Vulnerabilities & PatchesEmerging2 srcs
CVE-2026-70125 - Microsoft Outlook Remote Code Execution Vulnerability
Information published. This CVE was addressed by updates that were released in September 2026, but the CVE was inadvertently omitted from the September 2026 Security Updates. This is an informational change only. Customers who have already installed the September 2026 updates do not need to take any further action.
Vulnerabilities & PatchesEmerging1 src
CVE-2026-96676 - Fast FAC1900R uhttpd get_alias_name stack-based overflow
CVE ID : CVE-2026-96676
Published : Sept. 23, 2026, 10:30 p. m.
• 29 minutes ago
Description : A vulnerability was identified in Fast FAC1900R 20190827_2. 0. 2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0
• NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-96603 - Abdurrab5 online-makeup-store Admin functions.php confirm_user authorization
CVE ID : CVE-2026-96603
Published : Sept. 23, 2026, 10:17 p. m.
• 42 minutes ago
Description : A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions. php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure.
Severity: 7.5
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-96604 - SoftNews Media Group DataLife Engine Search search.php strip_data sql injection
CVE ID : CVE-2026-96604
Published : Sept. 23, 2026, 10:17 p. m.
• 42 minutes ago
Description : A vulnerability was identified in SoftNews Media Group DataLife Engine 18. 0. This affects the function strip_data of the file engine/modules/search. php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-96601 - Abdurrab5 online-makeup-store Admin Login index.php sql injection
CVE ID : CVE-2026-96601
Published : Sept. 23, 2026, 10:16 p. m.
• 42 minutes ago
Description : A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index. php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure.
Severity: 7.5
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-93352 - Laravel-Mediable 7.0.0 7.0.2 RCE via .pht File Upload
CVE ID : CVE-2026-93352
Published : Sept. 23, 2026, 10:16 p. m.
• 42 minutes ago
Description : Laravel-Mediable 7. 0. 0 before 7. 0. 2 contains an incomplete patch for CVE-2026-49972 in which the . pht extension is absent from the forbidden_extensions blocklist in config/mediable. php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .
pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.
Vulnerabilities & PatchesEmerging1 src
CVE-2026-86583 - Import and export users and customers = 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile
CVE ID : CVE-2026-86583
Published : Sept. 23, 2026, 10:16 p. m.
• 42 minutes ago
Description : The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2. 4. 17 via the plugin's own export and re-import workflow.
Vulnerabilities & PatchesEmerging1 src
CVE-2026-96602 - Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection
CVE ID : CVE-2026-96602
Published : Sept. 23, 2026, 10:16 p. m.
• 42 minutes ago
Description : A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin. php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure.
Severity: 7.5
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
F5 fixes actively exploited zero-day flaw in BIG-IP APM
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available.
BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources. APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users.
The flaw, tracked as CVE-2026-94127, is described as a heap-based buffer overflow and is rated 9. 8 on the CVSS scale. The vulnerability impacts the BIG-IP system when configured in appliance mode as well but can be exploited only when both APM and an OAuth authorization server profile are configured.
Vulnerabilities & PatchesEmerging1 src
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog.
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog :
• CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
• CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
• CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
• CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks and run their own code on the gateway.
Breaches & RansomwareEmerging1 src
The hunters go after the bureau.
ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrupts the EvilTokens cybercrime platform. Researchers turn Claude Code’s normal workflow against itself.
Pundits propose an AI Assurance Compact. A Ryuk ransomware gang member gets two years prison time. Our guest is Jen Sovada, General Manager of Public Sector at Claroty, on Project Watershed 250 and the challenges facing U. S. water utilities. Meta’s Muse mettles with messages.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
Vulnerabilities & PatchesEmerging1 src
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [... ]
Vulnerabilities & PatchesEmerging1 src
Security Slam 2026 – Fall Edition
Security Slam 2026 – Fall Edition is a 30-day virtual event from October 5 through November 6, 2026.
By Eddie Knight and Stacey Potter
What Is the Security Slam?
The Open Source Security Foundation (OpenSSF) is partnering with the Cloud Native Computing Foundation (CNCF) Security Technical Advisory Group (TAG Security) to support the 2026 Security Slam at KubeCon + CloudNativeCon North America.
The 30-day challenge runs from October 5 through November 6 and highlights OpenSSF projects as practical tools that help improve project security posture. Participants will use OpenSSF projects, among others, to achieve security hygiene milestones tailored to their project’s maturity level.
Policy & RegulationEmerging1 src
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found.
The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs.
The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses.
