Technology Intelligence

Threats against technology companies, software vendors, cloud services, and tech infrastructure.

1000
Total Reports
227
Critical Threats
270
High Threats
MEDIUMMalwareNEW

Alleged ATM malware creator appears in Nebraska court after arrest

Aguirre was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, becoming the first cybercriminal added to the list.

The Record
MEDIUMAi

South Korean officials believe AI agents were used to hack several banks

The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe a Chinese cybersecurity tool was used to hack the banks’ systems.

The Record
HIGHData Breach

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

Eduard Kovacs reports: The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reuters reported on Tuesday, citing two people familiar with the matter. The FBI has not publicly named the contractor or the organization involved. However, a senior bureau official told Reuters that its... Source

DataBreaches.net
MEDIUMAi

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]

BleepingComputer
MEDIUMVulnerability

ClickFix Attack Hides VBScript Payload in Browser Cache

ClickFix sites stage a VBScript payload in the browser cache to bypass the Run dialog's length limit

Infosecurity Magazine
MEDIUMVulnerability

UK picks banks as lead managers for digital gilt pilot

The UK government has selected six banks as joint lead managers for the Digital Gilt Instrument (Digit) pilot issuance.

Finextra
HIGHRansomware

Osaka Metropolitan University cancels classes after suspected ransomware attack

Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.

The Record
CRITICALVulnerability

NVD CRITICAL: CVE-2026-106037 — Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in...

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount attacker-described segments.

CVE-2026-106037
NIST NVD
HIGHData Breach

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek .

SecurityWeek
LOWAi

Securing Agent-to-Agent Communication: The Next Identity Frontier

As organizations deploy autonomous AI agents, security teams face a significant shift as non-human non-human entities making decisions, invoking tools, and delegating tasks to other agents without human intervention. Security architectures built around human users, static APIs, and distinct endpoints break down when AI agents dynamically collaborate across an environment. As these interactions bec

Rapid7
MEDIUMVulnerability

Gatehouse Bank backs youth homeless charity via new saver account

Gatehouse Bank has today launched a one-year fixed term Community Saver Account in support of the Bank’s charity partner, Depaul UK, a youth homelessness charity.

Finextra
CRITICALVulnerability

How to secure RMM software: 8 controls MSPs should test

RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery and tenant isolation. [...]

BleepingComputer
MEDIUMPhishing

Nikkei Discloses Two Employee Cloud Account Compromises

Nikkei says two employee cloud accounts were accessed, with one used to send 9,000 phishing emails

Infosecurity Magazine
MEDIUMVulnerability

Getnet simplifies European expansion for merchants

Expanding across Europe just became simpler for merchants. Getnet, Santander's global merchant payments platform, now enables multinational merchants, marketplaces and e-commerce companies to access payment services in over 30 countries across Europe through a single integration.

Finextra
MEDIUMVulnerability

Tribe Payments names Alex Lim head of sales and solutions, Asia-Pacific

Tribe Payments, a global payments fintech specialising in issuer and acquirer processing, has appointed Alex Lim as Head of Sales and Solutions, Asia-Pacific.

Finextra
MEDIUMVulnerability

OMS and Step One Finance extend integration with bespoke loan origination platform

One Mortgage System (OMS) has strengthened its partnership with Step One Finance through the integration of a bespoke loan origination system, further cementing OMS’s growing role in the second charge lending space.

Finextra
MEDIUMMalware

ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware

CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.

The Record
MEDIUMVulnerability

Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities

The IBM subsidiary has also announced its Lightwell Clearinghouse is now available to all customers

Infosecurity Magazine
MEDIUMMalware

FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Revolut eyes Philippines bank licence

Digital bank Revolut is considering the Philippines as the next market in its global expansion plans

Finextra
CRITICALVulnerability

Critical Medical Devices Unable to Support PQC Transition

Forescout found that just 6% of Internet of Medical Things (IoMT) and 16% of medical OT are capable of supporting post quantum cryptography

Infosecurity Magazine
HIGHVulnerability

NVD HIGH: CVE-2026-105918 — A vulnerability has been found in Kusalkasilva Learning-Management-System up to ...

A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious

CVE-2026-105918
NIST NVD
MEDIUMVulnerability

Self-described “cybersecurity engineer” arrested after computer case reopened

Natalie Dreier reports: A Florida man who calls himself a “cybersecurity engineer” on TikTok and Twitch was arrested after police reopened an investigation closed earlier this year. Mark Asea was held in the St. Lucie County Jail in Port St. Lucie, Florida, last week on a count of an offense against computer users, WPEC reported.... Source

DataBreaches.net
LOWVulnerability

Personio acquires spend management platform Circula

German unicorn Personio has purchased fellow German fintech Circula, one of Europe's largest spend management platforms.

Finextra
HIGHRansomware

Japan hands over ‘Qilin’ hacker group member to Germany

JiJi reports: Japanese police have captured a Russian national believed to be a key member of the “Qilin” international hacker group and extradited him to Germany, investigative sources said Tuesday. Qilin is believed to have carried out ransomware attacks against companies worldwide, causing major damage through data encryption. In 2025, the group claimed responsibility online... Source

DataBreaches.net
HIGHData Breach

Denmark Central Person Register (CPR) Breach: Cyberattack Exposes Data of 8.8 Million

Rescana’s new report on a breach affecting the Denmark Central Person Register (CPR) summarizes the situation: On October 5, 2026, Danish authorities publicly disclosed a significant data breach affecting the Central Person Register (CPR), Denmark’s national population database. Attackers exploited a legitimate company account to access the names, addresses, and CPR numbers of approximately

DataBreaches.net
MEDIUMVulnerability

ASOS customers receive ‘hack’ notification threatening leak

Sarah Butler reports: ASOS is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data. The value of Asos’s shares on the London Stock Exchange dived almost 12% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to... Source

DataBreaches.net
MEDIUMVulnerabilityPOC

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in

The Hacker News
LOWMalware

New Linux malware turns vulnerable IoT devices into proxy nodes

A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for NAT (STUN) infrastructure to blend into normal VoIP and WebRTC traffic. Fortinet’s FortiGuard Labs said it has been tracking the malware, dubbed ClingSTUN, across multiple attacks exploiting known vulnerabilities in routers, IoT devices, DV

CSO Online
MEDIUMAi

Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

Citing growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise

ASOS customers have received a seemingly legitimate push notifications claiming the retailer’s IT systems have been breached through a Snowflake breach

Infosecurity Magazine
MEDIUMAi

Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits

The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]

BleepingComputer
MEDIUMVulnerability

Here’s how experts think CISA should tell agencies to protect OT

Government auditors say federal agencies haven’t met mandated security steps for operational technology, which hackers targeted in water sector attacks this summer. The post Here’s how experts think CISA should tell agencies to protect OT appeared first on CyberScoop .

CyberScoop
MEDIUMAi

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,

The Hacker News
MEDIUMAi

DNB to lay off 400 and expand use of AI agents

Norway's biggest bank, DNB, is set to lay off 400 staff in its technology teams while it increases its investment in AI agents.

Finextra
LOWVulnerability

Possible Vulnerability in Apple’s Automatic Reboot

404Media is reporting (alternate link ) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot security feature. This is the feature that automatically puts an iPhone into a more secure state if it hasn’t been used for 72 hours. The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey,

Schneier on Security
CRITICALAi

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP

The Hacker News
MEDIUMVulnerability

Cybersecurity M&A Roundup: 39 Deals Announced in September 2026

Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind. The post Cybersecurity M&A Roundup: 39 Deals Announced in September 2026 appeared first on SecurityWeek .

SecurityWeek
CRITICALData Breach

Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

When Anthropic CEO Dario Amodei urged other leading AI labs to “pace the frontier” last week, his calls for caution were echoed by other prominent voices in tech. Both Sam Altman and Elon Musk agreed with Amodei’s assessment that pausing AI development was essential to prevent the extinction of the human race. Amodei listed several potential disasters that could arise from unchecked AI development

CSO Online
MEDIUMVulnerability

BNP Paribas SS implements Proxymity's Vote Connect

BNP Paribas’ Securities Services business, a leading global custodian with USD 17.5 trillion in assets under custody1, today announces the implementation of Proxymity’s Vote Connect Global solution as part of its general meetings services for global custody clients across EMEA and Asia Pacific, directly connecting issuers, intermediaries and investors through a near real-time, transparent and effi

Finextra
MEDIUMVulnerability

HSBC and Ant International expand treasury management services in Middle East

Ant International today announced an expanded collaboration with HSBC to enhance real-time treasury management services in the Middle East.

Finextra
MEDIUMVulnerability

Waypoint Trading launches market data product

Today marks the launch of Waypoint Wayfinder, a platform for financial institutions to manage the growing volume of notifications from exchanges.

Finextra
MEDIUMSupply Chain

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates 40,000 Downloads appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

Citrix Patches Third Actively Exploited NetScaler Zero Day

Citrix has released another patch for a zero day vulnerability under active exploitation, just a few days after patches were […] The post Citrix Patches Third Actively Exploited NetScaler Zero Day appeared first on The HIPAA Journal .

HIPAA Journal
CRITICALAi

Google’s bug bounty pause highlights growing AI vulnerability triage challenge

AI is accelerating the discovery of software vulnerabilities, but it is also creating a new bottleneck for defenders: deciding which machine-generated findings warrant investigation. Google has decided to temporarily stop accepting certain bug bounty submissions after a surge of largely invalid automated reports highlights a growing challenge for security teams as AI-driven vulnerability discovery

CSO Online
CRITICALMalware

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42 .

Unit 42 (Palo Alto)
MEDIUMSupply Chain

What Are the New Rules for Secure Open Source Consumption?

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/what-are-the-new-rules-for-secure-open-source-consumption" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/Secure%20Open%20Source%20Consumption.png" alt="Image with concentric hexagons at the center containing a lock icon" class="hs-featured-image" style="width:auto !important; max-widt

Sonatype (Maven/npm)
CRITICALZero Day

The AI app builder your team trusts has a root-level backdoor

The fastest-growing category of enterprise software right now is also the least scrutinized from a security standpoint. AI application platforms — tools that let teams build, connect and automate AI-powered workflows without writing much code — are landing in production environments faster than security teams can assess them. They connect to your APIs, your databases, your cloud credentials and yo

CVE-2026-0768CVE-2026-0769
CSO Online
MEDIUMVulnerability

French regulator targets crowdfunding platforms

France's financial watchdog, the Autorit&#233; des March&#233;s Financiers (AMF), has called on crowdfunding platforms to strengthen their practices in order to better protect investors.

Finextra
HIGHData Breach

8.8 Million Impacted by Data Breach at Denmark’s Central Person Register

Hackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens. The post 8.8 Million Impacted by Data Breach at Denmark’s Central Person Register appeared first on SecurityWeek .

SecurityWeek
HIGHVulnerability

More RMM Tools In the Wild, (Tue, Oct 6th)

It seems that a trend started&#x26;#xe2;&#x26;#x80;&#x26;#xa6; I continue my journey discovering more RMM ("Remote Management &#x26; Monitoring") tools abused by threat actors&#x21; A few days ago, I wrote a diary&#x5b;1&#x5d; about ScreenConnect used in the wild. Today, I found another one.&#xd;

SANS ISC
MEDIUMVulnerability

Qupital launches onchain e-commerce lending protocol

Qupital, Asia's leading AI-driven fintech platform specializing in cross-border e-commerce trade finance, today announced the official launch of the world's first AI-driven on-chain e-commerce lending protocol.

Finextra
MEDIUMPhishing

Nikkei discloses breaches of employees’ Microsoft, Google email accounts

Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]

BleepingComputer
MEDIUMVulnerability

FXPro launches &#39;real pro trader&#39; campaign

FxPro, the world's #1 broker, has unveiled its latest global brand campaign, taking a playful swipe at the stereotypes of the trading world.

Finextra
MEDIUMSupply Chain

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are

The Hacker News
MEDIUMVulnerability

Police Urge Passkey Use After Surge in Cybercrime Profits

Report Fraud says cybercrime revenue stemming from account takeover increased 417% annually

Infosecurity Magazine
MEDIUMVulnerability

Rothera goes live on Smartstream&#39;s Air to automate high-volume derivatives reconciliations

Smartstream, the trusted data solutions provider for leading global financial institutions and enterprises, today announced that Rothera, the U.S.-based CFTC-regulated event contract market, has gone live on Smartstream’s Air.

Finextra
LOWAi

What exactly is ISOC? And what does it mean for you?

Gartner recently released a new category of security tools: the Integrated Security Operations Center (ISOC) . This new category acknowledges the need to expand beyond traditional SIEM tools in the creation of a security portfolio, though, as they note in the introductory report, Security Information and Event Management (SIEM) isn’t going anywhere. Gartner’s evolution away from SIEM as an all-enc

CSO Online
MEDIUMAi

Social Engineering Detection Moves Into the Live Conversation

Companies are pouring time and dollars into security awareness training, but little evidence shows it actually works against social engineering. The post Social Engineering Detection Moves Into the Live Conversation appeared first on SecurityWeek .

SecurityWeek
HIGHRansomware

Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds

An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims

Infosecurity Magazine
CRITICALRansomware

AI accelerates n-day attacks, as flaw disclosures and exploits double

Attackers are increasingly weaponizing already-disclosed flaws rather than new zero-days, and AI tools may be accelerating how quickly they do it. According to a report from Google’s Threat Intelligence Group (GTIG), attackers have exploited more vulnerabilities in the wild thus far this year than they did all of last year. With the number of flaws disclosed each month sharply rising, AI tools are

CSO Online
HIGHRansomware

Engineer sentenced for locking over 3,000 devices on employer network

A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-94293 — An unauthenticated remote attacker can modify Asset Administration Shell submode...

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

CVE-2026-94293
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105778 — A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this...

A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-105778
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105701 — The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution i...

The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on t

CVE-2026-105701
NIST NVD
CRITICALVulnerability

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

CVE-2026-21589
The Hacker News
MEDIUMVulnerability

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-75962 — The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs,...

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts

CVE-2026-75962
NIST NVD
MEDIUMVulnerability

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to

The Hacker News
MEDIUMVulnerability

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-105704 — A vulnerability was identified in SourceCodester Drug Recommendation System 1.0....

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.

CVE-2026-105704
NIST NVD
MEDIUMVulnerability

Shares in British clothing company ASOS dive after hackers apparently send push notification

Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.

The Record
HIGHVulnerability

NVD HIGH: CVE-2026-105571 — A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is ...

A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early throu

CVE-2026-105571
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105486 — A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the functio...

A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d9

CVE-2026-105486
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105484 — A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230...

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.

CVE-2026-105484
NIST NVD
CRITICALRansomware

Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes

Dell’s security team has had a busy week. The company has announced a slew of Common Vulnerabilities and Exposures (CVEs) impacting its Dell Container Storage Modules (CSM) and Dell System Update (DSU). Disclosed by Dell in two security notices, these critical vulnerabilities could allow unauthenticated attackers to “completely bypass” authentication controls, gain root access, manipulate storage

CVE-2026-63688CVE-2026-63692
CSO Online
CRITICALZero Day

ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamics

A recent compromise of PeopleSoft by hacking group ShinyHunters is causing new concerns for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved. On Saturday, Reuters reported that a suspected member of ShinyHunters had been arrested by the FBI and has been cooperating

CVE-2026-35273
CSO Online
CRITICALZero Day

Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks

The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal , is causing concern for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved, but there has still been no official word from either the F

CVE-2026-35273
CSO Online
HIGHVulnerability

NVD HIGH: CVE-2026-105471 — A security flaw has been discovered in girishsaraf Online-Appointment-Booking-Sy...

A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks

CVE-2026-105471
NIST NVD
MEDIUMVulnerability

ANZ completes cross-border tokenised deposit payment with Swift ledger

Australia's ANZ has carried out a live corporate treasury transactions using tokenised deposits and Swift’s blockchain ledger.

Finextra
MEDIUMVulnerability

Anchorage Digital expands global services with Standard Chartered

Digital asset custody services provider Anchorage Digital has formed a partnership with Standard Chartered through which it will offer USD accounts and access to Swift wires, including transfers to and from third parties, to eligible non-US institutional clients.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-105470 — A vulnerability was identified in girishsaraf Online-Appointment-Booking-System ...

A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be

CVE-2026-105470
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105469 — A vulnerability was determined in girishsaraf Online-Appointment-Booking-System ...

A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql injection. The attack may be launched remotely. The exploit has been publicly discl

CVE-2026-105469
NIST NVD
CRITICALZero Day

Citrix discloses third actively exploited NetScaler zero-day in less than a week

The vendor was much quicker and consistent in its response to the latest defect, and researchers consider the impact relatively low compared to the previous pair of zero-days. The post Citrix discloses third actively exploited NetScaler zero-day in less than a week appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

CISA to keep cyber pay incentives, but less staff will qualify

Justin Doubleday reports: The Cybersecurity and Infrastructure Security Agency is continuing to offer cyber pay incentives to retain skilled technical staff, but less employees will qualify for the program under revised criteria that ties eligibility to job series and performance ratings. The revised policy has sparked some concern that CISA could lose more staff after... Source

DataBreaches.net
MEDIUMAi

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]

BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-105468 — A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to...

A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. This pro

CVE-2026-105468
NIST NVD
MEDIUMAi

Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

Beyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating with limited resources.

The Record
MEDIUMVulnerability

ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes

The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.

Dark Reading
HIGHVulnerability

NVD HIGH: CVE-2026-77226 — Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability ...

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-c

CVE-2026-77226
NIST NVD
CRITICALVulnerability

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]

CVE-2026-61500
BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-105392 — A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The imp...

A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The proj

CVE-2026-105392
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105387 — A security flaw has been discovered in girishsaraf Online-Appointment-Booking-Sy...

A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may

CVE-2026-105387
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105386 — A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to...

A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling releas

CVE-2026-105386
NIST NVD
MEDIUMVulnerability

Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement

Saif ‌al-Din Khader is cooperating with the FBI, reports said, as the bureau responds to a massive breach that exposed employee data.

The Record
MEDIUMVulnerability

Morgan Stanley sets up digital asset lab

Morgan Stanley has built a digital asset lab where it can test things like stablecoins, tokenisation and decentralised finance applications.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-105385 — A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to...

A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transaction_details.php. Executing a manipulation of the argument transaction_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utiliz

CVE-2026-105385
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101919 — A flaw was found in the HyperShift operator. The operator copies user-provided K...

A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When dow

CVE-2026-101919
NIST NVD
MEDIUMVulnerability

Aapryl forms data relationship with Nasdaq eVestment

Aapryl, an institutional analytics platform for investment manager evaluation, today announced a data relationship with Nasdaq eVestment.

Finextra
MEDIUMVulnerability

Versana digital loan voting platform goes live

Versana today announced the launch of Versana Loan Voting, a new digital technology solution designed to automate and streamline the amendment voting process across the broadly syndicated loan (BSL) and private credit markets.

Finextra
LOWVulnerability

US, Australia warn of latest Citrix vulnerability after NetScaler advisory

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm among cybersecurity experts.

The Record
MEDIUMVulnerability

IQVIA fined $7.8 million for failing to properly anonymize health data

Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]

BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-105383 — A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to...

