payments platform and program manager owned by Exodus Movement, Inc. (NYSE: American: EXOD) (“Exodus”), to give companies a single route to building and scaling card programs using fiat and digital currencies.
Flagstar Bank selects Fixact from Fiserv for core upgrade
Fiserv, Inc. (NASDAQ: FISV), a global leader in payments and financial technology, and Flagstar Bank, N.A. (NYSE:FLG), one of the nation’s largest regional banks, today announced that Flagstar has selected Finxact from Fiserv, a modern, cloud-native core banking platform, as the cornerstone of the bank’s core modernization strategy.
Apple Screen Sharing Security, (Mon, Aug 17th)
About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used a simple global password for authentication. Apple adapted the protocol for its own use, but overall, left the VNC prot
Trump-linked World Liberty Financial gets conditional bank charter approval
Donald Trump-linked crypto venture World Liberty Financial has received conditional approval for a bank charter from the Office of the Comptroller of the Currency.
NVD HIGH: CVE-2026-16471 — Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger ...
Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate readers that are becoming increasingly common on American streets. Read more in my article on the Hot for Security blog.
Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
Why data quality dictates security operations success
As AI takes on more security operations center (SOC) workflows to automate threat triage, indicator extraction, and incident report generation, security operations leaders face a persistent question: Does SOC performance depend more on the large language model (LLM) deployed or on the underlying quality of the security data it consumes? Academic studies offer conflicting answers. An original resea
680,000 Impacted by French Tax Authority Data Breach
Hackers used compromised credentials to access enterprise and personal tax-related data. The post 680,000 Impacted by French Tax Authority Data Breach appeared first on SecurityWeek .
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a
More than 2 million user records from TaxAct allegedly acquired; 450k already leaked
On August 13, DataBreaches was contacted anonymously on Signal by someone reporting that they had acquired more than 2 million records with clients’ phone numbers, usernames, and email addresses from TaxAct, which is owned by Cinven. TaxAct operates under its parent company and holding entity, Taxwell. Not all the phone numbers were real, they reported,... Source
More than 2 million user records from TaxAct allegedly acquired; 450k already leaked (1)
On August 13, DataBreaches was contacted anonymously on Signal by someone reporting that they had acquired more than 2 million records with clients’ phone numbers, usernames, and email addresses from TaxAct, which is owned by Cinven. TaxAct operates under its parent company and holding entity, Taxwell. Not all the phone numbers were real, they reported,... Source
More than 2 million user records from TaxAct allegedly acquired; 450k already leaked (with correction)
On August 13, DataBreaches was contacted anonymously on Signal by someone reporting that they had acquired more than 2 million records with clients’ phone numbers, usernames, and email addresses from TaxAct, which is owned by Cinven. TaxAct operates under its parent company and holding entity, Taxwell. Not all the phone numbers were real, they reported,... Source
Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
Olivier Acuna reports: Cryptocurrency broker Bits of Gold said personal data belonging to roughly 200,000 customers was stolen by hackers, the company reported. The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access to a third-party data analytics network and gained access to customers’ names, national ID numbers, emails,... Source
Windows Server 2022 reaches end of mainstream support in 60 days
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes
Ukraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.
Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon
Data breaches have recently been announced by Terry J. Dubrow, MD, SunCloud Health, Integer Precision Technologies, Minnesota ENT, and Nipro […] The post Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon appeared first on The HIPAA Journal .
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)
[object Object]
Zhipu says new coding AI developed advanced cyber skills faster than expected
Chinese AI developer Zhipu has launched GLM-5.3, a new coding-focused AI model that the company says has developed unexpectedly strong cybersecurity capabilities, putting it close to global leading models in vulnerability discovery while remaining behind them on deeper exploitation tasks. Zhipu’s own testing places GLM-5.3 slightly ahead of Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol on CyberGym
Irregular Details How a Naming Error Let AI Models Attack a Real Company
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models. The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek .
Revolut to open network of airport lounges across Europe
Revolut has unveiled plans for a network of premium branded airport lounges across major European destinations.
How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data,
New macOS malware turns stolen browsers into attacker-controlled sessions
Mac users are being freshly warned of suspicious websites asking them to open Terminal and install software. Jamf Threat Labs has uncovered a multi-stage macOS infostealer, dubbed AmnesiaStealer, that uses a ClickFix-style fake GitHub download page to trick victims into executing a command that installs malware. The campaign is designed to steal credentials and sensitive data before escalating int
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidenc
Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
Hacking Public Wi-Fi DNS to Steal Credentials
Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.
NVD CRITICAL: CVE-2026-74899 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in ...
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.
NVD CRITICAL: CVE-2026-74889 — openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info para...
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
NVD CRITICAL: CVE-2026-74886 — openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerabil...
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
NVD CRITICAL: CVE-2026-74880 — openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query paramet...
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
NVD CRITICAL: CVE-2026-74878 — openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP bru...
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.
NVD CRITICAL: CVE-2026-74876 — openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle...
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.
NVD CRITICAL: CVE-2026-74875 — openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when ...
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
NVD CRITICAL: CVE-2026-74872 — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulner...
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
NVD CRITICAL: CVE-2026-74800 — SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options...
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
NVD CRITICAL: CVE-2026-74799 — SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap a...
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act
The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act
Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
Anthropic has been conducting tests to identify issues in how AI agents interact with each other. The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek .
Companies prefer cash over digital payments - ECB
The decline in cash acceptance observed during and following the Covid-19 pandemic has paused, according to fresh data from the European Central Bank.
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the
Vishing Attack Provides Threat Act with Access to Quantum Health Network
Data breaches have recently been announced by the healthcare navigation and care coordination company Quantum Health, Heart of America Medical […] The post Vishing Attack Provides Threat Act with Access to Quantum Health Network appeared first on The HIPAA Journal .
Alipay launches full stack agentic commerce platform in China
Alipay today launched China’s first full-stack agentic commerce platform at its AI Ecosystem Partner Conference in Hangzhou, providing merchants with the tools to shift from digital operations to AI-powered operations.
French tax authority data breach affects 678,000 individuals
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]
Asic warns of surge in deepfake scams
Australia's Securities and Investment Commission (Asic) is warning of a spike in the use of generative AI to create vast networks of deepfake websites and celebrity investment endorsements to lure victims
Ingenico secures €150 million in fresh capital
Ingenico, a global leader in payment acceptance solutions, is proud to announce an agreement to reset its capital structure, anchored by a €150 million investment from a PIMCO-led group of global investors.
40,000 Impacted by SafePal Data Breach
Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information. The post 40,000 Impacted by SafePal Data Breach appeared first on SecurityWeek .
Ebanx expands leadership team
EBANX, a global technology company specialising in payment services for emerging markets, today announced a significant expansion of its senior leadership team.
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including
SafePal Data Breach Hits Tens of Thousands of Customers
Nearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breach
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]
How QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek .
What the CISO role will look like in 2029
Wolfgang Goerlich has spent his career in security and has been a CISO for the past seven years. Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He’s bracing for more. “For the future I see growing the role of CISO to be the pacesetter for innovation, to be in the board room and executive conversations advising them on how to take smart, calculated ri
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek .
Microsoft Faces Fresh Nightmare Eclipse Zero-Day
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/shield-breaks-microsoft-faces-fresh-nightmare-eclipse-zero-day-image_small-10-a-32573.jpg" align=right hspace=4><b>Attack Manipulates Defender Cloud Hydration to Install an Attacker DLL</b><br>Security researchers reproduced ShieldBreak, a claimed Windows Defender zero-day that manipulates cloud hydration and privileged Windows pr
Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code
Infostealers Harvest 1.7 Billion Credentials in Six Months
Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026
Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek .
NVD HIGH: CVE-2026-19980 — A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, B...
A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated re
NVD CRITICAL: CVE-2026-19977 — A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element ...
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Western Union gets New York nod for Intermax acquisition; still face California hurdles
Western Union has committed to maintain its store locations in New York State and cap fee increases for three years in order to head off opposition to its acquisition of rival Intermax.
Polygon joins BofE's Digital Pound Lab to test cross-border settlement
Polygon Labs has joined Nobo Finance and Dun & Bradstreet for phase two of the Bank of England's Digital Pound Lab, testing near-instant cross-border settlement.
Western Union gets New York nod for Intermax acquisition; still faces California hurdles
Western Union has committed to maintain its store locations in New York State and cap fee increases for three years in order to head off opposition to its acquisition of rival Intermax.
SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]
NVD CRITICAL: CVE-2026-19961 — A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function...
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD HIGH: CVE-2026-19960 — A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impac...
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
NVD CRITICAL: CVE-2026-19959 — A weakness has been identified in Edimax EW-7478APC 1.04. This affects the funct...
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclos
Anthropic confirms Claude is down in major outage affecting multiple services
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]
Wireshark 4.6.8 Released, (Sun, Aug 16th)
Wireshark release 4.6.8 fixes 28 vulnerabilities and 25 bugs.
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling
[object Object]
CVE-2026-6837: Root Command Injection Affecting 18 Zyxel Access Point Models
[object Object]
Large-scale DDoS attacks disrupted Threema secure messaging service
Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]
NVD CRITICAL: CVE-2026-74790 — Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering...
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
NVD CRITICAL: CVE-2026-73061 — Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb...
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
NVD CRITICAL: CVE-2026-73056 — SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive...
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an
New Jersey Federal Judge Dismisses Data Breach Class Action Against Background Check Company
There’s an update to a data leak incident reported in 2024. Phil Stilton reports: A federal judge has dismissed a proposed class action lawsuit against New Jersey-based background check company TABB Inc., finding the plaintiff failed to establish that he suffered a concrete injury necessary to pursue the case in federal court. In an opinion... Source
500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack
SuspectFile has a great read on the Anubis attack on Fairlife. Marco De Felice faithfully reports what Anubis claims in its exclusive communications with him, what Coca-Cola claims, and how the claims differ. One of the most striking statements detailed the group’s response to how or why they targeted Fairlife: “It was not a targeted... Source
CVE-2026-33696: From a Schema Name to RCE in n8n
[object Object]
Rep. Thompson brings bipartisan rural hospital cybersecurity act to House
NorthCentralPA reports: A group of legislators has introduced the bipartisan Rural Hospital Cybersecurity Enhancement Act to the House of Representatives with the intention to strengthen rural hospitals’ protection against cyber threats. The group includes U.S. Reps. Glenn “GT” Thompson (R-Pa.), Kim Schrier (D-Wash.), Erin Houchin (R-Ind.), Jill Tokuda (D-Hawaii), Jefferson Shreve (R-Ind.), and Je
NVD CRITICAL: CVE-2024-13784 — The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPre...
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no
NVD HIGH: CVE-2026-10734 — The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scri...
The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The /cf7_records viewer
NVD CRITICAL: CVE-2026-18316 — The Solace Extra plugin for WordPress is vulnerable to unauthorized modification...
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script
NVD CRITICAL: CVE-2026-18432 — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege...
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a conditio
NVD CRITICAL: CVE-2026-16098 — The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U...
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delet
NVD CRITICAL: CVE-2026-14524 — The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d...
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-c
NVD HIGH: CVE-2026-14498 — The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i...
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_arr
NVD CRITICAL: CVE-2026-19924 — A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01...
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
NC: Possible cyberattack hits Wake election software vendor, leaving poll workers’ data exposed
Caroline Yaffa reports: The Wake County Board of Elections is suspending its use of a software vendor after it reported a possible cyberattack. There’s no evidence that voting machines, ballots, voter registration records or systems used to count votes were affected, according to the county board. But the incident could have exposed information about people... Source
NVD HIGH: CVE-2026-19919 — A vulnerability was found in code-projects Online Shopping System 1.0. This impa...
A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
NVD CRITICAL: CVE-2026-73053 — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th...
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.
NVD CRITICAL: CVE-2026-73052 — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and...
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
NVD CRITICAL: CVE-2026-73050 — SiYuan versions before v3.7.4 fail to validate or escape the color field in attr...
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.