Vulnerabilities & PatchesEmerging1 src
Forcepoint security advisory (AV26-960)
Serial Number: AV26-960
Date: September 23, 2026
As of September 23, 2026, Forcepoint is affected by a vulnerability in the following product:
• Forcepoint Security Engine (NGFW)
• Versions 7.1.0 to 7.1.13
• Versions 7.3.0 to 7.3.1
• Version 7.33
• Version 7.4.0 to 7.4.1
• Version 7.5.0
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
• Forcepoint Hub
• Forcepoint Help and Resource Center
Forcepoint security advisory (AV26-960) - Canadian Centre for Cyber Security
Vulnerabilities & PatchesEmerging1 src
Dell security advisory (AV26-959)
Serial number: AV26-959 Date: September 23, 2026
As of September 21, 2026, Dell is affected by vulnerabilities in the following products:
• Dell Command Powershell Provider (DCPP)
• Prior to 2.10.2
• Dell Command Monitor (DCM)
• Prior to 10.13.2
• Dell Inventory Collector Client
• Prior to 15.0.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Vulnerabilities & PatchesEmerging2 srcs
CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printer
With Pwn2Own Ireland 2026 coming up, I wanted to share an unreleased blog post from my time as a Pwn2Own contestant. This post covers the discovery and exploitation of CVE-2024-0244, which is an unauthenticated heap-based buffer overflow leading to an arbitrary free() in the Canon MF753Cdw printer featured in Pwn2Own Toronto 2023.
This blog post gives an overview of the vulnerability and the exploitation techniques used.
Figure 1 - MF753Cdw printer
Figure 1 - MF753Cdw printer
Previously, I had exploited the very similarly named MF743Cdw at Pwn2Own Toronto 2022 using a classic stack buffer overflow, so I had a solid baseline understanding of this family of printers and their quirks. Starting Point Over the years at Pwn2Own, the Canon family of printers has been exploited many times, which means that many researchers have combed through the firmware.
Vulnerabilities & PatchesEmerging1 src
MikroTik security advisory (AV26-958)
Serial number: AV26-958 Date: September 23, 2026
As of September 22, 2026, MikroTik is affected by a vulnerability in the following product:
• RouterOS
• Prior to 7.25beta5
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
• 7.25beta [development] is released!
MikroTik security advisory (AV26-958) - Canadian Centre for Cyber Security
Vulnerabilities & PatchesEmerging1 src
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [... ]
Vulnerabilities & PatchesEmerging1 src
VU#273940: Enterprise Access Management EAM does not rotate RSA keys
Overview
Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26. 2. 6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X. 509 certificate.
Description
CVE-2026-82356
Imprivata EAM uses an RSA key pair to generate the X. 509 certificate that identifies the appliance to the clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment.
Vulnerabilities & PatchesEmerging1 src
NVIDIA security advisory (AV26-957)
Serial number: AV26-957 Date: September 23, 2026
As of September 22, 2026, NVIDIA is affected by vulnerabilities in the following products:
• Infrastructure Controller
• Versions 0 to 1.9
• NeMo Speech
• Versions 0.0 to 2.9
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
• Security Bulletin: NVIDIA Infrastructure Controller - September 2026
• Security Bulletin: NVIDIA NeMo Speech - September 2026
• NVIDIA Product Security
NVIDIA security advisory (AV26-957) - Canadian Centre for Cyber Security
Vulnerabilities & PatchesEmerging2 srcs
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it.
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
The flaw can allow an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. F5 disclosed the issue on September 22 and confirmed that exploitation had already been observed.
The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. More specifically, the vulnerable configuration is one in which APM operates as an OAuth Authorization Server. Systems using APM only as an OAuth Client or Resource Server are not affected.
Vulnerabilities & PatchesEmerging1 src
Ubiquiti security advisory (AV26-954)
Serial number: AV26-954 Date: September 23, 2026
As of September 22, 2026, Ubiquiti Inc is affected by vulnerabilities in the following products:
• Cloud Gateways
• Prior to 5.1.31
• Dream Machines
• Prior to 5.1.31
• Dream Routers
• Prior to 5.1.31
• Dream Wall
• Prior to 5.1.31
• Enterprise Firewalls
• Prior to 5.1.31
• Express
• Prior to 4.0.21
• Express 7
• Prior to 5.1.31
• UniFi Gateways
• Prior to 5.1.26
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
• Security Advisory Bulletin 069
Ubiquiti security advisory (AV26-954) - Canadian Centre for Cyber Security
Policy & RegulationEmerging1 src
VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
Overview
Cinnamon's Kotaemon (all versions up to v0. 12. 0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations.
Description
Cinnamon's Kotaemon is an open‑source, retrieval‑augmented generation (RAG) based tool that lets you build a chatbot capable of "chatting with your documents". As discussed in CVE-2026-86867 , all versions up to v0. 12. 0 fail to verify conversation ownership when loading a conversation. In multi‑user mode, each conversation row includes a user field that identifies its owner.
Vulnerabilities & PatchesEmerging1 src
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
Threat Actors & CampaignsEmerging1 src
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks.