A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This impacts an unknown function of the file php/controller.php. Such manipulation of the argument transaction_idS leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling relea

CVE-2026-105383
NIST NVD
MEDIUMVulnerability

Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data

Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website.

The Record
HIGHData Breach

WindRose Health Network Discloses Data Breach Affecting 33K Individuals

Data breaches have been announced by WindRose Health Network and Advantage Home Health Care in Indiana, Camden-on-Gauley Medical Center in [&#8230;] The post WindRose Health Network Discloses Data Breach Affecting 33K Individuals appeared first on The HIPAA Journal .

HIPAA Journal
CRITICALVulnerability

Secure Your Mission-Critical Application Estate: Qualys TotalAppSec is Now FedRAMP High Authorized (FedRAMP Certified Class D)

Key Takeaways Qualys TotalAppSec is now FedRAMP High Authorized on the Qualys Government Platform (FedRAMP Certified Class D, package FR2231052341). Federal AI use cases more than doubled in a year (3,611 use cases across 56 agencies), and most AI interactions are delivered through APIs; expanding an estate traditional IP-based inventory was never designed to measure. [&#8230;]

Qualys Blog
LOWVulnerability

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

CVE-2026-96940
The Hacker News
MEDIUMApt

Chinese Hackers Impersonate US Officials for AI Cyber Espionage

An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.

Dark Reading
HIGHRansomware

University of Illinois Chicago affected by ransomware attack on medical school

A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.

The Record
HIGHData Breach

South Korean president orders investigation after spate of bank data breaches

South Korea's president, Lee Jae Myung, has ordered an investigation into a series of data breaches at banks in the country.

Finextra
HIGHData Breach

Denmark population registry data breach affects 8.8 million people

Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]

BleepingComputer
MEDIUMVulnerability

Website Tracking Privacy Risks: Do You Know What Your Websites Are Sharing?

Website tracking privacy risks can remain hidden across a health system’s digital estate until a patient, regulator, or plaintiff discovers [&#8230;] The post Website Tracking Privacy Risks: Do You Know What Your Websites Are Sharing? appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Website Privacy: Your Privacy Policy Makes Promises But Does Your Website Keep Them?

Your privacy policy makes promises but does your website keep them? Privacy and compliance teams may not know every tool that is operating, what information it collects, or where that information is sent. The post Website Privacy: Your Privacy Policy Makes Promises But Does Your Website Keep Them? appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

NatWest Accelerator takes female-founder initiative She Scales nationwide

NatWest Accelerator is expanding its She Scales initiative across the UK after a pilot delivered 68 events and more than 1,800 attendances, with every surveyed participant saying they felt more confident or better equipped to build their business.

Finextra
LOWVulnerability

Bloomberg Electronic Markets brings automation to JGB Market-on-Close functionality

Bloomberg announced the first successful fully automated Japanese Government Bond (JGB) Market-on-Close trade, following the introduction of a new workflow. Aligned to BB3P (Hikene Trading), the Market-on-Close reference rate for JGBs, the automated workflow helps minimize tracking error and provides certainty of execution at a specific close time.

Finextra
CRITICALVulnerability

New Dell System Update flaw lets hackers gain root privileges

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]

BleepingComputer
MEDIUMVulnerability

Nueva EPS, Colombia&#8217;s largest regional healthcare promoting entity has allegedly been hacked

Colombia&#8217;s largest health-promoting entity, Nueva EPS, has allegedly been hacked by an individual demanding $15 million not to leak the data. Colombia&#8217;s healthcare system includes Entidad Promotora de Salud (EPS), regional health-promoting entities responsible for implementing objectives set by the Ministry of Health, developing guidelines and protocols, and overseeing healthcare deliv

DataBreaches.net
MEDIUMVulnerability

Nueva EPS, Colombia&#8217;s largest regional healthcare promoting entity has allegedly been hacked (1)

Colombia&#8217;s largest health-promoting entity, Nueva EPS, has allegedly been hacked by an individual demanding $15 million not to leak the data. Colombia&#8217;s healthcare system includes Entidad Promotora de Salud (EPS), regional health-promoting entities responsible for implementing objectives set by the Ministry of Health, developing guidelines and protocols, and overseeing healthcare deliv

DataBreaches.net
MEDIUMVulnerability

Basware buys payment fraud prevention platform Trustpair

Invoice lifecycle management firm Basware has acquired payment fraud prevention platform Trustpair. Financial terms were not disclosed.

Finextra
MEDIUMMalware

ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes

ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices

Infosecurity Magazine
MEDIUMVulnerability

Trulioo strengthens identity verification for Fiserv clients

Trulioo, a global risk intelligence platform, today announced a collaboration with Fiserv, a leading global provider of payments and financial technology solutions. Trulioo will bring its person and business verification capabilities to Fiserv, helping its clients streamline onboarding and underwriting across global markets.

Finextra
MEDIUMVulnerability

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek .

SecurityWeek
CRITICALAi

South Korea probes bank breaches amid suspected AI-powered attacks

South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]

BleepingComputer
CRITICALRansomware

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others

The Hacker News
MEDIUMVulnerability

Senate Unanimously Passes the Health Care Cybersecurity and Resiliency Act

A bipartisan bill that seeks to improve healthcare cybersecurity and resilience has been unanimously passed by the U.S. Senate. The [&#8230;] The post Senate Unanimously Passes the Health Care Cybersecurity and Resiliency Act appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMMalware

New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic

Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan

Infosecurity Magazine
MEDIUMVulnerability

EBAday 2027 moves to Rome: Early bird registration now open

The annual two-day summit for payments and transaction banking professionals hosted by the Euro Banking Association (EBA) and Finextra, returns for its 22nd edition in Rome, Italy on 15-16 June 2027.

Finextra
MEDIUMApt

Belarusian hacktivists spent two years inside Russian healthcare network, researchers say

Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure.

The Record
CRITICALVulnerability

CISA Sends CIRCIA Final Rule for White House Review

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has penned a final rule under the Cyber Incident Reporting for Critical [&#8230;] The post CISA Sends CIRCIA Final Rule for White House Review appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

tenfold CE: Our free Identity Governance tool just got 2 new features

tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity. [...]

BleepingComputer
MEDIUMVulnerability

Citrix NetScaler Targeted Via New Zero Day

The memory buffer vulnerability can result in denial of service to customers, with CISA warning it poses “significant risks” to the federal government

Infosecurity Magazine
MEDIUMVulnerability

TrueLayer and SumUp partner to simplify account top-ups

TrueLayer, the Pay by Bank network used by more than 30 million people across Europe - today announced that its Pay by Bank technology powers instant account top-ups in the SumUp App, the personal account offering for consumers from global financial technology company SumUp.

Finextra
MEDIUMVulnerability

HSBC expands data partnerships to back Hong Kong SMEs expanding overseas

HSBC today announced it is expanding its network of trade, cargo and corporate data providers through the Hong Kong Monetary Authority’s (HKMA) Commercial Data Interchange (CDI), supporting its ambition to make banking more responsive to Hong Kong small and medium-sized enterprises (SMEs) as they expand across markets.

Finextra
MEDIUMVulnerability

Iress sourcing data integrated into Access FS Elev8 platform

Financial technology company Iress has expanded the distribution of its mortgage and protection sourcing data through a new integration with Elev8, the CRM platform developed by Evolve Tech Solutions for Access FS.

Finextra
MEDIUMMalware

Japanese media group Nikkei discloses cyberattack targeting journalistic sources

The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources.

The Record
MEDIUMMalware

Japanese media group Nikkei discloses intrusions targeting employees and users

The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources.

The Record
MEDIUMVulnerability

Moorwand to issue new multi-currency Tap card

Tap Global Group plc (AIM: TAP, OTCID: TAPIF), the regulated digital finance platform, announces that it has appointed Moorwand Ltd ("Moorwand") as issuer and Bank Identification Number ("BIN") sponsor for a new Tap Mastercard programme.

Finextra
MEDIUMMalware

Alleged dev of Ploutus ATM malware appears in US court after arrest

The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]

BleepingComputer
MEDIUMAi

Need for Speed: AI-Driven Attacks Are Changing Security Strategies

AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.

Dark Reading
MEDIUMMalware

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek .

SecurityWeek
LOWVulnerability

Mynt valued at $7bn for upcoming IPO

Philippines unicorn Mynt could achieve a valuation of more than $7bn following an IPO that is set to be the country's biggest ever listing

Finextra
HIGHRansomware

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

Hackers stole patient information from Clover Health Investments and AngMar Management Services in July. The post 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Hackers Breached Propulsion System of U.S.-Bound Oil Tanker

Seen on Homeland Security Today: FBI and US Coast Guard investigators have found evidence that hackers accessed the propulsion system of an oil supertanker as it was approaching the Texas coast this summer, according to US officials familiar with the matter, an extraordinary breach that highlights the growing physical risks from cyberattacks. The cyberattack resulted... Source

DataBreaches.net
MEDIUMVulnerability

Daiwa Securities says info on 110,000 clients may have been leaked in vendor incident

Takashi Nakamichi and Ryo Horiuchi report that Daiwa Securities, Japan&#8217;s second-largest brokerage and investment banking firm, is responding to a breach at one of its vendors. Daiwa Securities Group said information on as many as 110,000 clients may have been stolen after the servers of an external vendor were hacked. Japan’s second-largest brokerage received a... Source

DataBreaches.net
HIGHRansomware

Ransomware group threatens to leak customer data from top insurance companies in South Africa

Luis Monzon reports: Ransomware-as-a-service group The Gentlemen threatened to leak data belonging to insurance companies LegalWise and Samwumed, with more South African companies likely to follow. The Gentlemen is one of the most active cybercriminal organisations in the world, and accounted for 17% of all ransomware attacks globally in July, according to Check Point Software.... Source

DataBreaches.net
CRITICALZero Day

Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush

Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively exploited zero-days . The new vulnerability, tracked as CVE-2026-88779 , is a memory-overflow issue that can cause a denial-of-service (DoS) condition on affected appliances. Cit

CVE-2026-88779CVE-2026-88772
CSO Online
HIGHData Breach

Data breach at Denmark’s national population register exposes 8.8 million people

Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.

The Record
MEDIUMVulnerability

The Credential Layer Is Expanding Faster Than Security Teams Can See It

Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they

The Hacker News
CRITICALMalware

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report

The Hacker News
LOWVulnerability

SEC publishes new crypto custody rules

The US Securities and Exchange Commission has proposed new rules designed to establish a dedicated legal framework for crypto custody within the wealth management and advisory market

Finextra
MEDIUMVulnerability

Kord launches dedicated sort-code for legal transactions

UK fintech Kord is launching the UK’s first dedicated legal sort code: 04-10-26.

Finextra
MEDIUMVulnerability

Curvestone AI selected for Barclays scaleup scheme

Curvestone AI, the AI compliance platform for regulated financial services, has announced its selection as one of only 25 companies chosen for the Barclays Eagle Labs Scaleup Programme.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-105290 — A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an...

A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The pr

CVE-2026-105290
NIST NVD
MEDIUMVulnerability

Another Historic Cipher Falls to AI

This one is from 1809, written by Napoleon&#8217;s nephew.

Schneier on Security
LOWVulnerability

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI appeared first on SecurityWeek .

CVE-2026-61500
SecurityWeek
MEDIUMVulnerability

APAC consumers show appetite for stablecoin

Almost half of consumers in Asia Pacific would be willing to use stablecoins in the next five years, according to recently published research from Visa

Finextra
MEDIUMVulnerability

Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach. The post Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge

The Hacker News
MEDIUMVulnerability

Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports

Google has paused its Open Source Vulnerability Rewards Program due to a flood of AI submissions

Infosecurity Magazine
MEDIUMAi

OpenAI will show visual ads in ChatGPT while you generate images

OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]

BleepingComputer
MEDIUMVulnerability

CaixaBank establishes new AI and data division

Spanish financial services firm CaixaBank has created its first AI and data division in a move designed to accelerate the bank's digital transformation efforts.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105285 — A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1...

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

CVE-2026-105285
NIST NVD
MEDIUMVulnerability

The US needs a real plan to defend its water systems

Here’s what it would take: stronger defenses for large utilities, hands-on help for smaller systems and federal support to make both happen. The post The US needs a real plan to defend its water systems appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Sky Links Capital appoints managing director

Sky Links Capital Group announced the appointment of Hormoz Faryar as Managing Director. Faryar brings over 25 years of institutional e-FX trading and sales expertise to lead the firm's institutional business development and expansion across global markets.

Finextra
MEDIUMVulnerability

Microsoft: Windows KB5124010 update crashes some games and apps

Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]

BleepingComputer
MEDIUMVulnerability

More UK Schools Are Recovering Faster from Cyber Incidents

Ofqual study finds growing number of UK schools are bouncing back “immediately” from cyber-attacks

Infosecurity Magazine
MEDIUMAi

Constructor launches agentic payment platform

Constructor, the product discovery platform for the agentic era, today announced Agentic Checkout, which integrates Stripe, to enable shoppers to both find and buy products within a single agent conversation and interface.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105284 — A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The imp...

A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-105284
NIST NVD
MEDIUMVulnerability

ELW Consulting launches cloud finance platform

ELW Consulting are proud to announce the launch of Elevations, a cloud-native platform covering the full development finance loan lifecycle, from origination to redemption.

Finextra
MEDIUMVulnerability

Frontline Education Breach Impacts K-12 School District Staff

A breach at school software provider Frontline Education has exposed employee data

Infosecurity Magazine
MEDIUMVulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]

BleepingComputer
LOWVulnerability

Should the CISO role be split in two?

In its roughly 30-year history, the CISO role has been reshaped by waves of new technology and rising cyber threats. In many organizations, CISOs now own risk reporting, information risk management, threat monitoring, cyber risk accountability and governance, and security strategy. And as AI and digital dependence grow, the CISO’s remit is growing beyond security controls. The latest IANS State of

CSO Online
CRITICALVulnerability

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

CVE-2026-61500
The Hacker News
MEDIUMVulnerability

Alleged ShinyHunters Leader Arrested in Jordan

Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post Alleged ShinyHunters Leader Arrested in Jordan appeared first on SecurityWeek .

SecurityWeek
LOWVulnerability

Community finance and open banking technology can support ‘credit invisibles’ – Salad Finance

People with low credit, whether due to a missed payment or a period of financial insecurity, are often disproportionately punished by the financial system by not being given loans, credit cards, and other forms of consumer credit.

Finextra
CRITICALZero Day

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to

CVE-2026-88779
The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-105232 — A flaw has been found in kishor-23 food-waste-management-system 411989e3ecb82895...

A flaw has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file delivery/deliverysignup.php of the component Registration Page. This manipulation of the argument username/email/location causes sql injection. The attack can be initiated remotely. The exploit has

CVE-2026-105232
NIST NVD
CRITICALZero Day

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier appeared first on SecurityWeek .

CVE-2026-88779
SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-105182 — A security flaw has been discovered in SourceCodester Online Reviewer Management...

A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

CVE-2026-105182
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105294 — Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability tha...

Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.

CVE-2026-105294
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105170 — A weakness has been identified in kishor-23 food-waste-management-system 411989e...

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the p

CVE-2026-105170
NIST NVD
MEDIUMApt

TTY Logs and the Data it Captures, (Sun, Oct 4th)

For an experiment, I created a script &#x5b;1&#x5d; that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM &#x5b;2&#x5d; to be correlated with all the data. &#xd;

SANS ISC
HIGHVulnerability

NVD HIGH: CVE-2026-105221 — The gist RubyGem before 6.1.0 contains an improper certificate validation vulner...

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

CVE-2026-105221
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105166 — A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb8...

A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The e

CVE-2026-105166
NIST NVD
CRITICALZero Day

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]

CVE-2026-88779
BleepingComputer
HIGHData Breach

South Korea&#8217;s President Lee Jae Myung orders thorough probe into data breaches at local banks

Lee Hyo-jin reports: President Lee Jae Myung on Sunday ordered a thorough investigation into a string of recent data breaches at financial institutions, as artificial intelligence (AI)-powered cyberattacks increasingly target them. According to Cheong Wa Dae, Lee was briefed on recent data breaches at financial and public institutions and their responses to the incidents. &#8220;The... Source

DataBreaches.net
MEDIUMVulnerability

Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data

The Slate Valley Unified School District in Fair Haven, Vermont, has been responding to a security incident since September 3. On October 2, Kairos threat actors contacted DataBreaches to alert us to the incident and their response to the district&#8217;s claim that they believed student data had not been compromised. They were also angry that... Source

DataBreaches.net
HIGHVulnerability

NVD HIGH: CVE-2026-105216 — go-micro before 6.0.0 contains an improper certificate validation vulnerability ...

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens an

CVE-2026-105216
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105089 — WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability ...

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.

CVE-2026-105089
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105215 — ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in...

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w

CVE-2026-105215
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105212 — ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypas...

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing exist

CVE-2026-105212
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105211 — ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V...

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

CVE-2026-105211
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105210 — ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authenticatio...

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, a

CVE-2026-105210
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105209 — ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorizati...

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and r

CVE-2026-105209
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105208 — ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with...

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens

CVE-2026-105208
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105207 — ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user ...

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account

CVE-2026-105207
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105158 — A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted elem...

A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through a

CVE-2026-105158
NIST NVD
MEDIUMVulnerability

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

The announcement comes after Trump hosted top executives of AI companies at the White House last week. The post Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force appeared first on SecurityWeek .

SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-105149 — A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects...

A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in

CVE-2026-105149
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105148 — A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability ...

A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was c

CVE-2026-105148
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105147 — A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unk...

A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but di

CVE-2026-105147
NIST NVD
MEDIUMVulnerability

Weekly Update 524: Live From Copenhagen

I&apos;m in Denmark! Well, just, I&apos;m now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepijn in the Netherlands and then Saif

Troy Hunt
MEDIUMAi

Anthropic asks Claude users to share voice data for AI model training

Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]

BleepingComputer
MEDIUMVulnerability

User Agent Strings Curiosities, (Sun, Oct 4th)

Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs.&#xd;

SANS ISC
MEDIUMVulnerability

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and

The Hacker News
MEDIUMAi

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a

The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105135 — A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects ...

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure

CVE-2026-105135
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105134 — A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects...

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve

CVE-2026-105134
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105133 — A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the fu...

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate thi

CVE-2026-105133
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-88779 — Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: b...

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

CVE-2026-88779
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105126 — LaraDashboard before 1.4.8 contains an improper privilege management vulnerabili...

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.

CVE-2026-105126
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105123 — W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnera...

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path

CVE-2026-105123
NIST NVD
HIGHVulnerability

CISA KEV: Citrix NetScaler — Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.