NVD CRITICAL: CVE-2026-73046 — SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t...
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure counter used by the cookie/session login path. This all
NVD CRITICAL: CVE-2026-73044 — SiYuan versions before v3.7.4 fail to validate or escape table column width valu...
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject event handlers on every table cell, executing arbitrary code in the Electron renderer with Node integration enabled.
NVD CRITICAL: CVE-2026-73043 — SiYuan versions before v3.7.4 contain a remote code execution vulnerability in t...
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the
NVD CRITICAL: CVE-2026-73042 — SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int...
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
NVD CRITICAL: CVE-2026-73041 — SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt...
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.
NVD HIGH: CVE-2026-19905 — A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function...
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but
NVD CRITICAL: CVE-2026-18855 — The Link Library plugin for WordPress is vulnerable to arbitrary file deletion d...
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). E
NVD CRITICAL: CVE-2026-19598 — The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to...
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met
Time ran out for victims; CRPx0 puts data up for sale
CRPx0 made the news last month for its somewhat novel approach of offering free OnlyFans accounts to get victims to click links that would deploy its malware. Since August 7, when it launched a leak site on both the clear net and dark web, CRPx0 has listed 47 victims that did not pay its extortion... Source
NVD HIGH: CVE-2026-19899 — A vulnerability was determined in SourceCodester Class and Exam Timetabling Syst...
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
UK: ICO reprimands ACRO Criminal Records Office after data breach
The Information Commissioner (the Commissioner) recently issued a reprimand to ACRO Criminal Records Office for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. ACRO Criminal Records Office (ACRO) is a national police unit providing a range of public services, including issuing Police Certificates and International Child Protection Certificates, and processing Subject Access.
KR: Sogang University data breach exposes 180,000 student, staff accounts
Hyeon Ye-Seul reports: Personal information belonging to roughly 180,000 students, alumni and staff at Sogang University was exposed in a cyberattack, the university said Saturday. The university said it had confirmed signs that some data tied to its integrated login accounts had been leaked following an attack by an unidentified outside party. Sogang posted an... Source
CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts
A recent report claims ransomware attacks on K-12 are down for the first half of 2026, while another news story’s headline today claims schools are becoming a new cybersecurity battleground. New? We don’t think it’s new. But the education sector has long been characterized as providing low-hanging fruit for criminals, and recent attacks on edtech... Source
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
[object Object]
NVD CRITICAL: CVE-2026-16142 — The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all ver...
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user() without verifying authentication or ownership. This makes it possible for unauthentic
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to
NVD CRITICAL: CVE-2026-15826 — The User Profile Builder plugin for WordPress is vulnerable to Authentication By...
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is submitted with a 61–70 character username, WordPress core rejects it with a WP_Error
NVD HIGH: CVE-2026-14279 — The Wholesale Market plugin for WordPress is vulnerable to privilege escalation ...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce (which is exposed to any authenticated user through wp_localize_script on the frontend) and that the caller has a positive user ID, then calls WP_User::add_role
Microsoft SharePoint JWT Token Authentication Bypass Technical Analysis (CVE-2026-55040)
[object Object]
CVE-2026-55040: SharePoint Server Subscription Edition improper JWT validation lead to Arbitrary Account Login
[object Object]
NVD HIGH: CVE-2026-16145 — The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin f...
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acces
NVD HIGH: CVE-2026-13360 — The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is ...
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in
NVD CRITICAL: CVE-2026-15341 — The User Session Synchronizer plugin for WordPress is vulnerable to Authenticati...
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce, capability, or shared-secret validation against the attacker-supplied `ussync-key`, `ussync-token`, and `ussync-ref` param
NVD HIGH: CVE-2026-15312 — The Propovoice: All-in-One Client Management System plugin for WordPress is vuln...
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's REST endpoint failing to validate the user-supplied `role` parameter against an allowlist of permitted WordPress roles and omitting any `promote_users` capability check before passing the sanitized value
NVD CRITICAL: CVE-2026-15303 — The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass...
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling wp_set_current_user() and wp_set_auth_cookie() for any WordPress user
NVD CRITICAL: CVE-2026-14484 — The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress ...
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the righ
NVD HIGH: CVE-2026-14433 — The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordP...
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user access
How Anthropic plans to watermark Claude's AI-generated text
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]
ERP Security Struggles to Keep Pace With AI Agents
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/erp-security-struggles-to-keep-pace-ai-agents-image_small-4-a-32574.jpg" align=right hspace=4><b>CIOs Confront Rising Identity and Security Risks as AI Agents Gain Access to ERP</b><br>As AI agents gain access to ERP systems, CIOs face risks from better-equipped attackers and authorized agents that can take harmful actions. Securi
Shield Breaks: Microsoft Faces Fresh Nightmare Eclipse Zero-Day
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/shield-breaks-microsoft-faces-fresh-nightmare-eclipse-zero-day-image_small-10-a-32573.jpg" align=right hspace=4><b>Attack Manipulates Defender Cloud Hydration to Install an Attacker DLL</b><br>Security researchers reproduced ShieldBreak, a claimed Windows Defender zero-day that manipulates cloud hydration and privileged Windows pr
New AI Playbooks Will Target Healthcare Cyber Risk
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/new-ai-playbooks-will-target-healthcare-cyber-risk-image_small-4-a-32572.jpg" align=right hspace=4><b>Dr. Brian Anderson, CEO of the Coalition for Heath AI, on Frontier AI Threats</b><br>Frontier AI models can identify network vulnerabilities and compress attacks from days or weeks into seconds, raising the stakes for healthcare.
Metasploit Wrap Up: Lot of summer shells and fit http profiles
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of th
Friday Squid Blogging: Searching for the Colossal Squid
Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there. Lots of footage of giant squid, and speculation about the colossal squid. Worth watching. As usual, you can
Investigation of banking hack leads to arrests in Germany, Brazil
Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.
Investigation of banking hack leads to arrests in Europe, Brazil
Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.
NVD CRITICAL: CVE-2026-17186 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute ...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
NVD CRITICAL: CVE-2026-17184 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute ...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
NVD CRITICAL: CVE-2026-17182 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass a...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
NVD CRITICAL: CVE-2026-17181 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write fi...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
Mission-Driven Security: Inside a Global Bank's Defense
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.
NVD CRITICAL: CVE-2026-73678 — MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated re...
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers
Russia Targeting Ukraine Using Internet-Connected Cameras
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/russia-targeting-ukraine-using-internet-connected-cameras-image_small-7-a-32566.jpg" align=right hspace=4><b>Attacks Against Ukrainian Soldiers and Materiel Tied to Hacking of European Devices</b><br>Hacked websites and internet-connected devices in Europe are serving as cyberespionage launchpads for Russia's ongoing war against U
CVE-2026-21852: How Cursor's AI Agent Mode Was Compromised — And Why Your API Gateway Can't Save You
[object Object]
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400
NVD HIGH: CVE-2026-19846 — A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This im...
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
Hackers arrested over €30M bank fraud exploiting service provider flaw
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]
Amid AI-Driven Bug Tsunami, NIST Looks to…AI
Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.
IAM Compliance Requirements and Best Practices
IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can
NVD HIGH: CVE-2026-63701 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Imprope...
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
NVD HIGH: CVE-2026-63700 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorre...
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrents
JPMorgan debanked Polymarket - FT
JPMorgan Chase ended its banking relationship with prediction market Polymarket last year over regulatory concerns, according to the Financial Times.
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]
What Boards Need to Know About Tech Risk
Why do so many boards underestimate technology risk until it becomes a crisis?
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]
Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks
Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June , and there are fears that they could have found a new target. Reco ha
France investigates tax authority breach after hacker claims 600,000 victims
French authorities confirmed that someone gained unauthorized access to systems at the Directorate General of Public Finances in late June after stealing or misusing someone’s identity.
Oracle’s new database security tool is free — for six months
Oracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments. Oracle Database Security Central will be available free of charge until the end of February 2027. It arrives at a critical time for Oracle customers, with attackers targeting security flaws to exploit the company’s database products . Oracle is also con
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan,
Chime considering adding stablecoin features to app
Consumer banking fintech firm Chime Financial is reportedly considering adding stablecoins as a feature in its app.
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
NHS admits data breach by sending patient data via pagers
STILL, NHS? Martin Bagot reports: The NHS has admitted a data breach by sending patients’ personal information over pager devices. A BBC investigation found sensitive medical data of transplant patients was routinely sent over an unencrypted pager network. The information included the names, dates of birth and types of organs being offered or needed. The small battery... Source
Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents
Data breaches have been reported by the Boston Healthcare for the Homeless Program in Massachusetts, Monongalia County General Hospital Company […] The post Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents appeared first on The HIPAA Journal .
Cyera's Oasis Security Buy is All About AI Agent Control
The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.
NVD CRITICAL: CVE-2026-72830 — Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in Con...
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.
NVD CRITICAL: CVE-2026-72829 — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key ...
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate super-privilege grants on a bare isSuperAdmin() check that reads access.api.super directly without consulting the key's scopes. As a result, an api.users.write-scoped key minted on
NVD CRITICAL: CVE-2026-72826 — The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scop...
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access scope, and the new key's scopes are read directly from the request body with no subset check. An attacker holding a minimal-scope API key on a super
NVD CRITICAL: CVE-2026-72824 — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key ...
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult api_key_scopes, so a least-privilege API key scoped only to api.pages.write and minted on a super account can enable process.twig on a page save even though admin.pages_twig is intentiona
NVD CRITICAL: CVE-2026-72822 — The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) ...
The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads (isSuperAdmin/hasPermission) and never invokes requirePermission(), so the api_key_scopes cap is never applied. As a result, a holder of a narrow-
NVD CRITICAL: CVE-2026-72811 — SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/...
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reacha
Texas Hearing Institute Ransomware Attack Affects 30,000 Patients
Texas Hearing Institute has announced a cybersecurity incident involving the protected health information of almost 30,000 patients. Data breaches have […] The post Texas Hearing Institute Ransomware Attack Affects 30,000 Patients appeared first on The HIPAA Journal .
Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients
A data breach at Aesto Health, a Birmingham, Alabama-based healthcare technology company, has affected several of its healthcare provider clients. Aesto […] The post Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients appeared first on The HIPAA Journal .
In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities appeared first on SecurityWeek .
Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek .
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and c
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions. The technique assumes that an operator already has code execution on the Windows host and does not involve
Nvidia partners with Wall Street mobilise funds for AI infrastructure, Goldman Sachs leads financing
Goldman Sachs is in talks with investors on financing Nvidia’s deal with leading asset managers to build AI infrastructure.
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . OpenAI, and then Anthropic , were each formed by AI developers who feared unrestrained corporate AI development—specifically, that companies like Google and Meta would steer the technology towards deleterious, maybe even catastrophically unsafe, outcomes for society. Their founders proclaimed that their
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek .
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap, said it
RingCentral data breach exposed info of 1.6 million accounts
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
AmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie data
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple began sending threat notifications to users in late 2021.
1.6 Million Likely Impacted by RingCentral Data Breach
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first on SecurityWeek .
Citigroup's Consumer Cards to acquire fintech Kard
Citi’s U.S. Consumer Cards business today announced that it has entered into an agreement to acquire Kard Financial, Inc. (Kard), a company that operates a commerce media and rewards platform that helps banks and fintechs deepen customer engagement through personalized offers.
French taxpayers' data stolen in cyberattack
French taxpayers’ data was stolen by a “malicious actor” in a June cyberattack, the French Finance Ministry stated on Thursday.
ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit
A $3,500,000 settlement has received preliminary approval from the court to resolve class action data breach litigation against ZOLL Medical […] The post ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit appeared first on The HIPAA Journal .
Cashflows makes strategic investment in Tap & Go, supporting growth
Cashflows, the platform that makes it easy for businesses to accept payments, announces its investment in Tap & Go, specialists in card payment technologies and merchant services.