The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s Daybreak program. OpenAI said it is also pledging over $1 billion in subsidized tokens to support the initiative.
During a panel discussion Dmytro Kushneruk, consul general of Ukraine in San Francisco, outlined how the tools would be used for cybersecurity automation, including functions such as incident response, threat triaging, login analysis, inventorying systems, code analysis and validating vulnerabilities.
How to fix your Windows File History if the September update broke it
A bug in the Windows Sept patch Tuesday update may stop File History from working. But a new optional update fixes it.
Cybersecurity Tokenomics: Denial of Wallet Attacks | Kaspersky official blog
Not long ago, many companies began actively implementing AI agents in a wide variety of workflows. Very quickly, the cost of using them became a pressing issue for companies. Moreover, it’s an issue that concerns more than just finance department — in addition to budgetary concerns, issues of reliability, operational stability, and even information security have emerged.
This is because the cost of automating one and the same process varies significantly from one deployment to the next, is unpredictable, and could be subject to external influences.
Furthermore, for a malicious actor attacking an organization, any process automated using AI and vulnerable to external influence is, in essence, a convenient target for a “new type of DDoS attack”.
Vulnerabilities & PatchesEmerging1 src
InfraTrust report warns network management systems under attack
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [... ]
Vulnerabilities & PatchesEmerging1 src
Critical security vulnerabilities in the Radicle network protocol
The Radicle peer-to-peer code-collaboration project has disclosed two critical vulnerabilities in the network protocol used by Radicle nodes. The first flaw is that the network protocol used by Radicle " does not give the confidentiality it was expected to give ", which allows anyone who can observe the network between two nodes to read the data exchanged.
The second is that peer authentication is broken and allows impersonation, so an attacker can spoof their Node ID and read private repositories they should not be able to read.
In practice, the two flaws are most useful when they can be exploited together: an attacker on the path sees the Node IDs at both ends of a connection, and both are normally on the allow-list. That attacker can read whatever is exchanged while they watch, and can then use a Node ID they saw to fetch the whole repository on demand.
Vulnerabilities & PatchesEmerging1 src
How One Kubernetes YAML Can Hand Over a GCP Organization
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [... ]
Vulnerabilities & PatchesEmerging1 src
80,000 relay servers help users in China slip past U.S. AI region bans
More than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U. S. AI models, according to Team Cymru. “What we have uncovered is an entire ecosystem designed explicitly to break the frontier model providers’ T&Cs, enabling fraud and illicit activity,” said Scott Fisher, Senior Principal Engineer at Team Cymru.
Earlier this month, CISA, the NSA and the FBI warned in a joint advisory that China-based AI firms are running large-scale knowledge … More →
The post 80,000 relay servers help users in China slip past U. S. AI region bans appeared first on Help Net Security .
Vulnerabilities & PatchesEmerging1 src
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet.
The popular cybercrime group ShinyHunters is claiming that it breached the U. S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead carried out in response to an FBI warning published earlier this year.
The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel. The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
Vulnerabilities & PatchesEmerging1 src
Critical WordPress RCE vulnerability announced
A critical vulnerability has been discovered in WordPress 's get_page_template() function for page-template resolution that could allow remote-code execution (RCE) by an unauthenticated attacker, in some limited circumstances. The project has provided an update for the most recent branch of WordPress, as well as backports of the fix for branches back to 4. 7 .
See the vulnerability report for the conditions required for an RCE attack to be successful.
The vulnerability also affects the ClassicPress fork of WordPress, though a security update has not been provided for that project yet. LWN covered ClassicPress in
• Users of either content-management system should update soon.
Vulnerabilities & PatchesEmerging1 src
How dynamic application security testing validates risk at runtime
Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them.
The IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment (Doc #US54119126, September 2026). The IDC MarketScape evaluated 16 vendors and named Rapid7 a Leader. We believe the result reflects the strength of Rapid7’s DAST capabilities, but the IDC MarketScape also offers a useful view of where the category is heading.
DAST has developed beyond traditional web scanning into a source of runtime evidence that can help organizations validate risk across the application layer.
DarkMe RAT trades zero-days for plain phishing emails
DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again.
This time around, its distribution has been simplified: instead of leveraging zero-day exploits, attackers are betting on a simple email to convince targets to run it on their machine: The malicious email pointing to the first stage downloader for DarkMe (Source: Huntress) The link supposedly points to … More →
The post DarkMe RAT trades zero-days for plain phishing emails appeared first on Help Net Security .
Vulnerabilities & PatchesEmerging1 src
Security updates for Wednesday
Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10. 0, dotnet8. 0, dotnet9.
0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5.
15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7. 0, linux-azure-fde-6.
Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.
Vulnerabilities & PatchesEmerging1 src
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [... ]
Threat Actors & CampaignsEmerging1 src
Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
Introduction
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators.
ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers.
Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control.