CVE-2026-88779Citrix NetScaler
CISA KEV
MEDIUMAi

Google Gemini could soon get full access to your Mac’s files, apps and the web

Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]

BleepingComputer
LOWVulnerability

The Italian Italy&#8217;s Data Protection Authority fines IQVIA €7 million over data protection breach

The following is a machine translation of a press release by Italy&#8217;s privacy guarantor: Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The data of one million patients of 800 family doctors are not anonymous. The Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million. The company, part of a... Source

DataBreaches.net
LOWVulnerability

Italy&#8217;s Data Protection Authority fines IQVIA €7 million over data protection breach

The following is a machine translation of a press release by Italy&#8217;s privacy guarantor: Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The data of one million patients of 800 family doctors are not anonymous. The Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million. The company, part of a... Source

DataBreaches.net
MEDIUMVulnerability

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]

BleepingComputer
LOWData Breach

ShinyHunters hacker &#8220;Rey,&#8221; allegedly involved in FBI data theft, detained in Jordan

Jana Winter, Raphael Satter, and A.J. Vicens report: A key member of the ShinyHunters hacking group, ‌which claims to have stolen data on every FBI employee, was detained this week in Jordan, three people familiar with the matter told Reuters. Two of ​the sources said he was cooperating with the FBI to identify ​his fellow... Source

DataBreaches.net
MEDIUMVulnerability

YARA-X 1.21.0 Release, (Sat, Oct 3rd)

YARA-X&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s 1.21.0 release brings 5 improvements and 4 bugfixes.&#xd;

SANS ISC
MEDIUMApt

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that

The Hacker News
CRITICALRansomware

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the

The Hacker News
MEDIUMVulnerability

Danish university DTU breach exposes data of up to 200,000 people

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]

BleepingComputer
CRITICALVulnerability

DHS readies major cyber contract

Justin Doubleday reports: The Department of Homeland Security is preparing this year to award a major cloud, cybersecurity and network services contract aimed at further centralizing the management of IT services across DHS. In a notice posted to Sam.gov last month, DHS laid out the notional timeline for award of the Network, Cloud and Cybersecurity... Source

DataBreaches.net
HIGHVulnerability

NVD HIGH: CVE-2026-105115 — OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation v...

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadge

CVE-2026-105115
NIST NVD
MEDIUMAi

OpenAI faces California DOJ subpoena amid growing cybersecurity incident notices

IAPP reports: Regulator inquiries into major AI companies&#8217; cybersecurity practices are ramping up. A day after reports surfaced about the likely escalation of a U.S. Federal Trade Commission probe into OpenAI and other developers, California Attorney General Rob Bonta advanced his office&#8217;s ongoing OpenAI investigation. Bonta announced the company was served an investigative subpoena to

DataBreaches.net
MEDIUMVulnerability

Fed employee repeatedly removed sensitive files, watchdog finds

Matt Bracken reports: A Federal Reserve Board staffer mishandled sensitive classified files and triggered hundreds of data loss prevention alerts leading up to their retirement, the agency’s inspector general revealed in a new report. The security issues with the employee were uncovered by the watchdog during its audit of the Fed’s offboarding process, which began... Source

DataBreaches.net
MEDIUMVulnerability

Senate passes bipartisan bill to bolster hospital cybersecurity

Naomi Diaz reports: The Senate passed the bipartisan Health Care Cybersecurity and Resilience Act by unanimous consent. The legislation aims to help healthcare providers strengthen their cybersecurity defenses and protect patient information, according to an Oct. 1 news release from the Senate Committee on Health, Education, Labor and Pensions. Sens. Bill Cassidy, MD, R-La., Maggie... Source

DataBreaches.net
MEDIUMVulnerability

Medical records giant Epic pauses product development to fix security bugs that risk patients’ data

Zack Whittaker reports: Epic, the software technology giant that makes the widely used MyChart software for accessing patients’ medical data, has paused most of its product development as the company works to protect its software and systems from cyberattacks. Judy Faulkner, the founder and chief executive of Epic, told Modern Healthcare last month that the... Source

DataBreaches.net
MEDIUMAi

doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

Fortra Patches Critical Vulnerabilities in BoKS

The bugs could lead to authentication bypass, shell command execution, and memory corruption. The post Fortra Patches Critical Vulnerabilities in BoKS appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of

The Hacker News
HIGHRansomware

N0n ransomware: what you need to know

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.

Graham Cluley
CRITICALVulnerability

NVD CRITICAL: CVE-2026-92084 — The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for W...

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcode

CVE-2026-92084
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-87115 — The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable...

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as

CVE-2026-87115
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104478 — Formwork before 2.3.13 contains a path traversal vulnerability in BackupControll...

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.

CVE-2026-104478
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104433 — Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerabil...

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference serve

CVE-2026-104433
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-82044 — UTMStack before 11.2.16 contains a server-side request forgery vulnerability tha...

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this to force the web-pdf microservice to fetch internal backend endpoints, the OpenS

CVE-2026-82044
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-82042 — UTMStack before 11.2.16 contains an authentication bypass vulnerability that all...

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtai

CVE-2026-82042
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-82041 — UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMInc...

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, res

CVE-2026-82041
NIST NVD
MEDIUMVulnerability

Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I&#8217;m not optimistic. As usual, you can also use this squid post to talk about the security stories in the news that I haven&#8217;t covered. Blog moderation policy.

Schneier on Security
MEDIUMVulnerability

Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus

The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.

The Record
MEDIUMVulnerability

RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail

The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.

Dark Reading
HIGHVulnerability

NVD HIGH: CVE-2026-82039 — UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupS...

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arb

CVE-2026-82039
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104991 — Phproject before 1.8.7 contains a missing object-level authorization vulnerabili...

Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess() authorization routine. Attackers can use a valid API key to read restricted issue contents a

CVE-2026-104991
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104988 — A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plug...

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST use

CVE-2026-104988
NIST NVD
MEDIUMVulnerability

Bipartisan backlash to ALPRs grows as two high-profile bills are introduced

Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.

The Record
CRITICALVulnerability

NVD CRITICAL: CVE-2023-54405 — H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud plat...

H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token pa

CVE-2023-54405
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2014-125130 — CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress t...

CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files

CVE-2014-125130
NIST NVD
HIGHData Breach

Frontline Education breach exposes school district employee data

Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]

BleepingComputer
HIGHRansomware

Warlock ransomware breach SharePoint in water, telecom operator attacks

The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]

BleepingComputer
MEDIUMAi

The legal questions raised by agentic AI hacks

Experts and policymakers want AI companies to face consequences for agentic hacks. There may not be a clear-cut answer under existing laws and regulations. The post The legal questions raised by agentic AI hacks appeared first on CyberScoop .

CyberScoop
CRITICALVulnerability

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw

The Hacker News
MEDIUMApt

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

The Hacker News
CRITICALVulnerability

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an

CVE-2026-63688
The Hacker News
CRITICALZero Day

Kiteworks &amp; Citrix Incidents Show Challenges of Zero-Day Response

One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.

Dark Reading
LOWVulnerability

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

<p><b>Bulletin ID:</b> 2026-120-AWS <br> <b>Scope:</b> AWS <br> <b>Content Type:</b> Important (requires attention) <br> <b>Publication Date:</b> 10/01/2026 08:30 AM PDT</p> <p><b>Description:</b></p> <p>The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVo

CVE-2026-103505
AWS Security Bulletins
MEDIUMVulnerability

SWIFT Banking &amp; Government Middleware Enables RCE

Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.

Dark Reading
CRITICALVulnerability

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]

BleepingComputer
MEDIUMVulnerability

Is Your Organization Ready for 2027's AI Accountability Era?

Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.

Dark Reading
MEDIUMAi

Is It Fair to Blame 'Rogue' AI for Security Failures?

"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.

Dark Reading
MEDIUMVulnerability

US sanctions Tren de Aragua gang members in ATM hacks crackdown

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]

BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-104637 — A weakness has been identified in onetwothreeneth HospitalManagementSystem up to...

A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remo

CVE-2026-104637
NIST NVD
MEDIUMVulnerability

YouTuber raises $15m for Brazil&#39;s &#39;Cash App&#39;

NG.Cash, the "Brazilian Cash App" founded by a former YouTuber, has raised $15 million to back its efforts to bring credit and crypto services to the country's young, unbanked population.

Finextra
MEDIUMVulnerability

Unidentified Flock Cameras in Florida

St. Lucie County in Florida discovered ( alt link ) a dozen Flock cameras whose ownership it can&#8217;t identify, and that the county government had not permitted. I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown. My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case

Schneier on Security
MEDIUMMalware

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

BMO taps Mastercard for embedded commercial virtual card payments

BMO and Mastercard today announced the availability of a new embedded Commercial payments capability that enables eligible Corporate Card clients to initiate and manage BMO Commercial virtual card payments directly within the software platforms they use to run their operations.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-93875 — The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scrip...

The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload

CVE-2026-93875
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-85215 — Improper neutralization of special elements used in an SQL command ('SQL injecti...

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection. This issue affects Paperwork: through 2026-09-09.

CVE-2026-85215
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-19652 — The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation i...

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowe

CVE-2026-19652
NIST NVD
MEDIUMVulnerability

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes

Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks

Infosecurity Magazine
HIGHRansomware

Mississippi mayor says ransomware incident led city to shut down systems

Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.

The Record
CRITICALRansomware

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.

The Record
MEDIUMVulnerability

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]

BleepingComputer
MEDIUMVulnerability

Vulnerability Backlogs Are an Ownership Problem

Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.

Dark Reading
MEDIUMVulnerability

InDebted names Chris McNamara CEO

InDebted, the global AI-native collections infrastructure company, today announced the appointment of Chris McNamara as Chief Executive Officer and Brendan Lee as Chief Financial Officer, both effective 1 October 2026.

Finextra
MEDIUMVulnerability

Coinpayments appoints founder Alex Alexandrov as group CEO

Coinpayments , the global digital assets payments infrastructure provider, has announced the appointment of founder Alex Alexandrov as Group CEO. Alexandrov founded the company in 2013 and has served as Chairman for much of its growth.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-104611 — A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown fu...

A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVE-2026-104611
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-104610 — A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_...

A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-104610
NIST NVD
MEDIUMMalware

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek .

SecurityWeek
CRITICALRansomware

City of Vicksburg, Mississippi, shuts down computers after cyberattack

Joseph Topping reports: The City of Vicksburg, Mississippi, has shut down its computer systems after a ransomware attack, potentially delaying in-person utility payments while emergency response and utility service continue. Mayor Willis Thompson told The Vicksburg Post that the city had disconnected its internet operations. “We had to bring our internet operations down, just for... Source

DataBreaches.net
MEDIUMVulnerability

Malicious Linux Implants Mimic Asian Mail Security Products

A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.

Dark Reading
LOWApt

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT , deployed against Taiwanese appliances. Additionally, we provide source code details of the

Rapid7
MEDIUMVulnerability

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]

BleepingComputer
MEDIUMAi

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-104609 — A weakness has been identified in onetwothreeneth HospitalManagementSystem up to...

A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulation of the argument user_id/patient_id/physician_id/discounts_id/services_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and co

CVE-2026-104609
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104457 — YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filter...

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them in

CVE-2026-104457
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104445 — YesWiki before 4.6.7 contains an authentication bypass vulnerability in the Acti...

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.

CVE-2026-104445
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104437 — Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transpare...

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.

CVE-2026-104437
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104416 — Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability...

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

CVE-2026-104416
NIST NVD
MEDIUMAi

WealthAi launches AI agents to oversee client onboarding and KYC process

WealthAi, the AI operating system OS for wealth managers and advisers, has launched a new suite of AI agents designed to oversee the client onboarding and KYC process end-to-end.

Finextra
LOWVulnerability

Crypto Scammers Hijack Microsoft&#8217;s Official X Account

Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft&#8217;s Official X Account appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is

The Hacker News
MEDIUMVulnerability

In Rare Move, Alleged Iranian State Hacker Extradited to US

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Lloyds survey reveals 71% of UK FIs believe tokenisation will reshape financial services

Lloyds' 10th annual Financial Institutions Sentiment Survey, conducted between April and May 2026, showed that 71% of the 100 senior leaders surveyed across UK banks, insurers, financial sponsors and asset and wealth managers, expect tokenisation to transform how money and assets move through the financial system.

Finextra
MEDIUMAi

How American Political Campaigns Are Using AI—and What They’re Spending on the Tools

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them. Candidates&#8217;, parties&#8217; and committees&#8217; spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet abo

Schneier on Security
MEDIUMVulnerability

Fairchild Medical Center &#038; Boone Health Settle Pixel Lawsuits

Fairchild Medical Center and Boone Health have agreed to settlements to resolve complaints alleging they impermissibly disclosed patient data to [&#8230;] The post Fairchild Medical Center &#038; Boone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal .

HIPAA Journal
CRITICALVulnerability

SequenceHash: multihashing for the rest of us

<p>Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a <a href="https://blog.trailofbits.com/2024/08/21/yolo-is-not-a-valid-hash-construction/#yolomultihash">common stumbling point</a> when cryptographers try to use hashes.</p> <p>As part of our goal to “fix software, not bugs,” Trail of Bits is introducing <a hre

Trail of Bits
CRITICALVulnerability

NVD CRITICAL: CVE-2026-94541 — The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerabl...

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the p

CVE-2026-94541
NIST NVD
HIGHData Breach

Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents

AngMar Management Services, a Mansfield, Texas-based home health and hospice management company, has identified unauthorized access to its information technology [&#8230;] The post Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

BMO and Mastercard enable corporate card clients to manage virtual card payments

BMO and Mastercard today announced the availability of a new embedded Commercial payments capability that enables eligible Corporate Card clients to initiate and manage BMO Commercial virtual card payments directly within the software platforms they use to run their operations. Through this expansion, BMO becomes the first Mastercard issuer in Canada to offer an integrated embedded finance and pay

Finextra
CRITICALRansomware

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek .

SecurityWeek
LOWVulnerability

Microsoft’s X account hacked in crypto pump-and-dump scheme

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]

BleepingComputer
HIGHRansomware

Police Target KillSec Ransomware Group with Arrests and Seizures

Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects

Infosecurity Magazine
CRITICALAi

Rolling the cyber dice with open-source and open-weight AI models

With typical cybersecurity exposure, I can conduct pen testing with deterministic tools. I am able to predict how a piece of software is going to respond. I even stand a decent chance of finding vulnerabilities before they can be exploited against me. What we are dealing with now is a new kind of exposure. For LLMs and AI models, there are invisible risks that are unscannable and virtually undetec

CSO Online
MEDIUMVulnerability

Mosaic Processing asks software platforms to examine payment costs

Mosaic Processing invites software platforms to review how payment acceptance fits into their products, customer relationships and business economics. The invitation includes booking, membership, billing, ERP and practice-management software companies that serve businesses accepting credit and debit cards.

Finextra
MEDIUMAi

AI Agents Aimed SQL Injection at US and Canadian Government Sites

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek .

SecurityWeek
CRITICALZero Day

EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage

Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational capacities of technology vendors whose wares compete in those markets. The EU CRA introduces mandatory reporting within 24 hours for any actively exploited vulnerabilities or severe incidents affecting produc

CSO Online
CRITICALZero Day

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure

The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days

Infosecurity Magazine
CRITICALVulnerability

NVD CRITICAL: CVE-2026-97637 — The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass vi...

The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()

CVE-2026-97637
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-95670 — The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Sc...

The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only

CVE-2026-95670
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-93756 — The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin fo...

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that wil

CVE-2026-93756
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102772 — The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...

The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an inject

CVE-2026-102772
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100107 — The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Sit...

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-100107
NIST NVD
CRITICALZero Day

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek .

CVE-2026-104286
SecurityWeek
MEDIUMMalware

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-102565 — The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site S...

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful

CVE-2026-102565
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-92174 — The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File I...

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to by

CVE-2026-92174
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-90438 — The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPr...

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u

CVE-2026-90438
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-15897 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Bec

CVE-2026-15897
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-15896 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no au

CVE-2026-15896
NIST NVD
CRITICALZero Day

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper

CVE-2026-104286
The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2026-19660 — The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass ...

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled

CVE-2026-19660
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-10026 — The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all ver...

The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server.

CVE-2026-10026
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-14378 — The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leadi...

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by

CVE-2026-14378
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104120 — A security vulnerability has been detected in modelcontextprotocol mcp-server-fe...

A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be us

CVE-2026-104120
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-86345 — A flaw was found in 389-ds-base. The server does not discard plaintext bytes alr...

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a cl

CVE-2026-86345
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103765 — Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in...

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server

CVE-2026-103765
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103764 — Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference...

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory

CVE-2026-103764
NIST NVD
MEDIUMVulnerability

Monarch acquires HMBradley

Personal finance platform Monarch has acquired MBI, the digital banking fintech formerly known as HMBradley.

Finextra
MEDIUMAi

Barclays ramps up use of Anthropic&#39;s Claude

Barclays is extending its use of Anthropic's Claude in an effort to accelerate software development, modernise its legacy systems and boost operational efficiency.

Finextra
MEDIUMAi

Australia&#39;s WeMoney launches AI and open banking-powered lending assessment service

Australia's WeMoney has launched an AI-powered lending assessment service built on the country's Consumer Data Right.

Finextra
HIGHVulnerability

CISA KEV: Zammad GmbH Zammad — Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

CVE-2026-102490Zammad GmbH Zammad
CISA KEV
HIGHVulnerability

CISA KEV: Zammad GmbH Zammad — Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

CVE-2026-102489Zammad GmbH Zammad
CISA KEV
HIGHVulnerability

NVD HIGH: CVE-2026-103761 — Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulne...

Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.

CVE-2026-103761
NIST NVD
CRITICALZero Day

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]

CVE-2026-104286
BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-104051 — PictShare before 3.7.1 contains an information disclosure vulnerability that all...

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API

CVE-2026-104051
NIST NVD
HIGHRansomware

Alleged KillSec Ransomware Mastermind a 16-Year-Old

Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.

Dark Reading
MEDIUMAi

Autonomous AI agents tried to hack US, Canadian government websites

Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]

BleepingComputer
MEDIUMVulnerability

Iranian accused of hacking American universities extradited from Montenegro

An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro.

The Record
MEDIUMVulnerability

New York and Wyoming regulators ink virtual currency MoU

The New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow and the Wyoming Division of Banking Commissioner Jeremiah Bishop today announced a memorandum of understanding (MOU) to facilitate coordinated oversight of entities engaged in virtual currency and digital asset activities in New York and Wyoming.

Finextra
MEDIUMVulnerability

Walapay raises $4.6m

Walapay, global payments infrastructure for account issuance, collections, FX, and payouts, today announced a $4.6 million seed round led by Generative Ventures, with participation from Commerce Ventures, Polygon, Verda Ventures, NGC Ventures, FGV Capital, AAF, Jsquare, Knollwood, Big Brain Holdings and others.

Finextra
HIGHRansomware

Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members

The teenager-run cybercrime group victimized roughly 500 organizations in less than two years. The post Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members appeared first on CyberScoop .

CyberScoop
LOWMalware

Microsoft says threat actors are ahead in the early AI race

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]

BleepingComputer
HIGHRansomware

Teenagers suspected of leading KillSec ransom group arrested during international operation

DataBreaches has reported on a group known as KillSec for almost two years. This time, we get to report on their arrest. The European Union Agency for Criminal Justice Cooperation issued this press release today: An international group of authorities from nine countries, coordinated by Eurojust and Europol, has successfully shut down a ransomware group... Source

DataBreaches.net
MEDIUMAi

OpenAI software attempted to secretly scrape data from dozens of prominent websites

The findings, released Thursday by Asymmetric Security, are just the latest example of rogue behavior spurred by OpenAI’s software.