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal Organizations (TCOs) and disrupt them. "By partnering with vetted United States companies subject to the direction and
Over 1,000 Charities Hit by Beacon CRM Data Breach
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on SecurityWeek .
Akira ransomware reboots into Windows Safe Mode to knock EDR offline
Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled. According to Huntress, the technique successfully took both its agent and Microsoft Defender’s real-time protection offline. This, the researchers said, gave the attacker a window to operate without endp
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
The cybersecurity backlog is not a security problem
Cybersecurity teams should be responsible for risk oversight, rather than for executing every corrective action. Assigning security teams the tasks of finding, prioritizing, assigning, implementing, tracking and validating every remediation does not foster accountability. Instead, it results in an organizational repository for unresolved issues. A more effective model distinguishes roles clearly:
Data analyst sent to prison for stealing data, extorting employer
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]
How CSOs can turn cybersecurity into a business growth strategy
For years, cybersecurity leaders have worked to convince organizations that security deserves a seat at the executive table. Today, that conversation is changing. The challenge is no longer proving that cybersecurity matters; it is demonstrating how security leaders can help organizations innovate, modernize, and grow with confidence. As organizations accelerate digital transformation, CSOs have a
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek .
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control
Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations
Threat intelligence researchers from Broadcom revealed that a known Chinese APT group may be linked to a lucrative crypto fraud operation
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs
[object Object]
Hackers Exploiting Unpatched GeoServer Zero-Day
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek .
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-12949 — The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via I...
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a t
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]
NVD HIGH: CVE-2026-19758 — A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue af...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem ea
MUFG trials blockchain settlement for Japanese Government Bond repo trades
Mitsubishi UFJ Financial Group (MUFG) is running a proof-of-concept for bringing Japanese Government Bond repo transactions on-chain using the Canton Network blockchain.
BofA to buy 49.9% stake in Indian digital lender Jio Credit
Bank of America has struck a $1.9 billion deal to buy up to 49.9% of Indian digital-native non-bank lender Jio Credit.
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.
The “philosophical shift” that the memo authorizes raises legal, practical and moral questions, experts say. The post A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. appeared first on CyberScoop .
NVD HIGH: CVE-2026-72856 — Budibase versions before 3.40.0 contain an authorization/authentication bypass i...
Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted middleware is a no-op and the route is protected only by a general authentication check, so any authenticated user — including a lowest-privilege BASIC ap
NVD HIGH: CVE-2026-72853 — Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle data...
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data.
NVD CRITICAL: CVE-2026-72851 — Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability i...
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake.
NVD CRITICAL: CVE-2026-72850 — Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authe...
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.
NVD HIGH: CVE-2026-72849 — Budibase before 3.40.0 contains a cross-site request forgery vulnerability in th...
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inh
NVD CRITICAL: CVE-2026-72842 — luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privile...
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-host`, achieving root code execution
NVD CRITICAL: CVE-2026-72841 — luci-app-openvpn fails to properly validate the instance_name2 parameter during ...
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system directories accessible on reboot.
NVD CRITICAL: CVE-2026-72839 — filebrowser through 2.63.16 fails to properly restrict scope and permissions whe...
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.
NVD CRITICAL: CVE-2026-72776 — AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution v...
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands
Oligo Raises $60M to Extend Runtime Security to AI Agents
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/oligo-raises-60m-to-extend-runtime-security-to-ai-agents-image_small-7-a-32556.jpg" align=right hspace=4><b>CEO: Funding Will Expand Exploit Blocking Across Cloud-Native and Agentic Apps</b><br>Startup Oligo raised $60 million to expand runtime exploit blocking to agentic AI, tracing activity from prompts and tool calls to system
Claims Data Shows Where AI Risk Is Hitting Now
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/claims-data-shows-where-ai-risk-hitting-now-image_small-10-a-32555.jpg" align=right hspace=4><b>Resilience Data Shows Social Engineering Dominates Over AI-Native Losses</b><br>AI is amplifying familiar attacks rather than creating new categories of loss. Resilience's Jud Dressler explains why social engineering dominates claims, w
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
Cameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92. The post Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack appeared first on CyberScoop .
NVD CRITICAL: CVE-2026-19297 — IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain una...
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
NVD HIGH: CVE-2026-18511 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gener...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash.
NVD HIGH: CVE-2026-18509 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.
NVD HIGH: CVE-2026-18077 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
NVD CRITICAL: CVE-2026-17482 — IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e...
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
NVD CRITICAL: CVE-2026-17481 — IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e...
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.
Ukraine shuts down 94 fraudulent call centers, seize millions in cash
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
New Zealand’s Sterling lands funding to run finance on autopilot
Sterling, the New Zealand AI startup building an autopilot for finance teams, has raised $3.8 million (NZD) in a round led by trans-Tasman venture capital firm Blackbird.
Extortion Gang Leaks Novo Nordisk's 'AI and ML Ecosystem'
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/extortion-gang-leaks-more-novo-nordisk-data-ai-models-rd-image_small-3-a-32553.jpg" align=right hspace=4><b>Fulcrumsec Claims 2nd Data Dump Exposes Firm's Hugging Face Models, Drug R&D Data</b><br>Extortion gang Fulcrumsec has leaked on its dark web site a second large cache of data it allegedly stole in a June attack on Novo Nord
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
Global Threat Campaign Hits Critical VMware vCenter Flaw
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
Attackers target zero-day vulnerability in geospatial data platform GeoServer
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data. The software is widely used by organizations in many industries, including the government, defense, science, education, engineering and technology sectors, and has been targeted by hac
Airwallex partners Affirm for US BNPL roll out
Airwallex, a leading global financial platform for modern businesses, and Affirm (NASDAQ: AFRM), the payment network that empowers consumers and helps merchants drive growth, today announced that merchants on Airwallex can now provide Affirm's flexible payment options at checkout to their eligible US customers.
NVD HIGH: CVE-2026-73530 — Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vu...
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`,
NVD CRITICAL: CVE-2026-19747 — A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B...
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.
NVD HIGH: CVE-2026-18846 — IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly v...
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server.
NVD CRITICAL: CVE-2026-17206 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
NVD HIGH: CVE-2026-17199 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.
NVD HIGH: CVE-2026-17069 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.
NVD HIGH: CVE-2026-17045 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perf...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.
NVD HIGH: CVE-2026-17004 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
NVD HIGH: CVE-2026-16987 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privi...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
NVD HIGH: CVE-2026-16982 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.
NVD HIGH: CVE-2026-16967 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.
NVD CRITICAL: CVE-2026-16961 — IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could s...
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
NVD HIGH: CVE-2026-16908 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.
NVD HIGH: CVE-2026-16887 — IBM i 7.6 could allow a remote attacker to cause a denial of service due to an o...
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
NVD HIGH: CVE-2026-16868 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.
NVD CRITICAL: CVE-2026-16867 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server reso...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
NVD HIGH: CVE-2026-16853 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive i...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
NVD CRITICAL: CVE-2026-16815 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
NVD HIGH: CVE-2026-14875 — IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrar...
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
NVD CRITICAL: CVE-2026-14525 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphe...
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
NVD HIGH: CVE-2026-13460 — IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI conta...
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.
NVD HIGH: CVE-2026-73482 — phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerabil...
phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central verifyCsrfGetToken check uses enforce=false and is bypassed when the token parameter is absent). A remote attacker can trick a logge
NVD HIGH: CVE-2026-72777 — Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerabil...
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses inc
NVD CRITICAL: CVE-2026-17197 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @
NVD HIGH: CVE-2026-72741 — Rainbond through 6.9.7 contains a broken access control vulnerability in the Che...
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, a
NVD CRITICAL: CVE-2026-67614 — CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the We...
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service with
NVD HIGH: CVE-2024-58374 — Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the get...
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying
ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods. The latest ThreatsDay Bulletin puts all of these short updates in one place, so you can quickly catch up on what happened, what changed, and what security teams
Hackers breach govt webmail while running parallel crypto fraud
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]
Curiouser and Curiouser
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]
AI 'watermark removers' flood the web. Almost none can prove they work.
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]
NVD HIGH: CVE-2026-73266 — A flaw was found in the clusterclaims-controller component of Multicluster Engin...
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.
Cryptohack Roundup: Harmony, BTCPay Exploits
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cryptohack-roundup-harmony-btcpay-exploits-image_small-2-a-32543.jpg" align=right hspace=4><b>Also: CTFC-led $48M Fraud Case, NFT Founder Charged in $10M Scam</b><br>This week, Harmony and BTCPay hacked, violent crypto thefts surged, the U.S. CFTC filed a $48 million fraud case, an NFT founder charged, North Koreans used artificia
Why API Discovery Is Critical for Modern AppSec Programs
Hidden API Estate And AI-speed Recon Are Reshaping Modern Application Risk Key Takeaways Unknown APIs create unattributed exposure, and such exposure rarely gets tested. Attackers build their own inventory through live reconnaissance; they do not wait for your spreadsheet. API discovery must pull from gateways, cloud, specs, traffic paths, scanners, and external exposure signals. OWASP […]
AI’s ‘middle class’ has gotten dramatically better at hacking
As frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models. The post AI’s ‘middle class’ has gotten dramatically better at hacking appeared first on CyberScoop .
Flock tightens privacy controls amid scandals over officer abuse
All Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.
Critical VMware vCenter RCE flaw exploited for reverse SSH access
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]
NVD CRITICAL: CVE-2026-73533 — Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introd...
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administ
NVD CRITICAL: CVE-2026-73532 — Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introdu...
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploa
New Mirai variant adds stealth capabilities to notorious botnet code
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities
CRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ data
NVD HIGH: CVE-2026-70455 — rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows ...
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting
NVD HIGH: CVE-2026-70452 — rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that al...
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass
NVD HIGH: CVE-2026-53803 — rsync before 3.5.0 contains a symlink following vulnerability that allows local ...
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local
NVD HIGH: CVE-2026-53795 — rsync before 3.5.0 contains an arbitrary file write vulnerability that allows at...
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessib
NVD HIGH: CVE-2026-53793 — rsync before 3.5.0 contains a path confinement bypass vulnerability that allows ...
rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can exploit improper handling of the /./ notation or forge delta-basis transfers referencing xname paths that cross the /./ bo
NVD CRITICAL: CVE-2026-53791 — rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that all...
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized a
NVD HIGH: CVE-2026-53784 — rsync before 3.5.0 contains a path traversal vulnerability that allows remote cl...
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to ref
NVD HIGH: CVE-2026-53783 — rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race conditi...
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and
Amex expands virtual card capabilities
American Express today announced new capabilities to help U.S. commercial customers simplify payments and give them more options to efficiently manage spending in their financial software of choice with American Express Virtual Cards.
Trezor discloses data breach affecting nearly 14,000 customers
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked. [...]
Data Breaches Announced by Five HIPAA-Regulated Entities
Data breaches have recently been announced by the Women’s Center for Radiology in Florida, Optalis Management Solutions in Michigan, the […] The post Data Breaches Announced by Five HIPAA-Regulated Entities appeared first on The HIPAA Journal .
In a first, US will allow some private firms to carry out cyberattacks
Zack Whittaker reports: The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday. In a newly published presidential memorandum, the Trump administration said the move will allow the federal government to use “innovative capabilities of the private... Source
Quincy Valley Medical Center notifies patients of Aesto breach
As Seen on Facebook: To our Patients, Some of you have or will receive a letter from Grant County Public Hospital District 2 describing a security incident involving one of our third-party vendors. It is important to us that you understand some facts regardin this incident. First, we were notified of the incident on July... Source
New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (
Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone
Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek .
Adobe Commerce Bug Targeted Immediately After Disclosure
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek .
Trump sued over selling early access to Truth Social posts
President Donald Trump has been sued over his media company's move to charge for real-time access to Truth Social posts.
OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits
Individuals affected by data breaches at OnePoint Patient Care and Clay-Platte Family Medicine may be entitled to claim benefits after […] The post OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits appeared first on The HIPAA Journal .