The Record
CRITICALAi

National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations

Sean Cairncross talked about regulations, China, pilot projects and more Thursday. The post National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations appeared first on CyberScoop .

CyberScoop
HIGHVulnerability

NVD HIGH: CVE-2026-15911 — Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a re...

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

CVE-2026-15911
NIST NVD
MEDIUMVulnerability

Sibos 2026: What does a successful ESG strategy look like?

How can global financial institutions maintain a coherent sustainability strategy with constantly shifting expectations? This was discussed at Sibos Miami 2026 by a panel of experts.

Finextra
MEDIUMVulnerability

BMO joins Project Agor&#225;

BMO today announced its participation in Project Agor&#225;, the global public-private collaboration convened by the Bank for International Settlements (BIS) and the Institute of International Finance (IIF) to explore how tokenization and programmability could enhance wholesale cross-border payments.

Finextra
MEDIUMAi

Bloomberg closes Canoe Intelligence acquisition

Bloomberg today announced the completion of its acquisition of Canoe Intelligence (“Canoe”), a leading AI-powered data management and intelligence platform for automating private markets data collection and delivery.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2023-54404 — Zod schema-validation library through 4.6.5 contains an uncontrolled resource co...

Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early te

CVE-2023-54404
NIST NVD
MEDIUMMalware

Researchers find Chinese hacking campaigns targeting AI firms, Asian governments

Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.

The Record
MEDIUMVulnerability

Give yourself room to be human

In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.

Cisco Talos
MEDIUMVulnerability

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right. The post Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Sibos 2026: Don&#39;t just think tech, think talent to achieve broad AI literacy

It’s not just the tech banks need to think about. The talent that is needed to make most organisational AI aspirations a reality is a huge part of the successful AI adoption — per an expert panel at the 2026 Sibos conference in Miami.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-96659 — A flaw was found in Foreman. This vulnerability allows an authenticated user wit...

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw

CVE-2026-96659
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-96658 — A flaw was found in Foreman. An authenticated attacker with low-level permission...

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

CVE-2026-96658
NIST NVD
MEDIUMVulnerability

Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains appeared first on SecurityWeek .

SecurityWeek
HIGHRansomware

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected

The Hacker News
CRITICALZero Day

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can

The Hacker News
MEDIUMData Breach

‘A treasure trove of information:’ Cybersecurity specialist says sensitive McMinnville records exposed online

KOIN in Oregon reports: Three clicks. That&#8217;s all Chuck Dornon said it took to reach private McMinnville records that should never have been public on the dark web. &#8220;Anything and everything that the city&#8217;s done is out there,&#8221; Dornon said. &#8220;This is probably the easiest form of information I&#8217;ve come across in a breach.&#8221; The... Source

DataBreaches.net
MEDIUMVulnerability

OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued guidance for state Medicaid [&#8230;] The post OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions appeared first on The HIPAA Journal .

HIPAA Journal
HIGHRansomware

Police disrupt KillSec ransomware, arrest suspected teenage leader

European police said raids against the KillSec ransomware-as-a-service operation included the arrest of a high-profile teen suspect.

The Record
MEDIUMVulnerability

Nubank rejects Monzo takeover talk

Brazilian digital banking giant Nubank has denied that it is pursuing a $10 billion takeover of Britain's Monzo.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2024-58388 — Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthentica...

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, inclu

CVE-2024-58388
NIST NVD
MEDIUMVulnerability

Stripe to buy embedded finance platform Parafin

Stripe has agreed to buy embedded financial products platform Parafin. Financial terms of the deal were not disclosed.

Finextra
MEDIUMVulnerability

Payments Canada welcomes six new members

Payments Canada announced today the approval of six new members: Bounce Finance Inc. (“Bounce Pay”), Everlink Payment Services ULC (“FIS Everlink”), Nium Canada Corporation (“Nium”), Pesapeer Incorporated (“Pesa”), Remitly Canada, Inc. (“Remitly”) and Vancouver City Savings Credit Union (“Vancity”).

Finextra
MEDIUMMalware

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

The Hacker News
MEDIUMVulnerability

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

European payments groups join forces to take on US giants

Some of Europe's biggest payments groups - Bancomat, Bizum, Wero, Sibs-MB WAY and Vipps MobilePay - have banded together to create a cross-continent network that can take on Visa and Mastercard.

Finextra
HIGHRansomware

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]

BleepingComputer
MEDIUMAi

Sardine launches AI research lab

Sardine, the leading agentic risk platform for fighting fraud and financial crime, today launched Sardine AI Labs, an applied research group advancing frontier intelligence to fight financial crime.

Finextra
MEDIUMVulnerability

Fiserv digital platform goes live with FI clients

Fiserv, Inc. (NASDAQ: FISV), a leading global provider of payments and financial services technology, today announced that its digital asset platform is live with financial institution clients, marking a significant milestone in the commercialization of stablecoin-enabled banking and payments.

Finextra
HIGHRansomware

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek .

SecurityWeek
CRITICALZero Day

Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation

Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges

Infosecurity Magazine
MEDIUMApt

AI policy circles targeted in China-linked phishing operation

Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and legal-sector experts. The post AI policy circles targeted in China-linked phishing operation appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

The Day-One Hole in Zero Trust Architecture

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]

BleepingComputer
MEDIUMVulnerability

China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders

TA419 posed as AI policymakers and economists to phish US AI policy experts' Microsoft 365 accounts

Infosecurity Magazine
MEDIUMVulnerability

Kiteworks patches max severity code injection vulnerability

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...]

BleepingComputer
MEDIUMVulnerability

Iplicit opens Newcastle office

Iplicit, the leading finance system for the UK and Ireland mid-market, has announced today the opening of a new office in Newcastle, a strategic move to strengthen its advantage over incumbent legacy vendors.

Finextra
LOWVulnerability

Tokenovate appoints William L’Heveder chief revenue officer

Tokenovate, the UK financial technology company providing post-trade workflows-as-a-service and programmable settlement solutions, has appointed William L’Heveder as Chief Revenue Officer.

Finextra
CRITICALAi

Google makes Gemini 4 AI model available to a trusted few

Google has unveiled a new frontier AI model after months of delay. Gemini 4 Argon is designed to handle complex, long-horizon workloads spanning software engineering, enterprise knowledge work such as legal and financial analysis, and cybersecurity. But only a few organizations can get their hands on it for now. Argon is “rolling out to a set of trusted cyber defenders through our Fairwind Program

CSO Online
HIGHData Breach

Data Breaches Announced by Saber Healthcare &#038; Buchalter

Data breaches have been announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm that provides services to [&#8230;] The post Data Breaches Announced by Saber Healthcare &#038; Buchalter appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Iliad Solutions adds Micah Kerr to US team

Iliad Solutions, a leading provider of payment testing and certification technology, has appointed Micah Kerr as Lead Technical Sales Consultant as it continues to expand its presence in the US. Micah joins from Capital One's Discover Global Payment Network.

Finextra
MEDIUMVulnerability

Marex expands digital assets offering with rolling spot crypto

Marex (NASDAQ:MRX), announced the launch of an OTC rolling spot crypto product for institutional clients, marking the latest step in the firm’s continued expansion of its digital assets offering.

Finextra
CRITICALZero Day

Cisco SD-WAN Manager hit by zero-day admin access attack

Cisco’s SD-WAN management software has been letting some attackers walk through an authentication check without having to prove who they are. The company says it has now fixed the flaw that was allowing it. The affected platform, Cisco Catalyst SD-WAN Manager , is used to configure and operate software-defined network deployments. Cisco said in an advisory that improper handling of URI encoding in

CVE-2026-76504
CSO Online
MEDIUMVulnerability

CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer

CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor

Infosecurity Magazine
MEDIUMVulnerability

StraitsX to bring first SGD-denominated stablecoin to Monad

StraitsX today announced plans to bring XSGD and XUSD to the Monad network in early 2027. XSGD is planned to become the first SGD-denominated stablecoin natively issued on Monad, expanding the currencies available to developers, businesses and institutions across the network.

Finextra
MEDIUMVulnerability

Jordan FinTech Academy and Mena Fintech Association sign MoU

Reflecting Jordan’s growing role in the regional fintech ecosystem, the Jordan FinTech Academy (Jordan FTA) at the Institute of Banking Studies (IBS) and the MENA Fintech Association (MFTA) have signed a Memorandum of Understanding (MoU) to establish a framework for cooperation, knowledge exchange, professional development, and stronger connections between fintech professionals and institutions in

Finextra
MEDIUMVulnerability

Gresham ships application to simplify complex reconciliation with AI

Gresham, a global leader in enterprise data automation for the financial services industry, today announces the availability of Control Studio, a new AI-enabled, self-service application for its Control reconciliation product.

Finextra
MEDIUMVulnerability

AI Has Changed Attack Speed, Not Security Fundamentals

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. The post AI Has Changed Attack Speed, Not Security Fundamentals appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Revolut expands loyalty programme with hotel transfers

Revolut, the global financial platform with over 80 million customers worldwide, has today expanded its RevPoints loyalty programme, bringing hotel transfers in-app.

Finextra
HIGHRansomware

Warlock Ransomware Hits Large Spanish, Portuguese Orgs

A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.

Dark Reading
LOWAi

How AI Is Changing the Roles Required in the Security Operations Center

As AI takes on more of the enrichment, correlation, and initial assessment inside the SOC, roles, skills, and KPIs still require deliberate redesign. Security leaders need to decide where automation is dependable, where human judgment should remain decisive, and how teams should be measured when alert handling is no longer the center of the operating model The Gartner® report, The Roles Required f

Rapid7
HIGHVulnerability

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure appeared first on SecurityWeek .

CVE-2026-73570
SecurityWeek
HIGHData Breach

Cyberattack on major Polish invoicing platform exposes customer data

One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners.

The Record
HIGHVulnerability

NVD HIGH: CVE-2026-103678 — A flaw was found in tnef. An attacker can exploit this vulnerability by providin...

A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Serv

CVE-2026-103678
NIST NVD
CRITICALVulnerability

Monta monta.app

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.</strong></p> <p>The

CVE-2026-95102CVE-2026-97363
CISA Advisories
CRITICALVulnerability

Meari IoT Cloud Platform OpenAPI Service

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data w

CVE-2026-101104CVE-2026-96613
CISA Advisories
MEDIUMVulnerability

Sibos 2026: Thoughts from experts at Commerzbank, SMBC, and The Clearing House

At Sibos Miami 2026, Finextra spoke to banking leaders across the industry on what the greatest challenges and opportunities in the global cross-border payments landscape.

Finextra
CRITICALRansomware

Armatura LLC Armatura One

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-contr

CVE-2023-46604CVE-2026-94591
CISA Advisories
CRITICALApt

Johnson Controls EasyIO Neo Series EC and CW Controllers

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.</strong></p> <p>The following versions of Johnson Controls

CVE-2026-64892
CISA Advisories
CRITICALPhishing

ABB Protection and Control IED Manager PCM600

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files.</strong></p> <p>The following versions of ABB Protection and Control IED Manager PCM600 are affected:</p> <ul> <li>Pro

CVE-2026-15952CVE-2026-15953
CISA Advisories
CRITICALZero Day

Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.

Datawater reports: Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed. CISA’s deadline is today. Patching alone will not tell you whether you were already breached. Threat level: Critical What: Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, both CVSS 9.5. Status: Explo

CVE-2026-88771CVE-2026-88772
DataBreaches.net
MEDIUMSupply Chain

How Financial Services Companies Can Modernize Their Software Supply Chain

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date

The Hacker News
MEDIUMAi

Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation

The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation appeared first on SecurityWeek .

SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-103283 — Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability tha...

Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.

CVE-2026-103283
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103271 — Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that...

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.

CVE-2026-103271
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103266 — Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, w...

Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the injected content may be rendered, resulting in HTML injection or cross-site scri

CVE-2026-103266
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103264 — Fleet versions before 4.87.0 contain an authentication bypass vulnerability in t...

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migr

CVE-2026-103264
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103262 — Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerabi...

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.

CVE-2026-103262
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103255 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security

CVE-2026-103255
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103250 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that fails to validate the sessionId parameter. Unauthenticated attackers can supply MongoDB query operators in the sessionId field to access conversation histories from other users and perform unauthorized write and delete operations.

CVE-2026-103250
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103248 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.

CVE-2026-103248
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103246 — n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ...

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and exfiltrate plaintext secrets to attacker-controlled hosts without ownership verification.

CVE-2026-103246
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103244 — ground-station versions before 0.8.0 contain an authentication bypass vulnerabil...

ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.

CVE-2026-103244
NIST NVD
MEDIUMVulnerability

Microsoft enables Windows settings backup by default for orgs

Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. [...]

BleepingComputer
MEDIUMVulnerability

Connected Cars Are a Surveillance Platform

Researchers at Northeastern University, in collaboration with Consumer Reports , evaluated how much modern cars spy in their drivers: To determine this, CR dug through thousands of pages of automakers’ privacy policies and asked questions of 15 different automakers­BMW, Ford, General Motors, Honda, Hyundai, Kia, Mazda, Mercedes-Benz, Mitsubishi, Nissan, Stellantis, Subaru, Tesla, Toyota, and Volks

Schneier on Security
MEDIUMVulnerability

FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

The FBI has a very simple message for the ShinyHunters gang: give yourselves up. On Tuesday, FBI cyber division assistant director Brett Leatherman released a video, thanking the Dutch police for arresting a 24-year-old man they believe to be a member of the group, and and who is separately suspected of attempting to arrange two murders. Read more in my article on the Hot for Security blog.

Graham Cluley
MEDIUMMalware

ShinyHunters suspect arrested, and is now investigated over alleged murder plots

An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and - in a sinister twist - the 24-year-old suspect is also being investigated for attempting to arrange two murders. Read more in my article on the Hot for Security blog.

Graham Cluley
MEDIUMMalware

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek .

SecurityWeek
CRITICALZero Day

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any

The Hacker News
CRITICALVulnerability

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

CVE-2026-76504
The Hacker News
HIGHData Breach

CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit

CPAP Medical Supplies and Services, a Jacksonville, Florida-based provider of durable medical equipment for treating sleep apnea, has agreed to [&#8230;] The post CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit appeared first on The HIPAA Journal .

HIPAA Journal
LOWVulnerability

The Fine Art of Frustrating the Adversary

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.

Cisco Talos
MEDIUMVulnerability

Agents Pick Dependencies, DoWI 8430.01 Holds You Accountable

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/your-agents-are-choosing-dependencies.-dowi-8430.01-says-you-own-the-result" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/Fed%20-%20Policy.png" alt="Image with hexagon shape at center containing a checkbox icon. The hexagon is surrounded by checkmarks throughout the image" class="hs-

Sonatype (Maven/npm)
MEDIUMVulnerability

Hackers stole Pentagon personnel records of over 3 million people

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. [...]

BleepingComputer
MEDIUMData Breach

500,000 Active Credentials Left Exposed on GitHub

Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default. The post 500,000 Active Credentials Left Exposed on GitHub appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

AI Threats Top Cybersecurity Preparedness Gap, PwC Finds

PwC finds global security leaders are most concerned about attacks on AI systems

Infosecurity Magazine
HIGHVulnerability

NVD HIGH: CVE-2026-96813 — The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugi...

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute

CVE-2026-96813
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-95687 — The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to...

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrato

CVE-2026-95687
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-15983 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `s

CVE-2026-15983
NIST NVD
LOWAi

Why AI agents are like the dog that pushed kids into the Seine

There is an interesting story about a French dog on the banks of the Seine river that helps us understand misbehaving AI agents. The dog is trained to save children from drowning. He succeeds and is rewarded, becoming an overnight sensation. He saves another child a week later. Not long after, someone witnesses the dog actually push a child into the river, jumping in to “save” him. The dog did not

CSO Online
CRITICALZero Day

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges. The post Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability appeared first on SecurityWeek .

SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-93882 — The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin ...

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and per

CVE-2026-93882
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-75957 — The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for Wor...

The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `check

CVE-2026-75957
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-19807 — The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerabl...

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the ca

CVE-2026-19807
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-15989 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role ag

CVE-2026-15989
NIST NVD
CRITICALAi

Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders

The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide. The post Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders appeared first on SecurityWeek .

SecurityWeek
LOWAi

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,

The Hacker News
MEDIUMApt

MI5 Warns Over 100 Academics Helped China's Espionage Plans

MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute

Infosecurity Magazine
MEDIUMVulnerability

Metamask discloses security incident affecting its infrastructure

On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41753 — The object name of a dynamically created BACnet File Object is interpreted as a ...

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

CVE-2025-41753
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-85679 — The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...

The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because r

CVE-2026-85679
NIST NVD
MEDIUMVulnerabilityPOC

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working

CVE-2026-86950
The Hacker News
MEDIUMMalware

ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...&#xd;

SANS ISC
CRITICALZero Day

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker

The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2026-92966 — The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordP...

The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbit

CVE-2026-92966
NIST NVD
HIGHVulnerability

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets." MetaMask

The Hacker News
CRITICALVulnerability

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-92245 — The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive...

The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom form field data — stored in appointment records, as well as per-appointment publ

CVE-2026-92245
NIST NVD
MEDIUMVulnerability

Why AI Coding Agents Keep Writing Broken Access Control

AI coding agents can produce authorization logic that compiles and passes review while exposing one tenant’s data to another. Learn why broken access control is difficult to detect and how to prevent it.

Snyk
MEDIUMVulnerability

Capitolis agrees $200m eSecLending acquisition

Capital markets technology provider Capitolis has added securities lending capabilities to its platform through a $200 million all-cash deal to buy eSecLending.

Finextra
MEDIUMVulnerability

Citi launches multi-market instant payments on Swift scheme

Citi has gone live with multiple markets on the Swift payments scheme, enabling bank clients to access multiple cross-border instant payment markets through a single account structure.

Finextra
MEDIUMVulnerability

Zilch eyes 2027 London IPO

Zilch is in talks with banks as it prepares to go public, with the UK-based buy now, pay later provider reportedly leaning towards a London listing.

Finextra
MEDIUMVulnerability

Apple Pay arrives in India

Apple Pay is finally launching in India, entering a huge but competitive market via a partnership with Axis Bank.

Finextra
MEDIUMVulnerability

Sibos 2026: How can capital be mobilised into climate impact investments?

In this Sibos Miami 2026 panel, experts discussed the need for funding in sustainable action and how financial institutions can invest in infrastructure and communities at risk.

Finextra
HIGHVulnerability

CISA KEV: Fortinet FortiMail — Fortinet FortiMail Path Traversal Vulnerability

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

CVE-2026-104286Fortinet FortiMail
CISA KEV
MEDIUMAi

FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers

An FTC spokesperson confirmed the investigation but declined further comment. The post FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers appeared first on SecurityWeek .

SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-103591 — DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file ...

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.

CVE-2026-103591
NIST NVD
MEDIUMMalware

US sanctions 10 over ATM malware scheme tied to Tren de Aragua

Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.

The Record
MEDIUMVulnerability

CVE-2026-86950: The Great Glyph Grift

[object Object]

CVE-2026-86950
r/cybersecurity
MEDIUMAi

OpenAI reveals ‘novel’ encryption bypass used in distillation attack

The company said individuals associated with Chinese company MoonshotAI were behind parts of the attack, but did not offer hard evidence for the claim. The post OpenAI reveals ‘novel’ encryption bypass used in distillation attack appeared first on CyberScoop .

CyberScoop
MEDIUMAi

Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.

Dark Reading
HIGHVulnerability

NVD HIGH: CVE-2026-103000 — pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a craf...

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version

CVE-2026-103000
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102999 — pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a craf...

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.

CVE-2026-102999
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102998 — pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a craf...

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.

CVE-2026-102998
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102997 — pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a craf...

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue af

CVE-2026-102997
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102996 — pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a craf...

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixe

CVE-2026-102996
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102995 — pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a craf...

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption

CVE-2026-102995
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2023-54403 — Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability...

Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files cont

CVE-2023-54403
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2023-54402 — iDocView contains a server-side request forgery vulnerability in its /doc/upload...

iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application con

CVE-2023-54402
NIST NVD
MEDIUMVulnerability

Trump, Tech Giants Strike Voluntary AI Safety Accord

The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.

Dark Reading
MEDIUMMalware

Russian state hackers use new RedFlick technique to push malware

The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]

BleepingComputer
MEDIUMVulnerability

Automakers routinely share personally identifiable connected-car data with third parties, report says

A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.

The Record
HIGHVulnerability

NVD HIGH: CVE-2026-102994 — pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a craf...

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace, resulting in long runtimes and application unavailability. This issue is fixed in versi

CVE-2026-102994
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102993 — pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a craf...

pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.

CVE-2026-102993
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101885 — ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path tr...

ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.

CVE-2026-101885
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101884 — OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variabl...

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.

CVE-2026-101884
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101880 — OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulner...

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving

CVE-2026-101880
NIST NVD
CRITICALZero Day

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) appeared first on Unit 42 .

CVE-2026-88771CVE-2026-88772
Unit 42 (Palo Alto)
CRITICALZero Day

DIVD says Zammad zero-days enabled AI-driven network breach

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]

BleepingComputer
MEDIUMVulnerability

After reports on suicide deaths, Pentagon puts Cyber Command on notice

An August 31 memo obtained by Recorded Future News shows that the Pentagon's assistant secretary for cyber policy made specific demands of U.S. Cyber Command leadership after reports of a cluster of suicide deaths.

The Record
MEDIUMVulnerability

Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.

The Record
MEDIUMVulnerability

UK competition watchdog raises concerns over Brink&#39;s-NCR Atleos deal

The UK's competition watchdog says it will undertake an in-depth investigation into cash management giant Brink's' planned $6.6 billion deal to buy ATM operator NCR Atleos - unless the parties take action to address concerns.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103475 — yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP a...

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.

CVE-2026-103475
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103474 — yii2-starter-kit through 4.2.0 fails to validate file types in the backend stora...

yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.

CVE-2026-103474
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103473 — Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnera...

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.

CVE-2026-103473
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103472 — restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up ...

restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.

CVE-2026-103472
NIST NVD
MEDIUMVulnerability

Over 543,000 valid credentials exposed in public GitHub repositories

More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]

BleepingComputer
HIGHData Breach

Radford experiencing outage after potential data incident

WFXR in Virginia reports: The City of Radford announced tonight (9/29) the city is currently dealing with an internet outage due to a potential data breach. City leadership says it reached out to cybersecurity professionals and legal counsel upon becoming aware of the incident. Both state and federal law enforcement have also been notified, and... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102490 — All versions of Zammad including the latest alpha enable the local zammad user t...

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

CVE-2026-102490
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102489 — Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha...

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

CVE-2026-102489
NIST NVD
MEDIUMVulnerability

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol

CVE-2026-73570
The Hacker News
HIGHData Breach

H1 2026 Healthcare Data Breach Report

There has been a 5.9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026, [&#8230;] The post H1 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMPhishing

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-103231 — A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up...

A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The proj

CVE-2026-103231
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103229 — A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7...

A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be u

CVE-2026-103229
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102427 — Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaS...

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that woul

CVE-2026-102427
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100277 — In JetBrains YouTrack before 2026.2.19197 account takeover was possible by repla...

In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature

CVE-2026-100277
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100276 — In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow ac...

In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action

CVE-2026-100276
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100273 — In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts de...

In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution

CVE-2026-100273
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100262 — In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users wi...

In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates

CVE-2026-100262
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100255 — In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account...

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

CVE-2026-100255
NIST NVD
MEDIUMVulnerability

Sibos 2026: The quantum tipping point

What does the quantum threat mean for financial services?

Finextra
CRITICALVulnerability

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]

BleepingComputer
CRITICALVulnerability

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. CVE-2026-76504 carries a

CVE-2026-76504
The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18782 — Improper neutralization of special elements used in an SQL command ('SQL injecti...

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.

CVE-2026-18782
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103395 — LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC se...

LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.

CVE-2026-103395
NIST NVD
MEDIUMVulnerability

One Inc launches XpressOne to accelerate insurance claims

One Inc, the leading digital payments network for the insurance industry, already connects more than 1.3 million vendors and providers with over 320 carriers.

Finextra
MEDIUMVulnerability

Lumin Digital appoints Mike Valentine to board of directors

Lumin Digital, the Compounding Growth Platform for banks and credit unions, today announced the appointment of Mike Valentine, outgoing chief executive officer of BCU, to its board of directors, effective October 1, 2026.

Finextra
CRITICALVulnerability

Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for

CVE-2026-76504CVE-2026-20127
Rapid7
MEDIUMApt

Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.

Dark Reading
MEDIUMAi

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared

The Hacker News
CRITICALZero Day

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]

CVE-2026-76504
BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-82307 — Improper neutralization of special elements used in an SQL command ('SQL injecti...

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.

CVE-2026-82307
NIST NVD
CRITICALRansomware

Higher education is under siege, and fragmented security is making it harder to respond

Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow. In Q2 2025, universities faced an average of 4,388 cy

Rapid7
MEDIUMVulnerability

Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post Google: AI Is Changing the Pace and Profile of Vulnerability Discovery appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]

BleepingComputer
MEDIUMVulnerability

AI-Found Vulnerabilities More Likely to Enable RCE, Google Says

AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise

Infosecurity Magazine
MEDIUMMalware

Mobile malware warning from Ukrainian researchers includes iPhone exploit kit

'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.

The Record
LOWSupply Chain

Unsloth’s model picker had a code-execution problem

True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines. Pillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the model repository. This could potentially allow attackers to use a speci

CSO Online
MEDIUMVulnerability

Microsoft to block Entra ID script injection attacks starting October

Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-76504 — A vulnerability in the API session-based authentication management of Cisco Cata...

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a spe

CVE-2026-76504
NIST NVD
CRITICALVulnerability

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Trading Technologies acquires Trafix

Trading Technologies International, Inc. (TT), a global capital markets technology provider, today announced it has acquired TRAFiX LLC (TRAFiX), a leading provider of equities and equity options order and execution management systems (OEMS) and FIX connectivity solutions.

Finextra
MEDIUMVulnerability

Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord

Trump and six AI firms sign a voluntary accord on internal controls, audits and board oversight

Infosecurity Magazine
CRITICALZero Day

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek .

CVE-2026-88771CVE-2026-88772
SecurityWeek
MEDIUMVulnerability

TeamViewer urges users to patch severe flaws “as soon as possible”

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]

BleepingComputer
LOWVulnerability

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post Chrome, Firefox Updates Patch Over 100 Vulnerabilities appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Robinhood deepens agentic AI offering in push to become go-to place for active traders

At yesterday evening’s HOOD Summit: Engines of Creation, Robinhood chairman and CEO, Vlad Tenev, announced a clutch of new active trading products.

Finextra
MEDIUMVulnerability

AI Boosts SOC Analyst Capacity but Limits Skill Development

Swimlane finds that AI is reducing repetitive work for SOC teams but some feel their careers may suffer

Infosecurity Magazine
MEDIUMMalware

Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters

The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware.

The Record
MEDIUMVulnerability

Know Your Enemy: Browser-Based Attack Techniques in 2026

Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1.

The Hacker News
HIGHData Breach

The Mental Health Association Data Breach Settlement Agreed

The Mental Health Association, a Chicopee, Massachusetts-based human services agency that provides substance use recovery and support services for developmental [&#8230;] The post The Mental Health Association Data Breach Settlement Agreed appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure

Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to [&#8230;] The post DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure appeared first on The HIPAA Journal .

HIPAA Journal
LOWVulnerability

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts

The Hacker News
MEDIUMAi

Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware

Cybersecurity researchers at Huntress identify campaign to deliver potent trojan which targets users searching for ChatGPT via Google

Infosecurity Magazine
MEDIUMAi

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do. The post Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

FCA opens the gateway to regulated crypto

From today, crypto firms can apply for authorisation from the FCA, marking a landmark moment as the UK takes a step closer towards becoming one of the most trusted places in the world to build and invest in cryptoasset businesses.

Finextra
CRITICALZero Day

Bitget hacked via zero-day in third-party security products

Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]

BleepingComputer
MEDIUMAi

I Want Better Reporting on AI Genie Behavior

AI systems are regularly completing tasks in ways that their prompters don&#8217;t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I&#8217;ve been calling &#8220; genie behavior ,&#8221; because I think that really gets at the core of what&#8217;s happening. I wish the popular press would report on this better. I don&#8217;t like the &#8220;going rogu

Schneier on Security
MEDIUMVulnerability

HSBC prepares for the launch of HK$-backed stablecoin, RedCoin

HSBC's forthcoming stablecoin launch in Hong Kong will bare the brand RedCoin.

Finextra
MEDIUMVulnerability

Sibos 2026: &#39;ISO 20022 is the Sagrada Familia of the financial industry&#39;

Representatives from Swift, Standard Chartered Bank, Federal Reserve Bank of New York and Deloitte took to the stage at Sibos 2026 in Miami to discuss the decision to postpone the removal of unstructured addresses, despite the push towards the long-term objectives of ISO 20022.

Finextra
MEDIUMApt

Russian APT Star Blizzard Uses &#8216;RedFlick&#8217; Infection Chain in Recent Attacks

The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post Russian APT Star Blizzard Uses &#8216;RedFlick&#8217; Infection Chain in Recent Attacks appeared first on SecurityWeek .

SecurityWeek
MEDIUMPhishing

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

The Hacker News
HIGHData Breach

Pentagon personnel database breach exposes personal data of millions

A Pentagon personnel database was breached for nine months without anyone noticing. Over three million people are affected. Read more in my article on the Hot for Security blog.

Graham Cluley
MEDIUMData Breach

ShinyHunters Defiant After FBI Calls on Members to Come Forward

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Brazil&#39;s CSD BR to use the XRP Ledger for recording and auditing financial assets and securities

CSD BR, a financial market infrastructure authorized to operate as a registrar, central securities depository and settlement system, today announced the first phase of a strategic partnership with Ripple, the leading provider of blockchain solutions across traditional and digital finance.

Finextra
MEDIUMMalware

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

Cisco Talos
CRITICALVulnerability

WaterISAC reckons with range of threats after summer of cyberattacks

Internet-exposed tech, PLCs, outside integrators and inside protections are all factors the water sector’s information sharing and analysis center is watching. The post WaterISAC reckons with range of threats after summer of cyberattacks appeared first on CyberScoop .

CyberScoop
CRITICALPhishing

The MFA you have isn’t the MFA you think you have

For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they’ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason — adding a second factor to a password login closed off an enormous share of credential-based attacks, and organizations that adopt

CSO Online
MEDIUMVulnerability

MoonPay opens for business in Korea

MoonPay has officially launched MoonPay Korea, its new subsidiary and planned hub for dedicated Asia-Pacific expansion.

Finextra
MEDIUMVulnerability

Kora debuts One Rail to support Pan-African stablecoin transactions

Pan-African payment infrastructure provider Kora has announced the launch of One Rail, a significant expansion of its payments infrastructure designed to support stablecoins.

Finextra
MEDIUMVulnerability

Aljazira Bank to grow international remittance services with Thunes

Thunes, the Smart Superhighway to move money around the world, has signed a new agreement with Aljazira Bank, one of Saudi Arabia's leading financial institutions, to modernize and expand its international remittance services.

Finextra
MEDIUMVulnerability

Visa and Lloyds complete live trials of stablecoin settlement

Visa and Lloyds Banking Group have completed a live pilot exploring how stablecoin-based settlement could support faster, more transparent and flexible cross-border transactions.

Finextra
MEDIUMAi

Duco clients report 76% time savings in post-trade reconciliation operations with AI platform

Duco, the leading platform for agentic Operations in financial services, today announced the results of its Pacesetters programme, in which an initial group of 12 clients cut the time spent on manual reconciliation operational work by an average of 76% using Duco’s agentic workspace in production trials.

Finextra
MEDIUMAi

Brits feel overwhelmed by growing sophistication of AI-powered scams

The UK's National Trading Standards body reports that half of Brits struggle to tell what’s genuine online, while a quarter admit to feeling overwhelmed by the sophistication of scams as AI supercharges criminal activity.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-102578 — A flaw was found in Moodle. An authenticated attacker with access to the questio...

A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.

CVE-2026-102578
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102458 — EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. U...

EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.

CVE-2026-102458
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102455 — EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability....

EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

CVE-2026-102455
NIST NVD
MEDIUMAi

Ant International’s Antom supports Google Gemini push into Asian markets

Google Gemini and Antom, a leading merchant payment and digitisation services provider under Ant International, today announced a strategic partnership to make AI tools for learning, creativity and productivity more accessible to users in Asia.

Finextra
MEDIUMAi

BMLL and Simudyne to deliver AI market simulation with high-fidelity historical data

BMLL, the leading independent provider of harmonised, continually engineered historical Level 3, 2 and 1 data and analytics for Capital Markets, today announced a partnership with Simudyne, an advanced generative AI and agent-based simulation platform designed to model and replicate market dynamics.

Finextra
CRITICALAi

Can we jail a superintelligence?

AI containment is essential, but security leaders should assume every boundary can fail once an agent can communicate, use tools, and act on real systems. On September 17, podcaster Steven Bartlett asked four AI experts an unusual question: Could you build a jail for a digital Einstein? The panel on The Diary of a CEO was debating whether AI could one day threaten humanity, but the question that s

CSO Online
CRITICALZero Day

Apple Patches CoreGraphics Zero Day Exploited in Attacks

Apple has patched CVE-2026-86950, a zero-day bug in the iOS CoreGraphics engine

CVE-2026-86950
Infosecurity Magazine
LOWAi

Whatever happened to the 36-month IT security roadmap?

Insight Global’s John Dickson had a problem familiar to many CISOs today. Employees were embracing AI tools faster than his security team could track them, and new AI agents and service integrations spread rapidly across the environment alongside them. Dickson and his security org had plans to build visibility into those non-human identities (NHIs), tracking what they could reach and how they beha

CSO Online
MEDIUMVulnerability

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional

The Hacker News
MEDIUMVulnerability

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

The Hacker News
MEDIUMVulnerability

Zumo launches UK Crypto Regulation Tracker

UK digital asset firm Zumo has launcheed a Crypto Regulation Tracker to help firms cut through red tape and conquer the complexities associated with the incoming comprehensive regulatory regime.

Finextra
MEDIUMAi

This month in security with Tony Anscombe – September 2026 edition

Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep pace

WeLiveSecurity (ESET)
HIGHRansomware

South Africa Seeks Help After Cyberattack Targets Air Traffic Control

As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.

Dark Reading
MEDIUMVulnerability

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. The post High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

CVE-2026-94545 (CVSS 9.5) affects Next.js apps using next/og on the Node.js runtime with sharp.

[object Object]

CVE-2026-94545
r/cybersecurity
CRITICALVulnerability

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

CVE-2026-88772
The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-102913 — A security flaw has been discovered in SourceCodester Car Driving School Managem...

A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-102913
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102911 — A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknow...

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is

CVE-2026-102911
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102910 — A security flaw has been discovered in SourceCodester Online Reviewer Management...

A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-102910
NIST NVD
MEDIUMAi

What Is Agentic AppSec?

Learn how Agentic AppSec uses grounded, bounded, and independently verified AI agents to run the application security loop.

Snyk
MEDIUMAi

Evo ADS Govern Agent Behavior Goes GA: Bringing MCP Usage Under Control

Evo ADS Govern Agent Behavior is now generally available, starting with MCP Governance. Discover, approve, monitor, log, and block MCP server usage across leading AI coding agents.

Snyk
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103109 — Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper in...

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.

CVE-2026-103109
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103101 — Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input valid...

Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.

CVE-2026-103101
NIST NVD
MEDIUMVulnerability

Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development

The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103056 — AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in ...

AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitr

CVE-2026-103056
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-103055 — AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verificatio...

AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.

CVE-2026-103055
NIST NVD
HIGHData Breach

Data breach incident targets prisoner medical records at 2 Mass. jails

Hadley Barndollar of masslive.com reports: A “cybersecurity incident” has occurred involving the electronic health record system for Suffolk County’s two jails, the system provider confirmed Thursday. Computer Systems Integrated Inc., which runs the EHRs-C platform containing prisoner health data and medical records, said it is aware of and investigating an incident involving the Suffolk County...

DataBreaches.net
MEDIUMVulnerability

Microsoft is rolling out Linux container support to WSL

Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102794 — A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects...

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-102794
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102793 — A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects ...

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in

CVE-2026-102793
NIST NVD
MEDIUMVulnerability

Elio Mortgage launches with $5.1m in pre-seed funding

AI-native startup Elio Mortgage has raised $5.1 million in pre-seed funding led by Motive Partners and Social Leverage.

Finextra
MEDIUMVulnerability

Circle and Volante partner to help banks integrate stablecoins into payment operations

Payments-as-a-Service specialist Volante Technologies is working with USDC-issuer Circle to help financial institutions integrate stablecoin payment and settlement capabilities into their existing operations.

Finextra
MEDIUMVulnerability

Valley Bank to buy digital SME banking platform Bluevine

Regional lender Valley National Bank has agreed to buy SME digital banking platform Bluevine for around $340 million in cash and stock.

Finextra
MEDIUMVulnerability

SMEs turn from banks to fintechs for cross-border payments

Most small and medium-sized businesses (SMEs) trading internationally are set to switch their current cross-border payment provider in the next two years, according to a Mastercard report.

Finextra
MEDIUMVulnerability

Sibos 2026: What does sovereignty look like in a multi-rail payments landscape?

A hot conversation topic at Sibos this year is interoperability with emerging payments rails, which begs the question of what monetary sovereignty means in a multi-rail digital financial system.

Finextra
HIGHVulnerability

CISA KEV: Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

CVE-2026-76504Cisco Catalyst SD-WAN Manager
CISA KEV
HIGHVulnerability

NVD HIGH: CVE-2026-103042 — LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL co...

LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.

CVE-2026-103042
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103041 — LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cac...

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.

CVE-2026-103041
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103040 — LightLLM through 1.2.0 contains a remote code execution vulnerability in the rou...

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.

CVE-2026-103040
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102792 — A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the fun...