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
vCenter Flaw Exploited Just Five Days After Disclosure
Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it
AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spread via a counterfeit GitHub download page titled "Download for macOS" and claims to be from a verified publisher. The page employs a ClickFix-style lure that
Brazil orders Discord to suspend livestreaming after teen suicide
Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.
White House taps security firms for offensive hack-back operations
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]
Trump taps cyber firms to go on offensive against criminals
The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.
AI agents wage near-autonomous cyberattack on Asian government networks
Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations. The campaign unfolded over four days in early July, during which multiple AI agents operated in parallel to map networks, identify vulnerabilities, and ex
Netdania adds Fenics FX options data
Netdania, part of United Fintech, has added institutional FX Options data from Fenics Market Data & Analytics to its APIs, giving the financial institutions it serves direct access to trusted pricing and volatility data across more than 400 currency pairs.
Sionic launches Instant Bank Pay in US through Microsoft Marketplace
Sionic, a leader in real-time, bank-to-bank payments at the point of sale, today announced the availability launch of its Instant Bank Pay service alongside Fraud Detection Service in Microsoft Marketplace, the unified online destination for customers to buy trusted cloud solutions,
The Model Is the Malware | What Four Agentic Intrusions Tell Defenders
OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions.
Uncle Sam Seeks Private Hackers to Disrupt Criminal Networks
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/uncle-sam-seeks-private-hackers-to-disrupt-criminal-networks-image_small-2-a-32549.jpg" align=right hspace=4><b>White House Program Will Tap Private Sector for Surveillance and Cyber Operations</b><br>The White House, in a major expansion of how it works with the private sector, has launched a program to engage private cybersecuri
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek .
Anthropic in talks to purchase Decart AI
AI firm Anthropic is in talks to Decart AI before its public listing, Bloomberg reported on Wednesday.
Germany moves to give spy agencies hacking and sabotage powers
Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era.
Trump Authorizes Private Sector Participation in Offensive Cyber Operations
The White House has authorized government-directed offensive cyber operations against transnational groups, prompting warnings over escalation and attribution risks
Trump administration opens door to private-sector cyber offensives
The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime. A presidential memorandum issued on August 12 directs the National Coordination Center to create a program authorizing participating companies to conduc
Oracle and Quantinuum partnership enables quantum-AI innovation
Cloud platform Oracle has partnered with quantum computing company Quantinuum to explore the potential of quantum-AI hybrid infrastructure.
NVD HIGH: CVE-2026-73629 — Serendipity before 2.6.0 contains a server-side request forgery vulnerability in...
Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges. Authenticated users with adminImagesAdd permission can bypass the filter using alternate address formats to request internal services and retrieve response bodies through the public uploads direct
NVD HIGH: CVE-2026-73625 — GitPython versions before 3.1.54 contain a remote code execution vulnerability i...
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.
NVD HIGH: CVE-2026-73623 — GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_opti...
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.
NVD HIGH: CVE-2026-73617 — Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB d...
Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied parameters are enriched with handlebars using noEscaping: true and parsed without operator filtering. Attackers can inject MongoDB operators through query parameters to bypass per-user access controls, read arbitrary documents, execute JavaScript via $where operators, or modify
NVD HIGH: CVE-2026-73615 — Network-AI versions before 5.15.1 contain a security matcher bypass vulnerabilit...
Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by stripping quotes before execution. Attackers can craft quoted commands that evade blocklist checks and approval gates while the executor runs the identical unquoted dangerous argv.
NVD HIGH: CVE-2026-73613 — filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulner...
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers can swap an ancestor directory with a symlink during the cache TTL window to redirect the raw os.Remove call to an out-of-scope target, bypassing Scoped
It took $58 to break Microsoft’s SCCM, but a patch made it harder
Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Manager ( SCCM ) to deploy operating systems, manage patches, distribute software, and monitor compliance across large Windo
How to Evaluate Managed Detection and Response (MDR) Providers
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/2am-test-evaluating-managed-detection-response-providers-image_small-7-a-32320.jpg" align=right hspace=4>Cyberattacks don't wait for business hours. In this video, Blackpoint Cyber explains why response-led MDR goes beyond alerts to deliver rapid investigation, containment and expert action before threats escalate.
Siemens Desigo DXR and PXC Controllers
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-08.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal
Johnson Controls Inc. Airwall
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to prot
Siemens Siveillance Video
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-09.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p> <
Siemens LOGO! Soft Comfort
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-13.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt pro
Haiwell IoT Cloud HMI Gateway
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.</strong></p> <p>The following versions of Haiwell IoT Cloud HMI Gateway are affected:</p> <ul> <li>H
Siemens Parasolid
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-10.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released
Siemens License Server (SLS)
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and rec
Johnson Controls Metasys
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-14.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators
Flow Neuroscience FL-100
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-225-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits.</strong></p> <p>The following versions of Flow Neuroscience FL-100 ar
ANDRITZ HIPASE-250 and 250 SCALA
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations.</strong></p> <p>The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected:</p
AVEVA Enterprise SCADA
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization.</strong></p> <p>The following versions of AVEVA Enterprise SCADA are
Hitachi Energy APM Edge Product
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availabilit
WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in
WhatsApp rolls out new feature that flags potential scam messages
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]
Trump turns to private sector in offensive hacking operations memo
One expert called it a “pretty big shift in U.S. cyber policy,” and there have been reservations in the past about opening the door to private sector involvement in cyber offense. The post Trump turns to private sector in offensive hacking operations memo appeared first on CyberScoop .
Venture Firm Team8 Secures Additional $365 Million
The Israeli company has nearly $2 billion in total assets under management since 2014. The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek .
CFTC orders Kalshi to keep operating in response to New York lawsuit
The US Commodity Futures Trading Commission (CTFC) ordered predictions market platform Kalshi to continue operating on Tuesday, opposing multiple state lawsuits against the company.
Separating AI’s Technological Problems from Its Capitalism Problems
This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press . AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the industrial revolution, when new technologies like the steam engine provided a quantum leap in our ability to do mechanical work outside of our bodies at scale.
Cisco Sees AI Fueling Network Upgrade Supercycle
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cisco-sees-ai-fueling-network-upgrade-supercycle-image_small-8-a-32540.jpg" align=right hspace=4><b>Customers Are Reprioritizing Budgets for AI, Security and Quantum Readiness</b><br>Cisco says agentic AI is driving a mult-year network upgrade cycle as hyperscalers and enterprises expand data center interconnects, move some infere
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek .
Flagstone adds dollar and euro savings options for UK SMEs that keep cash in foreign currencies
Flagstone, the UK’s largest cash deposit platform, has made dollar (USD) and euro (EUR) business savings accounts available to its fast-growing community of UK SME clients as part of its vast range of cash management products.
Klarna boosts membership perks and removes service fees
Klarna has increased cashback rates to deliver up to €6,000 worth of benefits and removed service fees for membership holders.
Dissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits
Settlements have received preliminary approval to resolve class action data breach complaints against Highland Health Systems and Albany Gastroenterology Consultants […] The post Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits appeared first on The HIPAA Journal .
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek .
Pepper Money announces plans to launch First Charge Mortgages in Scotland
Pepper Money, the leading specialist mortgage lender, has announced plans to launch its First Charge mortgage proposition in Scotland this September, strengthening its commitment to supporting brokers and customers with more complex borrowing needs.
finby boosts Wero to support the future of pan-European payments
finby, a European payment service provider and acquirer, announced the deployment of Wero, the pan-European digital payment solution, for its e-commerce merchants.
Creditspring expands access to responsible credit with new FCA credit broking permission
Creditspring, the subscription-based credit provider on a mission to improve financial stability across the UK, has secured FCA permission to operate as a credit broker, enabling the company to support more customers by introducing eligible members to carefully selected third-party credit products where these better meet their needs.
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .
Zilch launches new membership tiers
Zilch, the intelligent payments platform, today announces its most significant product expansion since launch. The company is rolling out two new membership tiers - Zilch Extra and Zilch Plus - alongside two new features: Zilch Advance, an open banking salary advance available to eligible members, and Pay Monthly, which allows eligible customers to spread the cost of purchases over up to 12 months
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek .
ICO Reprimands Criminal Records Office After 2023 Breach
The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach
Microsoft wants you to rethink your approach to cyber defense
Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft. David Weston, group manager in the Windows team at Microsoft, told delegates at Black Hat USA that traditional approaches to vulnerability remediation fail
Armored Likho expands its cyber-espionage toolkit
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Belgium's eID Authentication Opens Citizen Accounts to RCE
The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
AnMed Faces Continued Ransomware as Attacker Ramps Up Pressure
AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen claimed […] The post AnMed Faces Continued Ransomware as Attacker Ramps Up Pressure appeared first on The HIPAA Journal .
AnMed Investigating Ransomware Group’s Data Theft Claims
AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen claimed […] The post AnMed Investigating Ransomware Group’s Data Theft Claims appeared first on The HIPAA Journal .
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two si
More Novo Nordisk data dumped by FulcrumSec
FulcrumSec has dumped more data from its attack that Novo Nordisk first disclosed on June 11. FulcrumSec writes: Today we are releasing all of the Novo Nordisk data not included in our original post: their complete enterprise HuggingFace AI/ML ecosystem. 30 models, 70 datasets, and half a terabyte of proprietary Cell Painting microscopy images. 1.05... Source
Ransomware Attack Disables Canadian Hospital’s Doors, HVAC
Marianne Kolbasuk McGee reports: A Canadian hospital is dealing with a ransomware attack on its facility management systems that has affected the building’s doors and heating, ventilation and air conditioning equipment. Some experts said the incident underscores growing cyberthreats involving operational technology in healthcare. The attack this week on Manitoba, Ontario’s largest hosp
S&P Global data integrated into Microsoft 365 Copilot
Microsoft has struck a deal to integrate S&P Global AI-ready data, insights and analytics into its 365 Copilot workflows and agentic experiences.
Revolut reduces WeWork access for premium members
Revolut premium subscribers have lost access to a host of WeWork offices across Europe after the shared workspace firm increased its fees.
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]
Ransomware Attack Disables Canadian Hospital's Doors, HVAC
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ransomware-attack-affects-canadian-hospitals-doors-hvac-image_small-2-a-32535.jpg" align=right hspace=4><b>Experts: Incident Underscores OT Risks in Healthcare Environments</b><br>A Canadian hospital is dealing with a ransomware attack on its facility management systems that has reportedly affected its doors and heating, ventilati
Android malware combo takes out loans and relays victims' credit cards
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]
NVD CRITICAL: CVE-2026-73519 — WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret comp...
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node's management po
NVD CRITICAL: CVE-2026-71471 — A flaw was found in acm-search-v2-rhel9. An attacker with administrative privile...
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attac
NVD HIGH: CVE-2026-71469 — A flaw was found in search-v2-api. An unauthenticated attacker can exploit this ...
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).
NVD HIGH: CVE-2026-17485 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
NVD HIGH: CVE-2026-10534 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer...
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
NVD CRITICAL: CVE-2024-27253 — IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated ...
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
Enterprise AI Token Spend Shifts From Chat to Agents
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/enterprise-ai-token-spend-shifts-from-chat-to-agents-image_small-8-a-32539.jpg" align=right hspace=4><b>Token Volume Climbs While Business Outcomes Remain Unclear</b><br>OpenAI reports that enterprise customers are shifting token spend from chatbot conversations to agents deployed across systems and workflows, with Codex use sprea
Rush to Build Data Centers Leaves OT Security Behind
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/rush-to-build-data-centers-leaves-ot-security-behind-image_small-9-a-32538.jpg" align=right hspace=4><b>Siloed Systems Leaves OT Devices Only 'One Hop Away' From the Internet</b><br>In the rush to get servers on the ground, and especially to cater to the artificial intelligence boom, data center owners have neglected security and
Corma Raises $60M to Build Cyber Defense Foundation Models
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/corma-raises-60m-to-build-cyber-defense-foundation-models-image_small-1-a-32537.jpg" align=right hspace=4><b>Corma Says General-Purpose Models Aren't Optimized for Defensive Security</b><br>San Francisco-based Corma raised a $60 million Sequoia-led seed round to train foundation models for enterprise cyber defense, using security
NVD CRITICAL: CVE-2026-17616 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access ...
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
NVD HIGH: CVE-2026-16695 — IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attac...
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-16480 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an impro...
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
NVD HIGH: CVE-2026-14866 — IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injectio...
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
NVD HIGH: CVE-2026-13622 — A symlink following vulnerability was found in KubeVirt's virt-handler migration...
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions ca
NVD HIGH: CVE-2026-13433 — IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to do...
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
NVD HIGH: CVE-2026-13367 — IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation...
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
NVD HIGH: CVE-2026-13105 — IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip...
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
NVD HIGH: CVE-2026-13094 — IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrar...
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.
NVD HIGH: CVE-2026-11932 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access ...
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack.
NVD HIGH: CVE-2026-10543 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privil...
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security . Nightmare Eclipse has not provided the further details we req
Researcher creates workaround for Microsoft Defender security patch
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security . As of publication time, neither Microsoft nor Nightmare E
Axonius CEO Warns AI Deepens Asset Visibility Gaps
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/axonius-ceo-warns-ai-deepens-asset-visibility-gaps-image_small-10-a-32534.jpg" align=right hspace=4><b>Diamond: AI Agents Can Interact With Cloud Apps and Endpoints Across the Enterprise</b><br>Axonius CEO Joe Diamond said rapid AI adoption is deepening enterprise visibility gaps as security teams struggle to identify AI agents, m
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]
73 Strings makes leadership appointments
73 Strings, the AI-powered platform for private markets valuation and portfolio intelligence, today announced a series of senior leadership appointments following a period of rapid client growth and increasing adoption among the private capital community.
NVD HIGH: CVE-2026-73332 — CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_con...
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in vic
NVD HIGH: CVE-2026-73331 — CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that all...
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing SQL syntax that the database backend evaluates as part of an inadequately parameterized query. Attackers can supply malicious slug payloads using boolean- or union-style blind SQL injection techniques to extra
NVD HIGH: CVE-2026-73326 — CamaleonCMS contains a missing authorization vulnerability that allows any authe...
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to al
NVD CRITICAL: CVE-2026-73269 — A flaw was found in the cluster-curator-controller component. A local user, by c...
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access
NVD CRITICAL: CVE-2026-73268 — A flaw was found in the cluster-curator-controller component of multicluster eng...
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected
NVD HIGH: CVE-2026-72809 — SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass v...
SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0.1) for a specific set of endpoints (including /api/system/exit, getNetwork, getWorkspaceInfo, /assets/*, and /export/*). These localhost bypasses sit outside the
NVD HIGH: CVE-2026-72804 — SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph...
SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read protected document content and the complete reference topology.
NVD HIGH: CVE-2026-72801 — SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation materia...
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.
NVD HIGH: CVE-2026-72798 — SiYuan versions before v3.7.4 fail to properly filter related-database content i...
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block ty
NVD HIGH: CVE-2026-72795 — SiYuan versions before v3.7.4 fail to filter embedded block content by publish a...
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
NVD HIGH: CVE-2026-72794 — siyuan versions before v3.7.4 expose the session cookie signing key through the ...
siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access.
NVD HIGH: CVE-2026-72793 — SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the...
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate
NVD HIGH: CVE-2026-72789 — SiYuan before v3.7.4 fails to properly validate publish access for encrypted not...
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
NVD CRITICAL: CVE-2026-72508 — A flaw was found in the multicloud-operators-subscription component of Red Hat A...
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege esc
NVD HIGH: CVE-2026-67579 — Deserialization of Untrusted Data vulnerability in ash-project ash allows an una...
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset pagination decode the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex using
NVD HIGH: CVE-2026-18099 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input.
NVD HIGH: CVE-2026-17642 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-17445 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name.
NVD HIGH: CVE-2026-17417 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters.
NVD HIGH: CVE-2026-17111 — IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker co...
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
NVD CRITICAL: CVE-2026-17083 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
NVD HIGH: CVE-2026-17082 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name.
NVD HIGH: CVE-2026-13361 — IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
NVD HIGH: CVE-2026-13267 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access ...
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 could allow an authenticated user to gain privileges of another user via a specially crafted request.
NVD HIGH: CVE-2026-12618 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access ...
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
NVD HIGH: CVE-2026-12359 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access ...
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.
NVD HIGH: CVE-2026-12005 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access ...
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
NVD HIGH: CVE-2026-12004 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access ...
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by crafting a malicious HTTP request.
NVD HIGH: CVE-2026-11923 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access ...
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation
Key Takeaways Cloud environments change continuously, while security still relies on periodic scans, leaving gaps where risks go undetected. That gap becomes exposure. Qualys Real-Time CSPM monitors cloud changes as they happen, while still supporting periodic scans for environments that require them. It evaluates each finding in context by correlating posture data with vulnerabilities, asset [
Hundreds of fake Chrome VPN extensions route traffic through a proxy
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]
NVD HIGH: CVE-2026-73327 — Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate ext...
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be wr
NVD HIGH: CVE-2026-18713 — IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator ...
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
NVD HIGH: CVE-2026-18669 — IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the resu...
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
NVD HIGH: CVE-2026-17418 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
NVD CRITICAL: CVE-2026-17276 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
NVD HIGH: CVE-2026-17271 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
NVD HIGH: CVE-2026-17248 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to caus...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
NVD CRITICAL: CVE-2026-17218 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
NVD HIGH: CVE-2026-17110 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
NVD CRITICAL: CVE-2026-16956 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute ...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-16931 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of ...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options.
NVD HIGH: CVE-2026-16907 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.
NVD HIGH: CVE-2026-16906 — IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitr...
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.
NVD HIGH: CVE-2026-16904 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment.
NVD HIGH: CVE-2026-16863 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
NVD CRITICAL: CVE-2026-16860 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
NVD HIGH: CVE-2026-16856 — IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due ...
IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.
Bitwise Asset Management axes 14% of jobs
US crypto index fund manager Bitwise Asset Management has becomes the latest digital assets player to take an axe to its workforce, reducing its headcount by around 14%, according to Bloomberg.
N26 adds Wero payments to app
N26 today launched Wero, the digital wallet and instant payment solution developed by the European Payments Initiative (EPI), directly within the N26 app. The new feature enables customers in Germany and France to send and receive money in seconds using only a phone number or email address, removing the need to share or enter an IBAN.
Crypto.com launches tokenised US equities and ETFs in Europe
Crypto.com has launched Tokenized Stocks* - a new way for users to gain exposure to U.S. equities and ETFs directly through the Crypto.com App. Initially offering exposure to 1,500 underlying stocks and funds, access is available from as little as US$1.
Zoom Flaws Facilitate Zero-Click Remote Code Execution
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/zoom-flaws-facilitate-zero-click-remote-code-execution-image_small-8-a-32531.jpg" align=right hspace=4><b>Patch Now: Outdated Zoom Clients Still Vulnerable to Malicious Meeting Participants</b><br>Security experts are urging all Zoom users to patch their client, after the video communications giant fixed flaws that a malicious par
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
FBI: Hackers using social engineering to breach accounts and steal explicit content
Leaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.
NVD HIGH: CVE-2026-48554 — Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authen...
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable position, authenticated UI users can run arbitrary commands as the nagios user. Exploitation requi
NVD HIGH: CVE-2026-48553 — Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authen...
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a shell-executed command line, an authenticated attacker with NRDP access can inject OS commands through the macro value. Expl
NVD HIGH: CVE-2026-48551 — Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site req...
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.
NVD HIGH: CVE-2026-18847 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to ha...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
NVD HIGH: CVE-2026-18683 — IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator...
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
NVD HIGH: CVE-2026-18499 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerab...
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.
NVD HIGH: CVE-2026-18098 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw.
NVD HIGH: CVE-2026-17095 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.
NVD HIGH: CVE-2026-17094 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Israeli cyber firm Dream said the framework adapted mid-operation, corrected its mistakes and expanded as it went along. The post Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan appeared first on CyberScoop .
CA: Snoopers Beware; NL’s Privacy Commissioner Recommends Naming Individuals in Snooping-Related Breaches
VOCM reports: The province’s Privacy Commissioner is recommending that public bodies consider providing the name of anyone involved in snooping-related privacy breaches to affected individuals. The recommendation comes after an employee of NL Health Services had a peek at a person’s health record. NLHS was notified. The Privacy Commissioner says the health authority took the appropriate steps... S
Walmart Takes a 'Trusted Agent' Approach to Purple Teaming
Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises
Walmart's "Trusted Agent" Approach to Purple Teaming
Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises
NVD HIGH: CVE-2026-73325 — Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserializati...
Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking Python's pickle machinery during deserialization. Attackers can embed malicious __reduce_
NVD HIGH: CVE-2026-58076 — Apache Airflow's serialization layer reconstructed exception nodes by calling `i...
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoke
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]
Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation
The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to […] The post Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation appeared first on The HIPAA Journal .
RESOURCE: Introducing the Cyber Incident Registry
Over on DysruptionHub, Joseph Topping has introduced a new resource for exploring cyber disruptions, following incidents over time, and uncovering the connections between them: The registry is a research resource focused specifically on cyber disruptions. Each incident profile brings together what is publicly known about what happened, who was affected, the operational impact, the available... Sou
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek .
Flywire expands Trustly partnership to deliver open banking payments across US and Canada
Flywire Corporation (Nasdaq: FLYW), a global payments enablement and software company, today announced expanded support for open banking payments in the U.S. and Canada with Trustly, allowing payers to conveniently authorize secure, large domestic and cross-border payments directly from their bank accounts and in their local currency.
WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
Linux Kernel Process Accounting, (Wed, Aug 12th)
A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash&#;x26;#;x5f;history"&#;x26;#;xc2;&#;x26;#;xa0;and collecting meaningful additional data. Our reader David commented that this can also be done q
FBI: Hackers target online accounts to steal nude photos
The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.
Critical Vulnerabilities Identified in Popular Consumer Fertility Device
Vulnerabilities have been identified in two consumer health and wellness devices – The Mira Hormone Monitor, a popular fertility tracking […] The post Critical Vulnerabilities Identified in Popular Consumer Fertility Device appeared first on The HIPAA Journal .
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Stanbic IBTC Bank upgrades to Nucleus Software FinnAxia 9.0
Stanbic IBTC Bank, a member of Standard Bank Group, and Nucleus Software, a leading provider of lending and transaction banking solutions, have successfully advanced to FinnAxia® 9.0, marking a significant milestone in their long standing partnership and shared commitment to driving innovation in transaction banking.
Kast names Connor Fitzgerald US general manager
Kast, the global financial platform built on stablecoin rails, announced today that Connor Fitzgerald has joined the company as U.S. General Manager.
Mindgard Raises $30 Million to Protect AI Systems
The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams. The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek .
FE fundinfo gives Nexus for Financial Advisers an AI assistant
FE fundinfo today confirmed it is accelerating investment in Nexus for Financial Advisers, a unified, AI-powered workflow platform built on the breadth of FE fundinfo's data, designed to support the entire advice journey by bringing together the disconnected systems most advice firms rely on today.
NVD HIGH: CVE-2026-57858 — Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripti...
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to
Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
Something shifted in security operations over the last two years: AI stopped being a pilot program and became the plan. And if you survey 500 security professionals on whether that's going well – as Omdia did, commissioned by Rapid7 – you get a remarkable level of consensus: 97% report positive outcomes, 98% say AI reduces alert fatigue, and 95% say it's helping address staffing shortages. Those n
WhatsApp Unveils New Scam Alert Feature
Signal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek .
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek .
Three intrusions at UK criminal records office went undetected for two years
Unread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.
Walmart Leaders Transform Security Operations Without Going Bananas
The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency and team spirit are key factors.
Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
This month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.