A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-102792
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-74222 — U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_r...

U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP input path to access released memory and crash the bootloader.

CVE-2026-74222
NIST NVD
CRITICALZero Day

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks

Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.

CVE-2026-86950
Dark Reading
CRITICALZero Day

Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected

Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come. The post Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Signal adds encypted local backup support to iOS, desktop apps

Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]

BleepingComputer
LOWVulnerability

Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution

A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.

Dark Reading
MEDIUMVulnerability

US Air Force members given over 6 years in prison for cyber theft of more than $2 million

According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June.

The Record
MEDIUMAi

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

BleepingComputer
MEDIUMVulnerability

Controversial spyware firm Paragon to go public by end of year

The company plans to close the deal around the end of the year at which point Paragon will begin trading on Nasdaq under the REDLattice umbrella.

The Record
CRITICALVulnerability

NVD CRITICAL: CVE-2026-53988 — Dockhand before 1.0.40 contains an authentication bypass vulnerability in its gi...

Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or,

CVE-2026-53988
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102876 — SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construc...

SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, cr

CVE-2026-102876
NIST NVD
MEDIUMAi

OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

FBI tells ShinyHunters members to turn themselves in after recent arrest

The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]

BleepingComputer
MEDIUMApt

Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond

Microsoft says the cyberespionage campaign has hit U.S. and U.K. targets, relying on sheer volume and requiring only a single victim interaction. The post Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond appeared first on CyberScoop .

CyberScoop
MEDIUMAi

OpenAI apologizes for agents breaching Australian government websites without authorization

The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.

The Record
CRITICALVulnerability

US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says

Sean Cairncross said CEOs need to be cognizant of how it’s being used, however. The post US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says appeared first on CyberScoop .

CyberScoop
CRITICALVulnerability

Cyberattacks to be insured like accidents: Ministry of Finance discusses new rules for critical infrastructure

Roman Zaharov reports: Cyberattacks may start to be insured according to the principle already in effect for hazardous facilities. The Russian Ministry of Finance is discussing the possibility of making cyber risk insurance mandatory for businesses associated with critical infrastructure. This was stated by Deputy Finance Minister Ivan Chebeskov on the sidelines of the Moscow... Source

DataBreaches.net
MEDIUMVulnerability

BankPro picks Thredd to power card programmes

BankPro, the private digital bank headquartered in The Bahamas, today announced a strategic partnership with Thredd, the AI-first issuer processing platform, to power its physical and virtual debit and credit card programmes.

Finextra
LOWVulnerability

Shocker: suspected ShinyHunters member charged with attempted incitement to commit two murders

Anyone following the recent arrest of Pepijn van der Stap, the previously convicted hacker known as &#8220;Umbreon,&#8221; was likely shocked today when the prosecution announced that he was being charged with two counts of attempted incitement to murder. Here&#8217;s what we know so far. A 24-year-old Dutch national who previously served time for hacking-related crimes... Source

DataBreaches.net
CRITICALZero Day

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]

CVE-2026-88772
BleepingComputer
MEDIUMVulnerability

Jeeves raises $110m for stablecoin banking platform

Corporate card and expense management platform Jeeves has raised $110 million to scale its stablecoin-native banking platform for global enterprises.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-84440 — IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP...

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.

CVE-2026-84440
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-84436 — IBM Guardium Data Protection 12.2 is vulnerable to command injection in the cert...

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.

CVE-2026-84436
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102811 — Marmite through 0.4.2 contains missing authentication in the development server ...

Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project director

CVE-2026-102811
NIST NVD
MEDIUMPhishing

Former US Air Force members sent to prison over BEC attacks

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

BleepingComputer
LOWAi

Sibos 2026: Google Cloud reveals banks are moving from AI copilots to autonomous workflows

Held at The National Hotel in Miami during Sibos 2026, Google Cloud hosted a breakfast roundtable that focussed on the future of purpose-built AI for financial institutions, welcoming Georgina Bulkeley, director of financial services solutions, Google Cloud; Kristin Reinke, VP of finance, Google; Jason Allen, assistant treasurer, Google; Sarthak Pattanaik, chief data and AI officer, BNY; Joanne Ha

Finextra
MEDIUMVulnerability

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak

The Hacker News
MEDIUMVulnerability

Windows 11 2026 Update released, here's everything you need to know

Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. [...]

BleepingComputer
MEDIUMVulnerability

DARPA Selects Xint to Use AI in Securing Military Messaging Apps

The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software. The post DARPA Selects Xint to Use AI in Securing Military Messaging Apps appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached

The Hacker News
MEDIUMVulnerability

New Spectre v2 attack variant leaks Linux root password hash in minutes

A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]

BleepingComputer
MEDIUMVulnerability

Cloudflare Announces Public Certificate Authority for the Post-Quantum Web

Automated certificates for everyone, built for today, and hardened for the era of quantum computing.

Dark Reading
MEDIUMData Breach

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs

The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2023-54400 — Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.a...

Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with

CVE-2023-54400
NIST NVD
LOWVulnerability

Experian deliver Cashback Attributes

Experian today announced Experian Cashflow Attributes for commercial lenders, a new solution that transforms business bank transaction data into analytics-ready attributes to help financial institutions make more informed decisions and gain a deeper understanding of the financial health of the businesses they serve.

Finextra
MEDIUMVulnerability

Citi expands Token Services to the UAE and Japan

Citi has announced the expansion of Citi Token Services into the UAE and Japan, extending its global footprint and always-on 24/7 capability to support clients’ liquidity, payments, and collateral needs.

Finextra
MEDIUMAi

Automated AI agent used to breach cybersecurity nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]

BleepingComputer
MEDIUMAi

Throught Machine and AWS to drive AI-powered core migrations

Thought Machine, the cloud-native core banking and payments technology company, today announced an AI-powered migration solution to accelerate banking modernisation with Amazon Web Services, Inc. (AWS) Transform.

Finextra
MEDIUMVulnerability

Chainlink connects to Swift&#39;s blockchain ledger

Chainlink today announced it is working to enable financial institutions to connect their systems and key signing infrastructure to Swift's blockchain ledger through the Chainlink platform.

Finextra
MEDIUMVulnerability

Alleged ShinyHunters leader arrested in the Netherlands

The arrest of a 24-year-old man in Amsterdam, which occurred a week before ShinyHunters hacked the FBI, marks a major turning point for law enforcement’s push to track down the group’s members. The post Alleged ShinyHunters leader arrested in the Netherlands appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Terrabank to streamline cross-border payments with TerraPay and Mozrt

Terrabank, a Miami-based community bank and affiliate of Grupo Promerica, today announced a strategic partnership with TerraPay, a global money movement company, and Mozrt, a payments technology platform, to modernize and streamline cross-border payments.

Finextra
MEDIUMVulnerability

Nayax and Santander&#39;s Getnet collaborate on unattended payments

Getnet, the global merchant payments platform and the leading payment solutions provider in Latin America and Iberia, and Nayax Ltd (NASDAQ: NYAX, TASE: NYAX), a global commerce enablement, payments, and loyalty platform helping merchants scale their business, today announced its partnership aimed at accelerating integrated payment acceptance and commerce services across key markets in Europe and

Finextra
MEDIUMVulnerability

Center Parc Credit Union streamlines loan payment operations and plans for instant payments

Center Parc Credit Union has streamlined its loan payment operations with Alacriti's Orbipay Loan Payments solution, replacing fragmented payment processes with a unified self-service experience that makes it easier for members to make loan payments.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-102566 — CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary mod...

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.

CVE-2026-102566
NIST NVD
MEDIUMMalware

'NeedyMantis' Provides Long-Term Access to Compromised Networks

Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.

Dark Reading
LOWVulnerability

Autonomous Remediation Is Already Running at Enterprise Scale

The following is a guest blog by ITSPmagazine, based on their interview of Qualys President &#38; CEO Sumedh Thakar at Black Hat USA 2026. Sumedh Thakar has watched the same clock compress for 23 years. He joined Qualys as an early software engineer on the scanner, when organizations scanned once every 90 days and gave [&#8230;]

Qualys Blog
LOWSupply Chain

OpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing lines

OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company’s safety and alignment standards. GPT-6.1 Astra was being developed as a more autonomous model capable of handling complex tasks with less human assistance, and was expected to be integrated into ChatGPT and Codex. But internal testing found that it could evade oversight

CSO Online
MEDIUMVulnerability

RemoteThreat Launches With $7 Million for Offensive Operations Platform

The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek .

SecurityWeek
MEDIUMMalware

RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model

RatHat's C2 panel now builds malware and ranks victims with AI across nearly 100 deployments

Infosecurity Magazine
CRITICALZero Day

Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.

Dark Reading
CRITICALVulnerability

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company

The Hacker News
CRITICALVulnerability

Kiteworks lifts shutdown advisory after &#8216;credible threat intelligence&#8217; from federal authorities

The company said it found and patched a previously unknown critical vulnerability in one product during the weekend shutdown, and has no indication it was exploited. The post Kiteworks lifts shutdown advisory after &#8216;credible threat intelligence&#8217; from federal authorities appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Catch threats before they escalate with real-time Identity Telemetry

Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity before it escalates. [...]

BleepingComputer
MEDIUMVulnerability

Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials

AWS AgentCore SDK flaws could let attackers run commands in AI sandboxes and reach AWS credentials

Infosecurity Magazine
MEDIUMVulnerability

Bradesco completes pilot transaction using BofA cross-border payments tech

Bank of America today announced that Bradesco, one of Brazil’s largest private-sector banks, has completed the first pilot transaction using the bank’s Cross-Border Real-Time Payments solution.

Finextra
MEDIUMVulnerability

WPM Pathology Laboratory; Salina Regional Health Center Settle Class Action Litigation

A settlement has been agreed to resolve class action litigation over a November 2024 targeted cyberattack on the information systems [&#8230;] The post WPM Pathology Laboratory; Salina Regional Health Center Settle Class Action Litigation appeared first on The HIPAA Journal .

HIPAA Journal
LOWVulnerability

Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs

[object Object]

CVE-2026-88772
r/cybersecurity
CRITICALZero Day

Citrix Patches Actively Exploited NetScaler ADC &#038; NetScaler Gateway Vulnerabilities

Two critical zero-day vulnerabilities in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are under [&#8230;] The post Citrix Patches Actively Exploited NetScaler ADC &#038; NetScaler Gateway Vulnerabilities appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Astrana Health Notifies SEC About Social Engineering Incident

Astrana Health, a managed services organization that helps healthcare providers deliver value-based, coordinated care to patients, has notified the U.S. [&#8230;] The post Astrana Health Notifies SEC About Social Engineering Incident appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMSupply Chain

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

The Hacker News
MEDIUMVulnerability

Thai remittance fintech DeeMoney selects SEON as its fraud and compliance partner

SEON, the AI Command Center for Fraud Prevention and AML Compliance, today announced that DeeMoney, Thailand’s leading fintech for international money transfers, has selected SEON as its fraud and compliance partner.

Finextra
MEDIUMMalware

Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

Microsoft Threat Intelligence warns that NeedyMantis threat actor from China has targeted organizations across a range of industries

Infosecurity Magazine
MEDIUMVulnerability

AAIB deploys IBM&#39;s Safer Payments platform

Arab African International Bank (AAIB) achieved further progress in strengthening its digital payments security and fraud prevention capabilities through its collaboration with IBM and TECH-HUB.

Finextra
MEDIUMVulnerability

Scans for Wordfence Protected Websites, (Tue, Sep 29th)

Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-waf.php file will be created in the site&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s root directory &#x5b;1&#x5d;.&#xd;

SANS ISC
MEDIUMVulnerability

DTCC appoints Samir Pandiri as chief client officer

The Depository Trust & Clearing Corporation (DTCC), the premier post-trade market infrastructure for the global financial services industry, today announced the appointment of Samir Pandiri as Managing Director and Chief Client Officer, effective September 28.

Finextra
MEDIUMAi

Reco Raises $55 Million for Agentic Security

The company will use the funds to expand its sales, partnerships, channels, and customer support teams. The post Reco Raises $55 Million for Agentic Security appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands. The post Hackers Use ChatGPT Custom GPTs in ClickFix Attacks appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Swedish fintech Froda expands to France

Froda, the Swedish embedded financing platform serving Europe's smallest businesses, today announced its launch in France in partnership with Shine.

Finextra
MEDIUMVulnerability

FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data

Joseph Cox reports: The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical addresses, job roles, names of spouses, and medical records, represents a significant national security and... Source

DataBreaches.net
MEDIUMVulnerability

Russian pizza restaurant chain confirms cyberattack: Hackers claim 68 million users exposed

Andrey Mihayloff reports: Dodo Pizza has confirmed a cyberattack on its IT systems, admitting that attackers may have accessed personal data of a portion of its customer base. The company reported the breach to Roskomnadzor and stated that access to the system has since been blocked. According to the company, the exposed data may include:... Source

DataBreaches.net
LOWVulnerability

Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims

According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details.

The Record
HIGHRansomware

Arizona Supreme Court says hackers stole residents’ personal data

A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.

The Record
HIGHData Breach

Pentagon Personnel Agency Data Breach Impacts 3 Million People

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on SecurityWeek .

SecurityWeek
CRITICALPhishing

Baicells Nova 430H

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition.</strong></p> <p>The following versions of Baicells Nova 430H are affected:</p> <ul> <l

CVE-2026-96274
CISA Advisories
CRITICALVulnerability

VIVOTEK Camera Firmware

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system.</strong></p> <p>The followin

CVE-2026-22755
CISA Advisories
CRITICALPhishing

Viidure Dashcam Android Application

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform.</strong></p> <p>The foll

CVE-2026-94204CVE-2026-96587
CISA Advisories
MEDIUMAi

Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks

Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on SecurityWeek .

SecurityWeek
LOWAi

Finastra unveils AI-powered repair recommendations to support banks with smarter decision-making

Today at Sibos 2026 in Miami, Finastra announced the launch of Repair Recommendations – a new AI-powered capability within AI OperatorAssist. This move will help banks respond more quickly to growing payment activity by adding smarter decision-making into their existing workflows.

Finextra
CRITICALPhishing

Anjvision YSSD-RTMP-H5

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device.</strong></p> <p>The following versions of

CVE-2026-100291CVE-2026-100292
CISA Advisories
CRITICALSupply Chain

Lantronix G520 Series Cellular Gateway

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges.</strong></p> <p>The following versions of Lantronix G520 Series Cellular Gateway are affecte

CVE-2026-84409CVE-2026-91191
CISA Advisories
CRITICALPhishing

Toptech TMS7 and TopHAT

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.</strong></p> <p>The following versions of Toptech TMS7 and TopHAT are affected:</p> <ul> <li>TMS7 7.6.3 (CVE-2

CVE-2026-71379CVE-2026-70356
CISA Advisories
MEDIUMVulnerability

Vietnamese man charged in $16 million 'pig butchering' crypto scam

A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]

BleepingComputer
MEDIUMSupply Chain

Four Cyber Threats Harboring Big Plans for the Future

- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations. The post OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

HSBC rolls out new digital transaction banking platform

HSBC has vowed to reduce complexity for corporate clients with the roll out of a new digital transaction banking platform.

Finextra
LOWApt

Using Device Linking to Eavesdrop on WhatsApp and Signal

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. Germany&#8217;s Customs Office has been using these features to connect a police-controlled computer to a suspect&#8217

Schneier on Security
MEDIUMVulnerability

Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them. The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Anthropic prospectus warns of &#39;existential threat to humanity&#39;

Anthropic is inviting stock pickers to invest in no future, as its long-awaited IPO prospectus warns that its models could pose a 'catastrophic or existential risks to humanity'.

Finextra
MEDIUMAi

OperTraitors: How Kubernetes Operators Betray Your Security Posture

We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray Your Security Posture appeared first on Unit 42 .

Unit 42 (Palo Alto)
MEDIUMVulnerability

Securing the keys to the kingdom: Announcing Executive Threat Detection

This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most high-value IT assets.

Cisco Talos
MEDIUMVulnerability

How AI Changes the SDLC Beyond Faster Coding

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/how-ai-changes-the-sdlc-beyond-faster-coding" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/AI%20SDLC.png" alt="Image with concentric hexagon shapes at the center, with the innermost containing "AI" text with network nodes protruding out." class="hs-featured-image" style="width:auto !

Sonatype (Maven/npm)
MEDIUMSupply Chain

Daemon Tools Hackers&#8217; NeedyMantis Malware Dissected by Microsoft

The malware framework uses a modular architecture and a custom executable file format for long-term persistence. The post Daemon Tools Hackers&#8217; NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Japanese Railway Operators Hit with Weekend Cyber Attacks

Tokyo Metro and Keio have revealed separate cyber-attacks

Infosecurity Magazine
MEDIUMVulnerability

Broadridge appoints Theo Golden as head of tokenized products, international

Broadridge, (NYSE: BR) today announced the appointment of Theo Golden, CFA as Head of Tokenized Product, International, a newly created role.

Finextra
MEDIUMVulnerability

Icma examines the role of smart contracts in distributed ledger technology in fixed income markets

The International Capital Market Association (ICMA) has today published a new discussion paper, "Smart contracts and DLT-based fixed income markets: What’s next?", examining the growing role of smart contracts in distributed ledger technology (DLT)-based fixed income markets and the challenges that will need to be addressed as the market develops.

Finextra
MEDIUMVulnerability

Doconomy and Swedbank initiate climate research initiative

Doconomy and Swedbank have entered into a research collaboration as part of an international initiative exploring how consumers can better understand the climate and social impacts of their spending.

Finextra
MEDIUMVulnerability

Kiteworks Urges Customers to Restart Systems After Shutdown Notice

Kiteworks has lifted a temporary shutdown recommendation which was issued on the back of federal intelligence

Infosecurity Magazine
MEDIUMVulnerability

mambu connects with Mastercard Move

Mambu and Mastercard have today announced a strategic collaboration that will make it easier for financial institutions using Mambu to offer fast, secure and transparent cross-border payments.

Finextra
MEDIUMVulnerability

Zopa brings in targeted support for investment customers

Zopa, the British digital bank pioneer with 2 million customers, has launched targeted support for its investment customers.

Finextra
MEDIUMVulnerability

EPSG publishes version 11 of its SEPA Payments Standardisation Volume

The European Payments Stakeholders Group (EPSG), the industry association for payments harmonisation in the Single Euro Payments Area (SEPA), published version 11 of its SEPA Payments Standardisation Volume.

Finextra
LOWVulnerability

Walletdoc introduces Visa Payment Passkeys

South African shoppers can now skip the frustrating redirect to their bank and the one-time PINs that slow down online card payments and instead approve a purchase with a simple biometric check on their phone.

Finextra
MEDIUMVulnerability

EU backs spotixx

Frankfurt-based fintech spotixx has been awarded funding from the EU's Eurostars program. Germany’s Federal Ministry of Research, Technology and Space (BMFTR) is funding a joint project between spotixx and Dutch company Roseman Labs.

Finextra
MEDIUMVulnerability

Abhi and NymCard combine on SME credit provision for financial institutions in UAE

Abhi, an embedded finance platform providing Earned Wage Access (EWA) and financial technology solutions, , and NymCard, the leading payments infrastructure provider in the Middle East, today announced a strategic partnership to enable financial institutions to deliver more efficient credit solutions to small and medium-sized enterprises (SMEs) in the UAE.