NIST Seeks Public Input on AI-Ready NVD Modernization
The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research
HSBC invests in AI modelling firm
HSBC Asset Management (HSBC AM), the high street bank's investment management arm, has provided funding for London-based AI startup Model ML.
Hackers leverage new Microsoft SharePoint exploit in attacks
Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.
Siemens RUGGEDCOM APE1808
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for
M&T Bank appoints head of AI engineering
US-based M&T Bank has named Kalyana Bedhu as its new head of AI engineering
Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
From Cloudflare’s new report: Key insights The 1 Tbps club grew. Cloudflare mitigated a combined 935 network-layer DDoS attacks exceeding 1 Tbps in the first half of 2026 and a +519% quarter-over-quarter surge between Q1 and Q2. The attack-vector center of gravity shifted from botnet floods to reflection and amplification. DNS-based attacks accounted for 34.3%... Source
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing,
A serious incident occurred at MyDr, a Polish healthcare system provider
Adam Haertle reports: MyDr has just announced that it is investigating a serious security incident on its network. The alleged perpetrators of this incident contacted us earlier and claimed to have access to patient data from numerous Polish clinics. According to the hackers, they had access to 18,814,422 unique PESEL numbers. MyDr is one of the largest... Source
Enterprise Defenses Recovered at the Edge and Collapsed Inside
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness
Ceva Logistics Operations Disrupted by Cyberattack
Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek .
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance. Researchers from Malwarebytes found the campaign distributing a malicious Chrome extension called GhostDesk, which can capture credentials, cookies, keystrokes, and screenshots while also allowing attackers
Signal adds new security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could
RBI governor tells Indian banks to control AI
India's banking sector must be proactive in its adoption of AI and ensure that it determines how the technology reshapes the industry rather than let the technology dictate the inevitable changes.
California Puts AI Inside Critical Infrastructure Defenses
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/california-puts-ai-inside-its-critical-infrastructure-defenses-image_small-4-a-32525.jpg" align=right hspace=4><b>California Bets on AI Defense as Federal Cyber Funding Dries Up</b><br>California is directing state agencies to build artificial intelligence into the defenses protecting its power, water and transportation networks -
Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution. The post Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined appeared first on SecurityWeek .
Data Breaches Announced by Five Small Healthcare Organizations
Five small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of […] The post Data Breaches Announced by Five Small Healthcare Organizations appeared first on The HIPAA Journal .
CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix
[object Object]
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]
Itau Unibanco joins Brazilian tokenisation pilot
The largest bank in Latin America, Itau Unibanco, has teamed up with digital asset infrastructure provider OpenAssets in joining a tokenisation pilot in Brazil.
Prompt Injections for Defense
This seems to work : Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to pr
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek .
Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL
The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
Coinbase to launch tokenisation hub in Abu Dhabi
Crypto exchange Coinbase has chosen Abu Dhabi as the location for its international tokenisation hub.
Netcompany bolsters financial services division
Former Topdanmark CEO Peter Hermann will become a Partner in Netcompany with responsibility for the company’s ambitions within life & pension and insurance, while Søren Skov Mogensen, currently Group CEO of TITAN Containers and formerly a senior executive at Banking Circle Group and Danske Bank, will become the new CEO of Netcompany Banking Services.
Cashi launches stablecoin app
Cashi today launched its app and card in public beta, giving people a simple way to hold stablecoins and spend them like cash.
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were
4 gaps slowing AI in enterprise SOCs
Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-driven security software, many enterprise SOCs are struggling to translate AI into measurable operational improvements. The issue isn’t whether AI belongs in the SOC. It does. The challenge is that many organizations are approaching AI adoption in cybersecurity w
DASH names chief executive
Integrated financial planning software and investment platform, DASH Technology Group (DASH), has appointed experienced fintech and wealth management executive, Glenn Poynton, as chief executive officer, signaling the group’s focus on strengthening delivery for advisers and clients as it builds for its next phase of growth.
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek .
The AI harness is the new attack surface
Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted. That instinct is increasingly out of date. A growing body of security research — exploit demonstrations, independent red-teaming, and assessments by security researchers— points to the code sitt
NVD HIGH: CVE-2025-41770 — An unauthenticated denial-of-service vulnerability in the device's PLCnext Engin...
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.
NVD CRITICAL: CVE-2025-41769 — The device's PROFINET service is affected by a buffer overflow vulnerability tha...
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
Weekly Update 516: Live From Vietnam
A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to
Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek .
Microsoft Fixes 400 Flaws on August Patch Tuesday
Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek .
17 old software bugs that took way too long to squash
In 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code. Shockingly, the vulnerable code was almost 54 years old — and there was no patch available, and no expectation that one would be forthcoming. Fortunately, that’s because the system in question was Marvin Minsky’s 1967 implementation of a Un
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek .
The Agent Baseline: 35 controls, but where should you start?
The Agent Baseline defines 35 controls across six security outcomes—but the right starting point depends on how your organization uses agents. Learn how to sequence controls for coding, internal, and production agents.
NVD HIGH: CVE-2026-18961 — The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by Ventr...
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me endpoint as proof of mailbox ownership — Generic::normalize_common() copies this valu
Metabase SQLi exploit grants attackers total access
Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed. The Metabase vulnerability revealed on August 6, designated CVE-2026-72898 , is identified as critical, with a severity score of 10, the highest possible rating. It is present in versions 1
NVD HIGH: CVE-2026-73122 — A flaw was found in the multicloud-operators-channel component of Red Hat Advanc...
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm
NVD CRITICAL: CVE-2026-72526 — A flaw was found in the multicloud-integrations component. The Application propa...
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attac
NVD CRITICAL: CVE-2026-70398 — A flaw was found in multicloud-integrations, a component of Red Hat Advanced Clu...
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to
NVD HIGH: CVE-2026-66878 — A flaw was found in multicloud-operators-subscription. A privileged user, specif...
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock ( CVE-2026-68820 ), which, according to Todd Schell , principal product manager at Ivanti, has been a recurring target f
Kimwolf botnet rebuilt to survive takedowns, researchers say
Months after police seized its servers and arrested an alleged operator, the Kimwolf botnet is running code that disguises attacks as Chrome traffic and fetches its orders from the Ethereum blockchain. The post Kimwolf botnet rebuilt to survive takedowns, researchers say appeared first on CyberScoop .
Amex Ventures invests in autonomous finance startup Fazeshift
American Express's corporate venture arm has invested in Fazeshift, an AI-native platform deploying autonomous agents to execute end-to-end accounts receivable workflows.
Nasdaq to buy ATS LeveL Markets
Exchange operator Nasdaq has reached a deal to buy Alternative Trading System (ATS) LeveL Markets. Terms were not disclosed.
Federal judge issues second order blocking Trump mail-in voting directive
The U.S. Supreme Court temporarily reversed an earlier decision through the shadow docket. The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop .
Mistral Expands Sovereign AI Push With European Compute
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/mistral-expands-sovereign-ai-push-european-compute-image_small-6-a-32527.jpg" align=right hspace=4><b>French AI Firm Adds Regional Inference, Open Models and Compute Capacity</b><br>French AI company Mistral is expanding its sovereign AI strategy in Europe with regional inference, access to third-party open-weight models and plans
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them. Three of the vulnerabilities affect all Zoom client applications for all platforms before versions 7.1.5 and 7.0.6, while the fourth impacts Zoom Workplace VDI Clie
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
NVD CRITICAL: CVE-2026-5917 — libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_...
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository
NVD HIGH: CVE-2026-29036 — cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or refe...
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to app
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]
California Puts AI Inside Its Critical Infrastructure Defenses
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/california-puts-ai-inside-its-critical-infrastructure-defenses-image_small-4-a-32525.jpg" align=right hspace=4><b>California Bets on AI Defense as Federal Cyber Funding Dries Up</b><br>California is directing state agencies to build artificial intelligence into the defenses protecting its power, water and transportation networks -
Rapid7 Lays Off 12% of Staff as New CEO Reshapes Cyber Firm
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/rapid7-lays-off-12-staff-as-new-ceo-reshapes-cyber-firm-image_small-6-a-32526.jpg" align=right hspace=4><b>New CEO Wael Mohamed Targets Efficiency, Product Modernization and Higher Win Rates</b><br>Boston-based Rapid7 will cut roughly 314 jobs, or 12% of its workforce, as new CEO Wael Mohamed restructures the managed cybersecurity
Microsoft Patch Tuesday, August 2026 Security Update Review
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security.  Microsoft Patch Tuesday for August 2026  This month
Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security.  Microsoft Patch Tuesday for August 2026  This month
Microsoft's Patch Tuesday Deluge Continues With August Updates
Security experts say prioritization should be the main focus for the August updates, not the massive CVE volume.
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for on
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. [...]
ISMG Security Report: Could Hackers Read Patients' Thoughts?
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-security-report-implantable-brain-devices-hackers-image_small-6-a-32510.jpg" align=right hspace=4><b>Neural Implants Bring Hope for Treatment, But Pose New Cybersecurity Headaches</b><br>Implantable neural devices that plug into a patient's brain or spinal cord are offering transformative clinical therapy for illnesses such a
Post-Quantum Deadlines Collide With OT Reality
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/post-quantum-deadlines-collide-ot-reality-image_small-9-a-32524.jpg" align=right hspace=4><b>Practitioners Warn Software Upgrades Alone Won't Prepare Critical Infrastructure</b><br>Quantum-safe algorithms are here, but OT isn't ready to run them. Nearly all critical infrastructure - power grids, water systems and transportation ne
NVD CRITICAL: CVE-2026-73034 — DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allo...
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipart upload request with a traversal-poisoned user_id header to escape the intended upload directory an
NVD CRITICAL: CVE-2026-73032 — PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that a...
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt injection in PDFs, MITM interception of API requests, or a malicious custom LLM endpoint to execute arbitrary code in Zotero
NVD HIGH: CVE-2026-73031 — telegram-search contains a stored cross-site scripting vulnerability that allows...
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. The highlightKeyword function in MessageList.vue passes raw message content directly to v-html without HTML escaping or sanitization, enabling stored, cross-user, ze
NVD HIGH: CVE-2026-19091 — The GeoDirectory – WP Business Directory Plugin and Classified Listings Director...
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, whi
NVD CRITICAL: CVE-2026-16230 — The Formidable Digital Signatures plugin for WordPress is vulnerable to file del...
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only
NSA installs DHS lawyer as new general counsel
Kerianne Tobitsch, who most recently served as a senior lawyer at the Homeland Security Department, is the NSA's new general counsel, sources told Recorded Future News.
Apple Pay and Wallet chief Bailey to leave
Apple's head of payment and wallet services, Jennifer Bailey, is leaving after 23 years at the tech giant.
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. [...]
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. "Kimwolf v7 adds an HTTP/2-based
NVD HIGH: CVE-2026-72742 — DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio o...
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed output. The JSONAdapter and ChatAdapter parse untrusted language model completions through parse_value into TypeAdapter v
NVD HIGH: CVE-2026-15426 — The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwri
Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents.
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it
Zoomsday: Zero-click RCE in Zoom, from any meeting participant to any other (CVE-2026-53413)
[object Object]
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek .
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,
Stolen Change Healthcare data gets new handling rules in court order
Naomi Diaz reports: A federal judge in Minnesota has signed off on a strict set of rules for how the data stolen in Change Healthcare’s 2024 cyberattack can be handled during the ongoing lawsuit. Magistrate Judge Dulce J. Foster approved the plan, reviewed by Becker’s, Aug. 7. It applies to the combined lawsuit against UnitedHealth Group and several of... Source
TMX Investor Solutions agrees tech collaboration with Optio Incentives
TMX Investor Solutions, a subsidiary of TMX Group, today announced it has entered into a strategic technology collaboration with Optio Incentives (Optio), a leading global equity compensation and incentive management platform headquartered in Oslo, Norway.
Microsoft releases Windows 10 KB5120249 extended security update
Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. [...]
NVD CRITICAL: CVE-2026-71398 — Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi...
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
NVD CRITICAL: CVE-2026-71362 — Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul...
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
NVD CRITICAL: CVE-2026-69102 — MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT sig...
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and
NVD HIGH: CVE-2026-48416 — Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul...
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
NVD HIGH: CVE-2026-48415 — Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul...
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.
NVD HIGH: CVE-2026-48413 — Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability ...
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope i
NVD CRITICAL: CVE-2026-48381 — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia...
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not req
NVD CRITICAL: CVE-2026-27302 — Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi...
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
NVD HIGH: CVE-2022-50997 — Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in t...
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data
NVD HIGH: CVE-2016-20097 — Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the Signa...
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a SQL query. Attackers can control the markPath value returned by the query to supply an attacker-controlled filesystem path
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]
AI-native clearinghouse for insurance Axle raises $17.5m
Axle, the AI-native clearinghouse for insurance, today announced $17.5M in Series A funding led by Base10 Partners. The round included continued investment from Y Combinator and Gradient, with participation from Stage 2 Capital and industry angels including the founders of CoverGenius.
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs. 
Police Federal Credit Union rolls out Mahalo digital banking tech
Police Federal Credit Union (‘Police FCU’) has successfully launched the Mahalo BankingThoughtful Banking platform, completing its digital banking implementation in tandem with its core conversion to Corelation KeyStone. The credit union can now better align with evolving member expectations for real-time, convenient access to funds.
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
How Trail of Bits helps verify the integrity of your Signal chats
<p>Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt messages to an attacker rather than the intended recipient.</p> <p>Until now, the only way to detect such malfeasance w
NVD CRITICAL: CVE-2026-71384 — is affected by an Incorrect Authorization vulnerability that could result in a S...
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this is
NVD HIGH: CVE-2026-70355 — Improper neutralization of input during web page generation ('cross-site scripti...
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
NVD HIGH: CVE-2026-70354 — Out-of-bounds write in .NET allows an unauthorized attacker to execute code loca...
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
NVD HIGH: CVE-2026-70340 — Missing authorization in Azure CycleCloud allows an authorized attacker to eleva...
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
NVD HIGH: CVE-2026-70338 — Improper control of generation of code ('code injection') in Microsoft PowerShel...
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
NVD HIGH: CVE-2026-70336 — Improper control of generation of code ('code injection') in Visual Studio Code ...
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-70330 — Heap-based buffer overflow in Windows DNS allows an authorized attacker to eleva...
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
NVD CRITICAL: CVE-2026-70306 — Improper neutralization of input during web page generation ('cross-site scripti...
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
NVD HIGH: CVE-2026-70304 — Heap-based buffer overflow in Windows DNS allows an authorized attacker to eleva...
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-70130 — Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t...
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
NVD HIGH: CVE-2026-69278 — Incorrect authorization in Visual Studio Code allows an unauthorized attacker to...
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
NVD HIGH: CVE-2026-68821 — Improper privilege management in Windows Package Manager allows an authorized at...
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-68819 — Buffer over-read in Windows Network File System allows an unauthorized attacker ...
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
NVD HIGH: CVE-2026-66804 — Improper access control in Windows Cross Device Service allows an authorized att...
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-65813 — Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author...
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
NVD HIGH: CVE-2026-65810 — Relative path traversal in .NET Framework allows an unauthorized attacker to ele...
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-65799 — Integer overflow or wraparound in Windows DNS allows an authorized attacker to e...
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-65796 — Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize...
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
NVD CRITICAL: CVE-2026-65791 — Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize...
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-65783 — Use after free in Windows Autopilot allows an authorized attacker to elevate pri...
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-65778 — Use after free in Windows Autopilot allows an authorized attacker to elevate pri...
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-65769 — Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mo...
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
NVD CRITICAL: CVE-2026-65768 — Improper limitation of a pathname to a restricted directory ('path traversal') i...
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-65767 — Improper neutralization of input during web page generation ('cross-site scripti...
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
NVD HIGH: CVE-2026-65675 — No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an una...
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
NVD HIGH: CVE-2026-65672 — Heap-based buffer overflow in Windows Remote Access API allows an authorized att...
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-62914 — Improper neutralization of input during web page generation ('cross-site scripti...
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
NVD HIGH: CVE-2026-62910 — Improper control of resource identifiers ('resource injection') in Microsoft Exc...
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
NVD HIGH: CVE-2026-62901 — Unchecked input for loop condition in .NET allows an unauthorized attacker to de...
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
NVD CRITICAL: CVE-2026-62893 — Use after free in Windows Deployment Services allows an unauthorized attacker to...
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
NVD CRITICAL: CVE-2026-62878 — Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to ex...
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
NVD CRITICAL: CVE-2026-62815 — Use after free in Microsoft QUIC allows an unauthorized attacker to execute code...
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-62782 — Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disc...
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
NVD HIGH: CVE-2026-62777 — Missing authentication for critical function in Windows License Manager allows a...
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-62772 — Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unio...
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-62707 — Use after free in Windows Modern Device Management (MDM) allows an authorized at...
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-62702 — Null pointer dereference in Windows Graphics Kernel allows an unauthorized attac...
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
NVD HIGH: CVE-2026-61924 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d...
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
NVD HIGH: CVE-2026-61918 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d...
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
NVD HIGH: CVE-2026-61363 — Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac...
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-61359 — Heap-based buffer overflow in Windows Storage allows an authorized attacker to e...
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-61358 — Improper link resolution before file access ('link following') in Windows Access...
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-61357 — Use after free in Application Information Services allows an authorized attacker...
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-61352 — Concurrent execution using shared resource with improper synchronization ('race ...
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-61346 — Use after free in Windows Graphics Kernel allows an authorized attacker to eleva...
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-59134 — Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac...
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-59125 — Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized a...
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
NVD CRITICAL: CVE-2026-59124 — Deserialization of untrusted data in Microsoft High Performance Computing (HPC) ...
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-59122 — Concurrent execution using shared resource with improper synchronization ('race ...
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-59113 — Missing authorization in Visual Studio Code allows an unauthorized attacker to e...
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-58650 — Authorization bypass through user-controlled key in Visual Studio Code allows an...
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
NVD HIGH: CVE-2026-58641 — Integer overflow or wraparound in .NET allows an unauthorized attacker to elevat...
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-58612 — Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauth...
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
NVD HIGH: CVE-2026-57105 — Improper neutralization of input during web page generation ('cross-site scripti...
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
NVD HIGH: CVE-2026-57104 — Improper neutralization of input during web page generation ('cross-site scripti...
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
NVD HIGH: CVE-2026-56179 — Origin validation error in Windows Network Address Translation (NAT) allows an u...
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
NVD HIGH: CVE-2026-56174 — Untrusted search path in Windows Narrator Braille allows an authorized attacker ...
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-54984 — Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a...
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
NVD HIGH: CVE-2026-54981 — Inclusion of functionality from untrusted control sphere in Visual Studio Code -...
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
NVD HIGH: CVE-2026-54113 — Allocation of resources without limits or throttling in Windows Kernel allows an...
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
NVD CRITICAL: CVE-2026-50516 — Missing authentication for critical function in Microsoft Azure Kubernetes Servi...
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
NVD HIGH: CVE-2026-50472 — Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to ele...
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-49179 — Improper neutralization of special elements used in a command ('command injectio...
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
NVD HIGH: CVE-2026-48442 — CAI Content Credentials is affected by an Improper Limitation of a Pathname to a...
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is chang
NVD HIGH: CVE-2026-48439 — CAI Content Credentials is affected by an Uncontrolled Resource Consumption vuln...
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
NVD HIGH: CVE-2026-48438 — CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability ...
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
NVD CRITICAL: CVE-2026-48362 — ColdFusion is affected by an Improper Neutralization of Special Elements used in...
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
NVD HIGH: CVE-2026-47299 — Improper neutralization of special elements used in a command ('command injectio...
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
NVD HIGH: CVE-2026-42976 — Missing authentication for critical function in Windows RPC API allows an author...
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
NVD HIGH: CVE-2026-21273 — is affected by an Improper Input Validation vulnerability that could result in p...
is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Alert: Unpatched Fortinet Devices Fall to Gunra Ransomware
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/alert-unpatched-fortinet-devices-fall-to-gunra-ransomware-image_small-9-a-32518.jpg" align=right hspace=4><b>US and South Korea Tie Initial Access to Unpatched Firewalls and VPN Gateways</b><br>Critical infrastructure organizations running unpatched firewalls and VPN gateways - including Fortinet gear not updated since early 2025
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
The security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek .
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat
UK parliamentarians question banks over refusal to provide services to crypto firms
A group of UK politicians have written to the CEOs of the country's major banks asking them to clarify their approach to providing services to crypto and digital asset firms.
NVD HIGH: CVE-2026-19546 — A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for ...
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, the FBI, and international partners have issued a joint cybersecurity advisory about the Gunra ransomware-as-a-service (RaaS) operation, which is […] The post Healthcare Orgs Warned About Gunra Ransomware Attacks appeared first on The HIPAA Journal .
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]
AI Genie in the Wild
When I give talks about AI genies , I use this sort of example as a hypothetical. It’s happened . The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible. Andrew, who was sitting fourt
Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek .
Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
Operations at eight European warehouses belonging to France's CEVA Logistics have reportedly been disrupted by a cyberattack, and several other companies are feeling the effects.
NIST wants to overhaul its vulnerability database for the AI age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. The post NIST wants to overhaul its vulnerability database for the AI age appeared first on CyberScoop .
CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106)
[object Object]
Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages queried an Ethereum wallet to locate C2 infrastructure
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. The post The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It appeared first on SecurityWeek .
Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Cursor fixed a pre-trust code execution path in three days then closed the report as informative
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek .
RBC and BMO agree C$2bn Moneris sale
Royal Bank of Canada and Bank of Montreal have agreed a C$2 billion cash deal to sell payments processing joint venture Moneris to private equity firm Francisco Partners.
Mastercard names Yasemin Bedir president, Eemea
Mastercard today announced that Yasemin Bedir has been appointed President of the company’s Eastern Europe, Middle East and Africa (EEMEA) region, effective 1 September.
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek .
Cashi picks Thredd to power stablecoin spending card
Thredd, the AI-first issuer processing platform, today announced that it has been selected by Cashi to power its new stablecoin spending and cashback card programme, now live in Hong Kong, with expansion into Mexico set for late 2026.
Allvue Systems today launched Intelligent Loan Operations
Allvue Systems today launched Intelligent Loan Operations, uniting the full lifecycle of a loan transaction — from the moment a notice arrives from a loan agent to the moment its data is consolidated into the general ledger — on a single platform powered by agentic AI.
Thomaston Savings Bank signs for Diebold Nixdorf ATMs
Diebold Nixdorf (NYSE: DBD), a world leader in transforming the way people bank and shop, today announced that Thomaston Savings Bank is modernizing its self-service network with DN Series® ATMs, the company's latest terminal application software and comprehensive managed services.
Cleversoft to buy FS Assist to expand insurance reporting footprint
The cleversoft group, a leading provider of regulatory technology solutions for the financial services industry, today announced the signing of a definitive agreement to acquire UK-based FS Assist, a trusted specialist in regulatory reporting software for insurers and pension providers.
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]
NVD HIGH: CVE-2026-72778 — Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6...
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but Conditions::createCondition() later decodes and merges the JSON string in condition.config without re-runn
NVD CRITICAL: CVE-2026-72748 — AVideo contains an unauthenticated arbitrary file write vulnerability in the aVi...
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achiev
NVD HIGH: CVE-2026-72747 — AVideo fails to sanitize the phone field during user registration, allowing unau...
AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.
NVD HIGH: CVE-2026-72745 — FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in kerberos_Decryp...
FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in kerberos_DecryptMessage() (winpr/libwinpr/sspi/Kerberos/kerberos.c). The 16-bit EC (extra count) field of a peer-supplied GSS Wrap token (RFC 4121) is used directly in pointer arithmetic to locate the encrypted regions without being bounds-checked, while only RRC and the total buffer length are validated. A malicious peer (server or
NVD HIGH: CVE-2026-69109 — A vulnerability has been identified in Siemens License Server (SLS) (All version...