Finextra
CRITICALVulnerability

Kiteworks patches critical flaw, brings customer systems online

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]

BleepingComputer
MEDIUMVulnerability

Sibos 2026: BofA expands payments capabilities with new intelligence and real-time services

At Sibos 2026, held in Miami, Bank of America announced numerous updates across its banking services that tap into the opportunities offered by advanced analytics, AI and real-time networks.

Finextra
MEDIUMVulnerability

Brite Payments brings international Pay-by-Bank network to the UK

Swedish Pay-by-Bank network Brite Payments is launching in the UK after securing an Electronic Money Institution (EMI) licence from the Financial Conduct Authority (FCA)

Finextra
MEDIUMVulnerability

Timeshare exit scams: From fake buyers to recovery fraud

Con artists are targeting timeshare owners who want out – and some victims are hit twice

WeLiveSecurity (ESET)
MEDIUMVulnerability

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the

The Hacker News
MEDIUMVulnerability

Lessons from Microsoft Patch KB5002907: Two Layers of Patch Control in Qualys TruRisk Eliminate

How reliability scoring keeps risky patches out of zero-touch jobs, and how one blocking rule stops a paused update across your environment. Executive Summary Microsoft has paused the rollout of KB5002907, an optional Microsoft 365 Apps update that left some Office 2016 and Office 2019 installations unlicensed or removed. When an update runs into trouble [&#8230;]

Qualys Blog
CRITICALZero Day

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]

BleepingComputer
MEDIUMVulnerability

Marble raises €6.5m to automate compliance

French open-source infrastructure platform for fraud detection and AML/CFT compliance Marble has raised €6.5 million in a Series A funding round.

Finextra
CRITICALZero Day

Apple Patches Meta-Reported Zero-Day Linked to &#8216;Extremely Sophisticated Attack&#8217;

Apple has released iOS and macOS updates to patch the zero-day vulnerability tracked as CVE-2026-86950. The post Apple Patches Meta-Reported Zero-Day Linked to &#8216;Extremely Sophisticated Attack&#8217; appeared first on SecurityWeek .

CVE-2026-86950
SecurityWeek
CRITICALZero Day

Apple Patches Zero-Day Linked to &#8216;Extremely Sophisticated Attack&#8217;

Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team. The post Apple Patches Zero-Day Linked to &#8216;Extremely Sophisticated Attack&#8217; appeared first on SecurityWeek .

CVE-2026-86950
SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-102293 — A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the ...

A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVE-2026-102293
NIST NVD
LOWAi

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

The Hacker News
MEDIUMAi

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said.

The Hacker News
MEDIUMAi

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-102249 — A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability ...

A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did n

CVE-2026-102249
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-102245 — A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected ...

A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The

CVE-2026-102245
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102240 — A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the ...

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not res

CVE-2026-102240
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101354 — A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affecte...

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early ab

CVE-2026-101354
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101281 — A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected ...

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c75

CVE-2026-101281
NIST NVD
MEDIUMAi

Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI

Nvidia on Monday rolled out an agentic governance system called the Open Agent Safety Platform that combines software with out-of-band DPU-based silicon in a reference system design that it says will secure agents “from testing to deployment.” But while the Nvidia design’s silicon-based component provides some cybersecurity advantages, analysts argued that it cannot help with the vast majority of

CSO Online
CRITICALZero Day

Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings

The vendor’s products are a common, recurring target for attackers, yet the official warning for some Citrix NetScaler customers was too late. The post Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings appeared first on CyberScoop .

CyberScoop
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102361 — mall4j through 4.0 contains a missing authentication vulnerability in the PUT /u...

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.

CVE-2026-102361
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101264 — A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unk...

A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101264
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101263 — A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some...

A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101263
NIST NVD
MEDIUMVulnerability

ECB invites expressions of interest for digital euro innovation workstreams

The European central Bank is inviting private companies and organisations to join the digital euro innovation platform to collaborate on experiments with new value-added services and explore future technological developments.

Finextra
MEDIUMVulnerability

Sibos 2026: Keynote speakers explore interoperability, digital assets, and AI

Sibos 2026 in Miami kicked off with an introduction to the annual conference by Graeme Munro, chair of the board at Swift.

Finextra
HIGHVulnerability

CISA KEV: Apple Multiple Products — Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

CVE-2026-86950Apple Multiple Products
CISA KEV
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101262 — A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability...

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any wa

CVE-2026-101262
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101261 — A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown par...

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101261
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101260 — A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this iss...

A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument firstLogin results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respon

CVE-2026-101260
NIST NVD
CRITICALVulnerability

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s update for the current "27" branch does not address security issues, but fixes some functional

CVE-2026-86950
SANS ISC
HIGHVulnerability

NVD HIGH: CVE-2026-101188 — A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638....

A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101188
NIST NVD
MEDIUMAi

Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities

The Open Agent Safety Platform relies on both hardware and software components to monitor agent activities and quarantine unruly agents before they cause harm.

Dark Reading
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101187 — A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability...

A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used f

CVE-2026-101187
NIST NVD
CRITICALZero Day

One Packet Can Crash OT Servers in Industrial Sectors

A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.

Dark Reading
HIGHRansomware

Japan's Keio confirms ransomware attack disrupted business systems

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]

BleepingComputer
HIGHData Breach

Times Car confirms data breach affecting 6.6 million user accounts

Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]

BleepingComputer
MEDIUMAi

Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.

Dark Reading
MEDIUMVulnerability

Dutch police confirm arrest in ShinyHunters hacking investigation

Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. [...]

BleepingComputer
MEDIUMVulnerability

ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns

A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.

The Record
MEDIUMVulnerability

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the

CVE-2026-86950
The Hacker News
MEDIUMVulnerability

Misconfigured Supabase apps expose data in over 16,000 databases

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]

BleepingComputer
MEDIUMVulnerability

Over 16,000 Supabase databases expose PII, passwords, auth tokens

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]

BleepingComputer
MEDIUMAi

AI Agents Are Privileged Users; Who Is Auditing Their Access?

Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.

Dark Reading
MEDIUMMalware

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

The Hacker News
MEDIUMAi

As AI world debates security, NVIDIA releases open source tools for agents

One expert told CyberScoop that the announcement reflects industry recognition that after years of training models to behave safely or ethically, more outside controls are needed. The post As AI world debates security, NVIDIA releases open source tools for agents appeared first on CyberScoop .

CyberScoop
MEDIUMAi

IAM for AI agents: A Practical Enterprise Framework

What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended.

The Hacker News
MEDIUMVulnerability

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most

The Hacker News
MEDIUMAi

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

The Hacker News
LOWAi

Modulate Raises $25 Million to Advance Deepfake Detection

The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention. The post Modulate Raises $25 Million to Advance Deepfake Detection appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101081 — A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability ...

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-101081
NIST NVD
MEDIUMVulnerability

New Mexico jury finds Meta deceived consumers about data privacy practices

A New Mexico jury found Facebook violated the law nearly 44 million times by lying to consumers about its data privacy practices.

The Record
MEDIUMVulnerability

Hogan Lovells Cadwalader hacked by Silent Ransom Group; re-attacked after they wouldn&#8217;t pay

Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG&#8217;s recent attacks on Hogan Lovells Cadwalader. Yes, that&#8217;s &#8220;attacks,&#8221; plural. When New York City&#8217;s oldest law firm, Cadwalader, Wickersham &#38; Taft, merged with Hogan Lovells in 2022, it combined two powerhouse firms. Yet despite... Sourc

DataBreaches.net
CRITICALAi

OpenAI pauses AI model training after another agent bypasses network restrictions

OpenAI has paused training, evaluation, and inference involving tool use for its most-capable AI models after an agent bypassed network restrictions to communicate with an external chatbot during reinforcement-learning training of an internal research model. “Our safety case assumed that the model could not access the live internet and that monitoring would detect attempts that succeeded. The inci

CSO Online
MEDIUMVulnerability

Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions

A purported ad-blocker exfiltrates reams of sensitive information, and benefits from having Google's stamp of approval despite researcher warnings.

Dark Reading
CRITICALZero Day

US, UK warn of exploited Citrix NetScaler zero-day bugs

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.

The Record
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101077 — A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function pr...

A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101077
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101076 — A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the func...

A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101076
NIST NVD
MEDIUMVulnerability

Still on probation from previous arrest for hacking and extortion, Dutch national is arrested again (1)

In June 2023, DataBreaches reported on the arrest of a young Dutch national who was a highly respected &#8220;white hat&#8221; by day but also a prolific &#8220;black hat.&#8221; History seems to have repeated itself. Pepijn van der S. has been arrested once again for criminal activities. The Past Predicted the Present Pepijn van der Stap,... Source

DataBreaches.net
HIGHRansomware

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]

BleepingComputer
MEDIUMAi

JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack

The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.

Dark Reading
MEDIUMVulnerability

Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official

September 25 &#8211; U.S. Department of Justice: Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101075 — A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The imp...

A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi

CVE-2026-101075
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101074 — A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected elemen...

A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted

CVE-2026-101074
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101073 — A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an...

A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in

CVE-2026-101073
NIST NVD
MEDIUMVulnerability

Call for Presentations Open for 2026 CISO Forum Virtual Summit

SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs. The post Call for Presentations Open for 2026 CISO Forum Virtual Summit appeared first on SecurityWeek .

SecurityWeek
HIGHRansomware

Dutch Police Arrest &#8216;Reformed&#8217; Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.

Krebs on Security
CRITICALZero Day

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42 .

CVE-2026-88771CVE-2026-88772
Unit 42 (Palo Alto)
LOWVulnerability

Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach

Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets

Infosecurity Magazine
MEDIUMSupply Chain

The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches

A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.

Qualys Blog
MEDIUMVulnerability

Swift provdes cross-border gateway to Bizum, PayID and Pix users

Swift has launched an initiative to bring the pay-by-alias experience of domestic national payment systems, Bizum, PayID and Pix, to cross-border transactions, enabling consumers to send money internationally using a mobile number or email address, rather than account details.

Finextra
MEDIUMVulnerability

Swift provides cross-border gateway to Bizum, PayID and Pix users

Swift has launched an initiative to bring the pay-by-alias experience of domestic national payment systems, Bizum, PayID and Pix, to cross-border transactions, enabling consumers to send money internationally using a mobile number or email address, rather than account details.

Finextra
LOWVulnerability

ShinyHunters trades financial extortion for a reckless war of ego with the FBI

Cybercrime experts are stunned as ShinyHunters risks agent safety and intense federal heat in a bizarre attempt to force the retraction of an agency advisory. The post ShinyHunters trades financial extortion for a reckless war of ego with the FBI appeared first on CyberScoop .

CyberScoop
CRITICALRansomware

Autonomous agents attack Azure using compromised identities and destroying resources

Jadepuffer, an autonomous AI attacker first identified in July, has expanded into Azure environments, using compromised digital identities to enumerate resources, delete cloud assets and collect other credentials, according to Microsoft. The activity includes “extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be us

CSO Online
CRITICALRansomware

Autonomous agents attack Azure using compromised identities, destroying resources

Jadepuffer, an autonomous AI attacker first identified in July, has expanded into Azure environments, using compromised digital identities to enumerate resources, delete cloud assets and collect other credentials, according to Microsoft. The activity includes “extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be us

CSO Online
MEDIUMVulnerability

BNY unveils Pay-to-Wallet technology option for banks

BNY has unveiled a Pay-to-Wallet capability, making it possible for banks to send cross-border payments from bank accounts to participating retail digital wallets, using existing Swift payment messages and correspondent banking infrastructure.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-90924 — Use of default credentials vulnerability in Innotim Software, Telecommunications...

Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

CVE-2026-90924
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101072 — A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects ...

A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101072
NIST NVD
MEDIUMVulnerability

US banks invited to join Apple Pay class lawsuit

US banks have been given the green light to pursue a class action lawsuit against Apple over historical fees paid for access to the firm's mobile wallet.

Finextra
MEDIUMAi

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

The Hacker News
MEDIUMAi

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. [...]

BleepingComputer
MEDIUMVulnerability

Cyberattack on Polish medical software provider exposes patient data

Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.

The Record
MEDIUMAi

NVIDIA Launches Open Platform to Secure Autonomous AI Agents

NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents

Infosecurity Magazine
HIGHVulnerability

NVD HIGH: CVE-2026-86330 — An OS command injection flaw was found in the set_hostname_internal function of ...

An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can p

CVE-2026-86330
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101067 — A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. Th...

A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this dis

CVE-2026-101067
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101066 — A vulnerability was determined in dbgate up to 7.3.1. The impacted element is th...

A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about

CVE-2026-101066
NIST NVD
MEDIUMAi

Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns

A quarter of victims of deepfake attacks have lost over $1m. CISOs worry that boardrooms don’t understand the threat

Infosecurity Magazine
MEDIUMVulnerability

Former US soldier gets nearly six-year sentence for hacking, extorting telecoms

A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records.

The Record
MEDIUMVulnerability

Prison Sentence for Former US Soldier Who Hacked AT&#038;T and Verizon

Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers. The post Prison Sentence for Former US Soldier Who Hacked AT&#038;T and Verizon appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

The Hacker News
HIGHData Breach

DC Health Agency Exposes 400,000 Beneficiary Records

The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed. The post DC Health Agency Exposes 400,000 Beneficiary Records appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101039 — A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this...

A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101039
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101038 — A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by ...

A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond i

CVE-2026-101038
NIST NVD
MEDIUMVulnerability

New forms of intelligent money set to hit traditional bank B2B revenue streams

Stablecoins, tokenized deposits, and central bank digital currencies are projected to account for approximately four percent of global payments volume by 2030, diverting vast chunks of income from traditional bank revenue pools.

Finextra
LOWVulnerability

New Attack Against RSA

ArsTechnica is reporting on a &#8220;new&#8221; attack against RSA, one that bypasses factoring. First, this attack isn&#8217;t new. The original research is from 2007 . What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key. Third, the attack only works against pure signatures. T

Schneier on Security
MEDIUMVulnerability

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs

[object Object]

CVE-2026-88771
r/netsec
MEDIUMVulnerability

Google Warns of ShinyHunters&#8217; Fresh Oracle PeopleSoft Campaign

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters&#8217; Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek .

CVE-2026-35273
SecurityWeek
MEDIUMVulnerability

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform. The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

The platform combines open source software and a reference system design to keep AI agents within set boundaries. The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101037 — A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the f...

A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-101037
NIST NVD
CRITICALZero Day

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Overview On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772 . Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor

CVE-2026-88771CVE-2026-88772
Rapid7
MEDIUMVulnerability

CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack

[object Object]

CVE-2026-32740
r/netsec
CRITICALZero Day

NetScaler admins told to patch critical zero-days in ADC and Gateway now

Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “ Monday will be too late ,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirme

CVE-2026-88771CVE-2026-88772
CSO Online
MEDIUMAi

MCP Is Creating Major Governance Gaps, Researchers Warn

Ox Security found security shortcomings in analysis of over 15,000 MCP servers

Infosecurity Magazine
MEDIUMMalware

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]

BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-101015 — A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected ...

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclo

CVE-2026-101015
NIST NVD
MEDIUMVulnerability

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

The Hacker News
MEDIUMPhishing

The devil is still in the email – but wearing a new mask

When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack

WeLiveSecurity (ESET)
MEDIUMPhishing

The devil is still in the email – but wears a new mask

When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack

WeLiveSecurity (ESET)
MEDIUMVulnerability

Nubank in talks to take over Monzo

Brazilian neobank Nubank is reportedly eyeing a takeover of UK digital bank Monzo, in a deal that would value the British challenger at $10 billion.

Finextra
CRITICALZero Day

Citrix Patches Critical Zero Days Under Active Exploitation

Citrix has confirmed exploitation of two critical zero-day RCE bugs

Infosecurity Magazine
LOWSupply Chain

Stolen AI credentials feed growing LLM proxy economy

Cyber threat groups have increasingly targeted enterprise AI assets, such as credentials, cloud environments, and research, as a means for operationalizing their own use of AI . Now, another sophisticated means for obfuscating illegitimate use of AI resources is coming more clearly to light. According to a report last week from security firm Team Cymru, malicious actors are employing proxy servers

CSO Online
HIGHVulnerability

NVD HIGH: CVE-2026-101012 — A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to ...

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling re

CVE-2026-101012
NIST NVD
MEDIUMVulnerability

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]

BleepingComputer
CRITICALZero Day

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek .

CVE-2026-88771CVE-2026-88772
SecurityWeek
MEDIUMVulnerability

Weekly Update 523: Live From a Norwegian Fjord

How&apos;s that view?! With NDC Oslo now done, it&apos;s a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott&apos;s and my "Cyber-broken" talk. In the meantime, this week is mostly about the ShinyHunters trajectory targeting both

Troy Hunt
CRITICALVulnerability

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to

CVE-2026-88771
The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-101009 — A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected eleme...

A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendo

CVE-2026-101009
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101008 — A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the functio...

A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted ear

CVE-2026-101008
NIST NVD
CRITICALData Breach

California Critical Access Hospital Announces Cybersecurity Incident

Data breaches have been announced by Modoc Medical Center and Vista Del Mar Child and Family Services in California, Park [&#8230;] The post California Critical Access Hospital Announces Cybersecurity Incident appeared first on The HIPAA Journal .

HIPAA Journal
CRITICALVulnerability

CISA orders feds to patch exploited Citrix flaws by Wednesday

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101002 — A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affec...

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early

CVE-2026-101002
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101001 — A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impac...

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi

CVE-2026-101001
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101000 — A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affec...

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted ear

CVE-2026-101000
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100896 — A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected ...

A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVE-2026-100896
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100891 — A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. ...

A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used

CVE-2026-100891
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100888 — A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. ...

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for

CVE-2026-100888
NIST NVD
MEDIUMVulnerability

Revolut gets green light to buy Argentinian bank

Revolut has received the regulatory go-ahead to acquire small Argentinian lender Banco Cetelem from BNP Paribas.

Finextra
MEDIUMVulnerability

Singapore to train 80,000 FS sector employees in AI skills

Singapore's financial services sector has moved to prepare itself for the artificial intelligence era through the launch of an AI workforce co-lab and a commitment to train 80,000 employees in the technology.

Finextra
MEDIUMAi

OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email

OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100886 — A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4...

A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa

CVE-2026-100886
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100885 — A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unk...

A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this is

CVE-2026-100885
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101090 — Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect e...

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to b

CVE-2026-101090
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101084 — obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-co...

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

CVE-2026-101084
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101065 — Obot is an open-source AI agent/MCP platform. In all versions up to and includin...

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca

CVE-2026-101065
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-101062 — Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENAB...

Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own dom

CVE-2026-101062
NIST NVD
CRITICALVulnerability

AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772

[object Object]

CVE-2026-88771CVE-2026-88772
r/blueteamsec
MEDIUMVulnerability

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

[object Object]

CVE-2026-88771CVE-2026-88772
r/blueteamsec
HIGHVulnerability

NVD HIGH: CVE-2026-88778 — Predictable exact value from previous values vulnerability in Citrix NetScaler A...