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.
NVD HIGH: CVE-2026-64629 — A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235...
A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
NVD HIGH: CVE-2026-59700 — A vulnerability has been identified in Simcenter Femap (All versions < V2606.000...
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
NVD CRITICAL: CVE-2026-58115 — A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1...
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attac
NVD HIGH: CVE-2026-50064 — A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 ...
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.
NVD HIGH: CVE-2026-50062 — A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 ...
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
NVD HIGH: CVE-2026-50060 — A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 ...
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
NVD HIGH: CVE-2026-50059 — A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 ...
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. [...]
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script . Figure 1: The Rapid7 Labs PoC for CVE-2026-55040. ⠀ A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authen
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first
DDoS attacks over 1 Tbps surged fivefold in the second quarter
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]
Local governments in four states dealing with cyberattacks that have shut down services
Municipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations.
NAB to reshuffle tech leadership
National Australia Bank (NAB) has moved to replace the leader of its technology division as well as its chief operating officer.
NVD HIGH: CVE-2026-50237 — A Server-Side Request Forgery and supply chain flaw was found in the OpenShift C...
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
NVD HIGH: CVE-2026-50236 — An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhoo...
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
Kids’ online safety bill faces dim prospects of passage this session despite progress
Proponents of the Kids Online Safety Act are cheering recent progress but acknowledge a long road ahead for legislation that, despite mounting political pressure, may be difficult to pass this session.
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with. That decision carries a cost for
Brazil to expand Pix payment system
Brazil's central bank is considering expanding the scope of its instant payments system Pix to integrate it with other international systems.
GitHub already has an EDR. You just have to listen to it
Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said. At their Black Hat USA 2026 presentation, researchers Yossi Weizman of Microsoft and Mor Weinberger of Echo argued the case, saying, “GitHub can tell you’re being hacked. You’re just not listening.” The duo described an EDR-style detection a
Corma Raises $60 Million for Defensive Cybersecurity AI Model
Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue. The post Corma Raises $60 Million for Defensive Cybersecurity AI Model appeared first on SecurityWeek .
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks
Police and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week also
Johnson Controls C-CURE 9000 and Victor application server (Update A)
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.</strong></p> <p>The following versions of Johnson Controls C-CURE 9000 and Victor application server (Updat
Mira Hormone Monitor, Mira Android App
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information,
Pulsetto Vagus Nerve Stimulator
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings.</strong></p> <p>The following versions of Pulsetto Vagu
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The
OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models
OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window
OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats. Daybreak now has two access levels. Blue gives approved defenders access to frontier general-purpose models such as GPT-5.6 Sol for authorized defensive work, while
AI for Military Support
Interesting empirical research: “ Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI .” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a high-fidelity replica of an AI decision-support system (DSS) used in military targeting. After reconstructing the interfac
NVD CRITICAL: CVE-2026-58231 — SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent...
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek .
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]
Court Sets Strict Security for Change Health's Stolen Data
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/court-sets-tight-security-for-change-healths-stolen-data-image_small-8-a-32507.jpg" align=right hspace=4><b>Plaintiffs, Experts Face Strict Rules for Handling Data Stolen in 2024 Attack</b><br>A federal court last week approved stringent security requirements on how plaintiffs' attorneys and experts must safeguard a copy of stolen
China-Linked Hackers Use N-able Flaw in Ransomware Attacks
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-image_small-6-a-32506.jpg" align=right hspace=4><b>Microsoft Says Storm-1175 Exploited CVE-2026-18577 After Its Disclosure</b><br>Microsoft says China-linked Storm-1175 is exploiting N-able N-central authentication bypass CVE-2026-18577 to gain administrative RMM acces
Banks facing AI concentration risk
The banking sector is at risk of being beholden to a limited number of AI vendors according to rating agency Moody's.
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let
Data Breaches Reported by Sunshine Health; Health Payment Systems
A vishing attack on Sunshine Health, a Florida-based Medicaid and health insurance agency, involved the theft of the PHI of […] The post Data Breaches Reported by Sunshine Health; Health Payment Systems appeared first on The HIPAA Journal .
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42 .
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek .
Insurtech funding hits four-year high
Funding for the insurtech sector surged to its highest level in four years in Q2, helped by a number of megadeals mainly focused on AI.
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI. The post OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber appeared first on SecurityWeek .
Emirates NBD and DFDF launch fintech fund
Emirates NBD, a leading banking group in the Middle East, North Africa, Türkiye and South Asia (MENATSA) region, has announced a strategic partnership with Dubai Future District Fund (DFDF) to drive FinTech and AI innovation and enhance customer experience.
NVD HIGH: CVE-2026-72694 — A flaw was found in MRTG. When the MRTG daemon is started as a root user and sub...
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. Thi
NVD HIGH: CVE-2026-72693 — `openvt -u` is intended to identify the owner of the current VT and then execute...
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node
NVD HIGH: CVE-2026-15567 — A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOf...
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
NVD HIGH: CVE-2026-15565 — A flaw was found in Undertow. A remote attacker can cause Out of Memory on webso...
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
NVD HIGH: CVE-2026-15563 — A flaw was found in EAP's IIOP. The listener's NameService would accept bind ope...
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
NVD HIGH: CVE-2026-15562 — A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who ...
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.
NVD HIGH: CVE-2026-15561 — A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing li...
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
NVD HIGH: CVE-2026-15560 — when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplie...
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.
NVD HIGH: CVE-2026-15556 — A flaw was found in Picketlink's SP signature validation; a SAML response contai...
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
NVD HIGH: CVE-2026-15555 — A flaw was found in JBoss marshalling. The Infinispan session replication path d...
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.
NVD HIGH: CVE-2026-15554 — the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes with...
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.
NVD CRITICAL: CVE-2026-10579 — A flaw was found in Picketlink Federation SAML; the unsolcited response handler ...
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of
Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of
United Fintech installs senior leadership team
United Fintech has appointed three new partners and established a senior leadership team, putting in place a long-term partnership model as the company enters its next chapter as trusted, neutral infrastructure for wholesale finance.
OpenAI Pauses Some Development of Astra Model on Security Concerns
OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns
Security leaders’ rogue AI confidence could actually be disastrous
A large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope. Nine in 10 IT and security leaders surveyed by IT observability vendor WanAware believe in their capabilities to find malfunctioning agents, but only 26% acknowledge that
Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat
Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek .
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
NVD CRITICAL: CVE-2026-19425 — Travel Agency Management System developed by Win Men Intermational has a SQL Inj...
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
NVD HIGH: CVE-2026-19424 — Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Refe...
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
The future of AI security research isn’t autonomous, it’s human-amplified
Meet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.” But it didn’t do it alone; it was guided by a human the entire time, which may be the most interesting finding of all. A researcher from security company PortSw
NVD HIGH: CVE-2026-66763 — SAP BusinessObjects Business Intelligence Platform stores certain sensitive cred...
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected inform
NVD HIGH: CVE-2026-58243 — SAP ABAP Development Tools does not perform necessary authorization checks for c...
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality
NVD HIGH: CVE-2026-58230 — SAP Approuter does not sufficiently validate certain token content under specifi...
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality
NVD HIGH: CVE-2026-44765 — Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integrat...
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, in
NVD HIGH: CVE-2026-44764 — Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integrat...
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed
NVD HIGH: CVE-2026-44763 — SAP Manufacturing Integration and Intelligence allows a privileged attacker to e...
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the i
NVD CRITICAL: CVE-2026-44758 — SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig...
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability
NVD CRITICAL: CVE-2026-34265 — SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl...
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
Astraeus launches wealth management infrastructure platform
Former staffers at mobile banking firm MoneyLion have raised over $10 million for an AI-native infrastructure platform for wealth management firms.
More than half of Brits lose money acting on social media financial advice
Over half of Brits who have acted on financial advice on social media have lost money as a result, according to a TSB survey.
Meta Puts Open-Source AI Bet on Muse Glimmer
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/meta-puts-open-source-ai-bet-on-muse-glimmer-image_small-1-a-32508.jpg" align=right hspace=4><b>Local Agentic AI Model Targets Coding, Tool Calling and Multi-Step Tasks</b><br>Meta hopes to recapture the momentum it had when it first launched its Llama artificial intelligence model. Now, with a new model and an increased focus on
CISA KEV: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CISA KEV: Microsoft Windows Ancillary Function Driver for WinSock — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CISA KEV: Metabase Metabase — Metabase SQL Injection Vulnerability
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]
Obsidian Secures $85M to Control AI Agents in SaaS Apps
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/obsidian-secures-85m-to-control-ai-agents-in-saas-apps-image_small-10-a-32511.jpg" align=right hspace=4><b>CEO Hasan Imam Says AI Agents Are Already Modifying and Deleting Enterprise Data</b><br>Obsidian Security raised $85 million at a $1.1 billion valuation to expand real-time monitoring and enforcement as enterprises give auton
Court Sets Tight Security for Change Health's Stolen Data
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/court-sets-tight-security-for-change-healths-stolen-data-image_small-8-a-32507.jpg" align=right hspace=4><b>Plaintiffs, Experts Face Strict Rules for Handling Data Stolen in 2024 Attack</b><br>A federal court last week approved stringent security requirements on how plaintiffs' attorneys and experts must safeguard a copy of stolen
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42 .
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
Multistate Water System Attacks Widen, Iran Suspected
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
The FTC wants to regulate AI for ideological bias
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech. The post The FTC wants to regulate AI for ideological bias appeared first on CyberScoop .
NVD HIGH: CVE-2026-73030 — unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulne...
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
NVD HIGH: CVE-2026-63622 — A flaw was found in libvirt. A local attacker, specifically a process running as...
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for
NVD HIGH: CVE-2026-18982 — A flaw was found in the RHOAI training-operator. This vulnerability allows a use...
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissio
NVD HIGH: CVE-2026-18951 — A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training op...
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrar
NVD HIGH: CVE-2026-18950 — A flaw was found in odh-dashboard. An authenticated user of the dashboard can ex...
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access withi
NVD HIGH: CVE-2026-18949 — A flaw was found in odh-dashboard. This vulnerability allows an attacker, who ha...
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.
NVD CRITICAL: CVE-2026-18948 — A flaw was found in Feast. The system improperly deserializes user-defined funct...
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the regis
NVD HIGH: CVE-2026-18947 — A flaw was found in Feast. An authorization bypass vulnerability exists in the /...
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The cons
NVD HIGH: CVE-2026-18941 — A flaw was found in Feast and feast-operator. The default configuration for both...
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (R
NVD HIGH: CVE-2026-18621 — A flaw was found in Data Science Pipelines (DSP). An attacker with namespace edi...
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code
NVD HIGH: CVE-2026-18620 — A flaw was found in Data Science Pipelines. A restricted user, or tenant, can ex...
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclos
NVD HIGH: CVE-2026-18618 — A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata...
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could lead to a denial of service by crashing the MLMD pod, disrupting all pipeline runs
NVD HIGH: CVE-2026-18617 — A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace edit...
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable LOCAL INFILE functionality and exfiltrate sensitive files, such as the service accoun
NVD HIGH: CVE-2026-18611 — A flaw was found in the Data Science Pipelines Operator. This vulnerability allo...
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a cryptographically weak pseudo-random number generator (PRNG) to generate these credentials,
NVD HIGH: CVE-2026-18608 — A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's C...
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be exploited. If the DSPO pod were compromised, an attacker could leverage these priv
NVD HIGH: CVE-2026-15581 — A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability al...
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
NVD HIGH: CVE-2026-15467 — A flaw was found in the trustyai-service-operator's LMEvalJob controller. An aut...
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
NVD CRITICAL: CVE-2026-14450 — A flaw was found in the MaaS API. This vulnerability allows any pod within the c...
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized access and escalate privileges. The concrete consequences include the ability to mint
NVD HIGH: CVE-2026-13717 — A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper conf...
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.