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

CVE-2026-88778
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-88777 — Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N...

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88777
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-88776 — Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N...

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88776
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-88775 — Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gatew...

Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

CVE-2026-88775
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-88774 — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue ...

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

CVE-2026-88774
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-88773 — Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')...

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

CVE-2026-88773
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-88772 — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue ...

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

CVE-2026-88772
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-88771 — Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc...

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771
NIST NVD
CRITICALZero Day

Citrix admins warned to shut down NetScalers over 2 exploited zero-days

Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]

BleepingComputer
CRITICALZero Day

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. [...]

CVE-2026-88771CVE-2026-88772
BleepingComputer
MEDIUMVulnerability

Wireshark 4.6.9 Released, (Sun, Sep 27th)

Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.&#xd;

SANS ISC
LOWVulnerability

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]

BleepingComputer
MEDIUMAi

Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors

Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]

BleepingComputer
MEDIUMAi

OpenAI’s Systems Meddled With U.S. Government Sites

Kate Conger, Ana Swanson, and Cecilia Kang report that OpenAI was behaving somewhat badly again- unless you just view it as a curious child exploring without evil intent? OpenAI’s artificial intelligence went rogue and meddled with the websites for the Education Department, the Commerce Department and the Securities and Exchange Commission this summer without the... Source

DataBreaches.net
HIGHData Breach

UK: Ten NHS staff removed over Noah Woods data breach

Tom McArthur and Louise Parry report: Ten NHS staff have been removed from duty or suspended after a data breach involving the digital medical records of three-year-old Noah Woods. Launching an &#8220;urgent&#8221; investigation, Dr Martin Mansfield, deputy chief medical officer at East Suffolk and North Essex NHS Foundation Trust, said that any unauthorised access of... Source

DataBreaches.net
HIGHData Breach

Personal information of over 23,500 Simba customers leaked in data breach

Rhea Yasmine reports: Personal information of more than 23,500 Simba customers has been compromised in a data breach, the telco said in a statement on Sept 25. The data involved included names, identity card numbers, dates of birth, mobile numbers, and e-mail addresses belonging to 23,549 people, who had registered for Simba&#8217;s services. No credit... Source

DataBreaches.net
CRITICALZero Day

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

<p>CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: <a href="https://www.cve.org/CVERecord?id=CVE-2026-88771">CVE-2026-88771</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-88772">CVE-2026-88772</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-88773">CVE-2026-88773</a>, <a href="https://www.cve.

CVE-2026-88771CVE-2026-88772
CISA Advisories
HIGHVulnerability

NVD HIGH: CVE-2026-93302 — MatchTrustedPeer ignores the public key used, leading to forged CA clones passin...

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The peer must know the certificates being loaded to either of those APIs to take advantage of the issue. When OPENSSL_COMPATIBLE_DEFAULTS is als

CVE-2026-93302
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-89134 — A certificate with no dNSName SAN but another SAN type present (e.g. registeredI...

A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL && !cert->isCA instead of "no dNSName SAN", so an out-of-scope CN was accepted. This incomplete fix from CVE-2026-6731, leading to the name-constraint check issue,

CVE-2026-89134
NIST NVD
MEDIUMVulnerability

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek .

CVE-2026-65660
SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-94418 — Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate sig...

Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse returned 0, so any parse error hid it. ParseCertRelative() reaches its validity-date, name-constraint and critical-extension checks only after ConfirmSignature() has

CVE-2026-94418
NIST NVD
CRITICALZero Day

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26. Citrix has not confirmed the flaws or published a fix. Some administrators say they have taken appliances offline rather than wait for one to be available. NetScaler ADC and

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-100846 — MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in...

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserializati

CVE-2026-100846
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100844 — MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner c...

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ';' on

CVE-2026-100844
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100842 — MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatia...

MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(

CVE-2026-100842
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100838 — Contrast is a confidential-computing runtime for Kubernetes. In versions before ...

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critic

CVE-2026-100838
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100723 — vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (b...

vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is

CVE-2026-100723
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100721 — vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module...

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-str

CVE-2026-100721
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-71426 — Contrast is a confidential-computing runtime for Kubernetes. In versions before ...

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator,

CVE-2025-71426
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-71425 — Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and...

Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initi

CVE-2025-71425
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100740 — A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the funct...

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.

CVE-2026-100740
NIST NVD
HIGHVulnerability

CISA KEV: Citrix NetScaler — Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

CVE-2026-88772Citrix NetScaler
CISA KEV
HIGHVulnerability

CISA KEV: Citrix NetScaler — Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771Citrix NetScaler
CISA KEV
CRITICALVulnerability

NVD CRITICAL: CVE-2026-82901 — The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitr...

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o

CVE-2026-82901
NIST NVD
LOWVulnerability

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

CVE-2026-35273
BleepingComputer
MEDIUMApt

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2026-85984 — The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPres...

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici

CVE-2026-85984
NIST NVD
MEDIUMVulnerability

China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents. The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]

BleepingComputer
MEDIUMVulnerability

Microsoft pauses KB5002907 update after Office license deactivations

Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]

BleepingComputer
MEDIUMVulnerability

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100717 — froxlor is a server administration panel. In versions 2.3.10 and earlier, Valida...

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan

CVE-2026-100717
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100716 — Froxlor is a server administration panel. In versions 2.3.10 and earlier, the cu...

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component

CVE-2026-100716
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100715 — Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink foll...

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because mak

CVE-2026-100715
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100714 — Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchalleng...

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only bla

CVE-2026-100714
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100706 — kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Po...

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc

CVE-2026-100706
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100697 — Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins...

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST contain

CVE-2026-100697
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100693 — Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation ...

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.

CVE-2026-100693
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100690 — Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css...

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox.

CVE-2026-100690
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100686 — Budibase versions before 3.45.0 fail to validate per-app authorization in the PO...

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.

CVE-2026-100686
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100685 — Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint ...

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to acces

CVE-2026-100685
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100682 — Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in ...

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.

CVE-2026-100682
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100670 — Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in ...

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() an

CVE-2026-100670
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100669 — Grav before 2.0.25 ships web server configuration samples whose access-control d...

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, system, vendor, ignore_folders) sets ignoreCase="false" on its URL Rewrite <match> element, overriding the IIS default of ignoreCase="true";

CVE-2026-100669
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100646 — SiYuan is a self-hosted personal knowledge management system. In versions up to ...

SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cr

CVE-2026-100646
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100645 — SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnera...

SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.

CVE-2026-100645
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100642 — SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery v...

SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative a

CVE-2026-100642
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100641 — SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before ...

SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as <img src=invalid onerror=...> becomes an executable event-handler attribute. Because the SiYua

CVE-2026-100641
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100638 — SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setN...

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessibl

CVE-2026-100638
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100637 — SiYuan versions before v3.8.4 contain a path traversal vulnerability in the chec...

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.

CVE-2026-100637
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100625 — Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_b...

Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and validates only that job's stored upload_path, but then forwards the user-controlled TUS resource suffix taken from /build/upload/:jobId/* to the builder service while injecting Capgo's privil

CVE-2026-100625
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100617 — Cap-go capgo.app fails to validate that principals in channel_permission_overrid...

Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization.

CVE-2026-100617
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100612 — Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control...

Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs a BEFORE UPDATE guard (enforce_sso_provider_client_update_guard()) that freezes only the dns_verified_at, domain, status and enforce_sso columns; provider_id (as well as metadata_url and attribute_map

CVE-2026-100612
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100608 — Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboa...

Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASHBOARD=true, and !isCloud()), the /admin/queues mount is protected only by the verifyTokenForBullMQDashboard middleware, which validates the JWT but performs no role, permission, or workspace/organizati

CVE-2026-100608
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100605 — Flowise through 3.1.4 contains missing route-level RBAC checks on chat message e...

Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts, model responses, and delete messages.

CVE-2026-100605
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100315 — A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5d...

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file mydetailsfaculty.php. The manipulation of the argument myfid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about a

CVE-2026-100315
NIST NVD
MEDIUMVulnerability

Poland reports a second medical data cyberattack in recent weeks

Polish healthcare entities have been the victims of cyberattacks recently. First, it was the MyDr system. Now it&#8217;s a software manufacturer that markets the Medyc software used by Polish healthcare providers. Stanisław Kaleta reports: Poland has been hit by another medical data cyberattack, weeks after an unprecedented breach exposed the personal information of almost 19... Source

DataBreaches.net
MEDIUMAi

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]

BleepingComputer
MEDIUMMalware

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek .

SecurityWeek
HIGHData Breach

Pentagon data breach of military personnel raises national security concerns

Sean Lyngaas and Davis Winkie report: A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts. “Unauthorized users” gained access to a vulnerable computer server belonging to the Defense Manpower Data Center (DMDC) beginning... Sou

DataBreaches.net
CRITICALZero Day

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

CVE-2026-35273
The Hacker News
MEDIUMVulnerability

Some Supabase customers are publicly exposing reams of people’s data to the web

Zack Whittaker reports today&#8217;s nominee for the &#8220;No need to hack when it&#8217;s leaking&#8221; honors: Thousands of databases hosted by development platform Supabase are exposing people’s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found. UpGuard told TechCrunch that it found around 16,000 databases on which some degree of... Source

DataBreaches.net
MEDIUMAi

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to

The Hacker News
MEDIUMAi

OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-98163 — In the Linux kernel, the following vulnerability has been resolved: cgroup: Avo...

In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()") extended the lifetime of tasks on the dying_tasks list. The iterators have provision to go through dying_tasks because of dying threadgroup leaders or explicit C

CVE-2026-98163
NIST NVD
CRITICALVulnerability

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint

CVE-2026-65660
The Hacker News
MEDIUMVulnerability

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief

The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18143 — The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitr...

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it p

CVE-2026-18143
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100597 — OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-che...

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path is changed concurrently. An attacker able to win the race can cause a sandboxed

CVE-2026-100597
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100596 — OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users exe...

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

CVE-2026-100596
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100589 — OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the ...

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated s

CVE-2026-100589
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100588 — OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administr...

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can insp

CVE-2026-100588
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100585 — OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-onl...

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner, causing the requested action to proceed without owner consent. The practica

CVE-2026-100585
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100580 — OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensit...

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw proce

CVE-2026-100580
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100568 — OpenClaw versions before 2026.8.1 fail to properly restrict access to operator c...

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.

CVE-2026-100568
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100561 — OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain a...

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it w

CVE-2026-100561
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100560 — OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability ...

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.

CVE-2026-100560
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100559 — OpenClaw versions before 2026.8.1 contain a command parser vulnerability where e...

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.

CVE-2026-100559
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100558 — OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in...

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener resources and cause denial of service without consuming the WebSocket pre-auth co

CVE-2026-100558
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100557 — OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability ...

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.

CVE-2026-100557
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100555 — OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and ...

OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostname to the Synology NAS, where it could resolve to a different destination. When attachment delivery accepted a remotely influenced hostname, an attac

CVE-2026-100555
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100552 — OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per...

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist,

CVE-2026-100552
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100551 — OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gatew...

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by

CVE-2026-100551
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100544 — openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured ...

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a dep

CVE-2026-100544
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100543 — OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hash...

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config

CVE-2026-100543
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100541 — OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2....

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a c

CVE-2026-100541
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100535 — OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose t...

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to

CVE-2026-100535
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100532 — @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through...

@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and ca

CVE-2026-100532
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100530 — OpenClaw versions before 2026.8.1 fail to bind working directory context to reus...

OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially different effects.

CVE-2026-100530
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100520 — Laranode versions before 1.2.1 contain a path traversal vulnerability in the POS...

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.

CVE-2026-100520
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100504 — Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnera...

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution.

CVE-2026-100504
NIST NVD
CRITICALVulnerability

3 Consulting Myths Debunked by Unit 42 Experts

Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by Unit 42 Experts appeared first on Unit 42 .

Unit 42 (Palo Alto)
HIGHVulnerability

NVD HIGH: CVE-2026-100419 — gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in...

gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the

CVE-2026-100419
NIST NVD
HIGHRansomware

U.S. Soldier Gets 70 Months in Prison for AT&#038;T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&#038;T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

CVE-2023-45208
Krebs on Security
CRITICALZero Day

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]

BleepingComputer
MEDIUMVulnerability

Army soldier sentenced for spree of attacks on AT&#038;T, Snowflake and other major companies

Cameron Wagenius was involved in some of the most high-profile attacks of 2024 while on active duty. The post Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies appeared first on CyberScoop .

CyberScoop
HIGHVulnerability

NVD HIGH: CVE-2026-10758 — Esri LERC is an open-source image or raster format which supports rapid encoding...

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an application that uses LERC to crash the application, leading to a denial of service.

CVE-2026-10758
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100391 — MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerabili...

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.

CVE-2026-100391
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100390 — Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the...

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.

CVE-2026-100390
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100389 — GestSup versions before 3.2.61 contain a remote code execution vulnerability in ...

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.

CVE-2026-100389
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100387 — pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in d...

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.

CVE-2026-100387
NIST NVD
MEDIUMApt

Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this : Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life

Schneier on Security
HIGHRansomware

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]

BleepingComputer
MEDIUMVulnerability

How the CISO CFO Relationship is a Key to Cybersecurity Success

Building a financial bridge: Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk and enable business growth are better prepared to face today's threat landscape.

Dark Reading
MEDIUMVulnerability

Why the CISO-CFO Relationship Is a Key to Cybersecurity Success

Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk, and enable business growth are better prepared to face today's threat landscape.

Dark Reading
MEDIUMVulnerability

Kiteworks urges customers to stop using platform after warning from federal intelligence agencies

Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”

The Record
HIGHVulnerability

NVD HIGH: CVE-2026-100372 — ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the a...

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web

CVE-2026-100372
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100310 — GNU libextractor before 1.16 loads plugins from an untrusted search path specifi...

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.

CVE-2026-100310
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-100208 — Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorize...

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

CVE-2026-100208
NIST NVD
MEDIUMVulnerability

Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings

Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.

The Record
CRITICALVulnerability

NVD CRITICAL: CVE-2026-97064 — X-SpringBoot through 6.0 ships with a hardcoded static master login verification...

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.

CVE-2026-97064
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-97063 — X-SpringBoot through 6.0 returns login verification codes in HTTP responses from...

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.

CVE-2026-97063
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-97060 — X-SpringBoot through 6.0 lacks object-level authorization in user management end...

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users via POST /sys/user/update and POST /sys/user/delete endpoints.

CVE-2026-97060
NIST NVD
MEDIUMAi

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.

Dark Reading
MEDIUMVulnerability

Bitget hit by $387.5 billion hack

Bitget has halted customer withdrawals after hackers that the crypto exchange suspects are linked to North Korea stole more than $380 million.

Finextra
MEDIUMVulnerability

Bitget hit by $387.5 million hack

Bitget has halted customer withdrawals after hackers that the crypto exchange suspects are linked to North Korea stole more than $380 million.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-97885 — A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098...

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument fid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a

CVE-2026-97885
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-97883 — A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Pr...

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the argument gid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is use

CVE-2026-97883
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-97882 — A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to ...

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component Faculty Authentication. Executing a manipulation of the argument fid/pass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available t

CVE-2026-97882
NIST NVD
LOWVulnerability

Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]

BleepingComputer
MEDIUMAi

What We Missed: Google Gemini Joins the AI Escape Party

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.

Dark Reading
MEDIUMVulnerability

Supreme Court permits states to use SAVE database for citizenship checks

Three justices wrote in a dissent that longstanding privacy laws protecting sensitive personal data held by the government should prevent the use of the database. The post Supreme Court permits states to use SAVE database for citizenship checks appeared first on CyberScoop .

CyberScoop
MEDIUMApt

AI tools help hacker break in for $25 per target

It’s cheap to set yourself up as a hacker these days using AI. Someone attacked 105 online retailers over a period of five days, compromising 27 of them — all for an average of $25 per attack, according to research by Israeli security company Gambit . But the attacks have been going on for much longer. Whoever is responsible used open-source AI harnesses to mount the attack. Gambit has identified

CSO Online
CRITICALVulnerability

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]

CVE-2026-5430
BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-97878 — A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted ...

A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-97878
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-97877 — A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issu...

A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The

CVE-2026-97877
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-97871 — A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue a...

A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclos

CVE-2026-97871
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-89032 — BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerabi...

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes su

CVE-2026-89032
NIST NVD
LOWMalware

Documentation placeholder domain used in ClickFix attacks

The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according to Manifold Security, which discovered the problem.

CSO Online
HIGHData Breach

Labcorp Settles Multistate Data Breach Investigation for $2.3 Million

A coalition of 44 state attorneys general has agreed to settle a multistate investigation of Laboratory Corporation of America (Labcorp) [&#8230;] The post Labcorp Settles Multistate Data Breach Investigation for $2.3 Million appeared first on The HIPAA Journal .

HIPAA Journal
LOWAi

Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]

BleepingComputer
MEDIUMAi

NatWest unveils AI-powered audio-visual spending insights tool

NatWest is set to trial a fully generative audio-visual AI spending insights tool that lets customers explore their finances through natural voice and text conversations.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-93306 — IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW...

IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web int

CVE-2026-93306
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-84882 — IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Univers...

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.

CVE-2026-84882
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-84862 — IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in t...

IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.

CVE-2026-84862
NIST NVD
MEDIUMVulnerability

Crypto CEO accuses North Korea of stealing $387 million from Bitget platform

The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.

The Record
MEDIUMData Breach

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek .

SecurityWeek
LOWVulnerability

GitLab issue email’s only security is obscurity

It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor security defaults and a long-lived token embedded in the address mean that anyone who knows the address can potentially modify protected repositories. If project owners publish or leak these addresses, as some have, then they become vulnerable. The

CSO Online
MEDIUMVulnerability

Socure brings identity verification and fraud prevention to Circle Arc mainnnet

Socure, the leading AI-native trust infrastructure for global identity and risk intelligence, today announced that RiskOS is being used for identity verification and fraud prevention on Arc, the open Layer 1 blockchain built by Circle and now live on public mainnet.

Finextra
LOWVulnerability

NFU Mutual selects Bloomberg and Clearwater Analytics for investment management workflow

Bloomberg and Clearwater Analytics ('Clearwater') today announced that NFU Mutual ('NFUM'), the UK's leading rural insurer, has selected Bloomberg Buy-side Solutions together with the Clearwater platform to modernize its investment operating model.

Finextra
CRITICALVulnerability

Cyberattack hits Welsh police force, may have affected staff data

Dyfed-Powys Police in Wales said a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information.

The Record
MEDIUMAi

OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]

BleepingComputer
MEDIUMVulnerability

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

[object Object]

CVE-2025-13032
r/netsec
MEDIUMAi

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. [...]

BleepingComputer
MEDIUMVulnerability

Stopping IT Worker Scams Requires Revamped HR Process

Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.

Dark Reading
LOWMalware

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to this

The Hacker News
MEDIUMVulnerability

US prosecutors seize Tether-linked payment firm&#39;s bank accounts - FT

US federal prosecutors have seized bank accounts belonging Capstone, a payments business working on behalf of stablecoin issuer Tether and its sister exchange Bitfinex, according to the Financial Times.

Finextra