Search
Find merged stories by title or summary.
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks and run their own code on the gateway.
🏴☠️ Rhysida has just published a new victim : Legis
Legis Legis is a well-known Latin American publisher that creates specialized legal and business information resources. Founded over 60 years ago, the company serves professionals across six countries including Colombia, Venezuela, Argentina, Mexico, Peru, and Chile. DATABASES (SQL)PST/OSTLEGAL DOCUMENTS:Tutela - constitutional actions with claimants' personal dataID card copies (cedulas) of shareholders and third partiesEnvironmental sanction proceedings against the company (AUTO 10852)Sanction dispute with the pension authority (UGPP)Signed cease & desist - trademark dispute (Xpandia case)Personal data transfer agreements (Colsubsidio, Universidad Externado)Litigation log of all company lawsuitsContract matrix, payment agreements, reorganization documentsFINANCE & OWNERSHIP:Shareholder and ultimate-beneficial-owner register with ID copiesOwnership structure: ~99.
Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and social engineering, passwords alone are no longer enough. MFA is one of the most effective security controls available. It’s a cornerstone of ASD’s Essential Eight maturity model and a recognized component of major cybersecurity frameworks worldwide.
Critical security vulnerabilities in the Radicle network protocol
The Radicle peer-to-peer code-collaboration project has disclosed two critical vulnerabilities in the network protocol used by Radicle nodes. The first flaw is that the network protocol used by Radicle " does not give the confidentiality it was expected to give ", which allows anyone who can observe the network between two nodes to read the data exchanged. The second is that peer authentication is broken and allows impersonation, so an attacker can spoof their Node ID and read private repositories they should not be able to read. In practice, the two flaws are most useful when they can be exploited together: an attacker on the path sees the Node IDs at both ends of a connection, and both are normally on the allow-list. That attacker can read whatever is exchanged while they watch, and can then use a Node ID they saw to fetch the whole repository on demand.
Security updates for Wednesday
Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10. 0, dotnet8. 0, dotnet9. 0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5. 15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7. 0, linux-azure-fde-6.
Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek .
NVIDIA Infrastructure Controller Hit by 14 Security Flaws Enabling Privilege Escalation and Code Execution
NVIDIA has released version 2.0 of its Infrastructure Controller to remediate 14 security vulnerabilities in the Linux-based infrastructure-management software, including a critical hard-coded credentials flaw that could enable remote compromise. The vulnerabilities affect versions 0 through 1.9, and NVIDIA is urging users to upgrade or clone the latest release from the project’s GitHub repository. NVIDIA’s security bulletin, issued on September 22, 2026, rates the flaws from medium to critical severity under CVSS v3.1. NVIDIA Infrastructure Controller Hit by 14 Security Flaws Collectively, the weaknesses could expose affected deployments to code execution, privilege escalation, data tampering, denial-of-service conditions , and information disclosure. The highest-rated issue, CVE-2026-65113, carries a CVSS score of 9. 8.
SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code
SolarWinds released Observability Self-Hosted 2026. 2. 3 to address two critical remote code execution vulnerabilities that could let unauthenticated attackers compromise affected deployments. The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, carry CVSS severity scores of 9. 8 and 8. 8, respectively, and security researcher Kai Huang of Armadin reported them. SolarWinds said both vulnerabilities affect deployments operating under specific non-default communication or configuration conditions, making configuration reviews as important as applying the available update. SolarWinds Observability Flaws CVE-2026-28324 is a critical remote code execution vulnerability with a CVSS score of 9. 8. According to SolarWinds, the issue stems from insufficient integrity checks in SolarWinds Observability Self-Hosted.
NVIDIA Fixes Linux Component Flaws That Could Expose Sensitive System Information
NVIDIA released a security update for its Infrastructure Controller software for Linux, addressing 14 vulnerabilities that could let attackers access sensitive system information, execute code, alter data, or disrupt affected environments. The update, published in NVIDIA’s September 2026 Infrastructure Controller security bulletin, affects versions 0 through 1. 9. NVIDIA recommends that organizations clone or update the software to version 2. 0 or later to address all reported issues. Among the patched flaws is CVE-2026-65127, a medium-severity vulnerability caused by uncleared debug information. The issue carries a CVSS score of 4. 1 and is tracked as CWE-1258. An attacker with local access, high privileges, and favorable conditions could potentially retrieve sensitive system information left exposed through debugging artifacts.
Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign
A threat group best known for exploiting previously unknown flaws in WinRAR and Windows has switched to a much simpler method: an email link to what appears to be an image. New research from Huntress details a 2026 campaign delivering DarkMe, a remote access trojan (RAT) historically linked to Water Hydra and also tracked as DarkCasino. The group made headlines in 2023 and 2024 for weaponising two zero-days, CVE-2023-38831 in WinRAR and CVE-2024-21412 in Windows Defender SmartScreen, in attacks on foreign exchange traders. This time, no exploit is involved. According to Huntress, victims receive a phishing email containing a link that looks like it serves a picture but instead downloads a file called image. pif, a Windows program in disguise. The file carries forged details suggesting it belongs to a security product named “Aegis Sentinel”.
InfoSec News Nuggets – 09/23/2026
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach The ShinyHunters extortion gang says it broke into FBI systems through a new, unpatched Oracle PeopleSoft zero-day. It claims it then moved into FBI-managed AWS GovCloud infrastructure and took 2 to 3TB of data on current and former employees and job applicants. The group defaced the FBI Jobs site with its logo, and the FBI has confirmed it is investigating “claims regarding unauthorized activity affecting FBIjobs. gov.” It has not confirmed a breach. ShinyHunters calls the attack retaliation for a May 2026 FBI FLASH report about the group and has given the bureau a week to correct or remove it. It also says it is now using the same PeopleSoft flaw against Fortune 500 companies. None of these claims has been independently verified, so organizations running PeopleSoft should watch closely for an Oracle advisory.
Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek .
Google Chrome 154 Patches 108 Security Flaws Including 11 Critical Vulnerabilities
Google has rolled out Chrome 154 to the Stable channel for Windows, Mac, and Linux, delivering fixes for 108 security vulnerabilities. The update, version 154. 0. 8037. 57 for Linux and 154. 0. 8037. 57/. 58 for Windows and Mac, addresses one of the largest security patch batches Chrome has shipped in recent memory, including 11 flaws rated Critical severity The most severe issues affect Chrome’s graphics and rendering stack. Multiple critical bugs were found in ANGLE, Chrome’s cross-platform graphics abstraction layer, including buffer overflows. Google Chrome 154 Patches 108 Security Flaws Additional critical flaws hit the GPU process, WebGL, ServiceWorker, Fullscreen, WindowDialog, and AdFilter components, with largely use-after-free and out-of-bounds write issues that could allow an attacker to achieve remote code execution or sandbox escape via a malicious web page.
Critical SolarWinds Flaws Let Attackers Remotely Execute Code on Observability Servers
SolarWinds released Observability Self-Hosted 2026. 2. 3 to fix two serious vulnerabilities that could let unauthenticated attackers remotely execute code on affected observability servers . The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, affect specific non-default configurations and communication modes. The update was released on September 22, 2026, and is especially important for organizations running SolarWinds Observability Self-Hosted in environments with Web Performance Monitor, or WPM, players. Successful exploitation could let a remote attacker run arbitrary commands on a vulnerable server without logging in first. CVE-2026-28324 is rated 9. 8 out of 10 on the CVSS severity scale, making it a critical issue.
8 Just-in-Time (JIT) Access Tools: Our Top Picks by Use Case (2026)
Quick Answer: Zero standing privileges is the destination; the lane depends on what you’re granting. PAM estates adding JIT: CyberArk and Delinea (and BeyondTrust) extend the platforms you already run. Cloud-native JIT for AWS/GCP/Azure roles: Apono and P0 Security lead the born-JIT startups. Infrastructure access (servers, K8s, databases): StrongDM’s zero-standing-access platform. SaaS app access and approvals in Slack: Lumos. Developer-workflow approvals: Indent status diligence advised. Every lane shares the thesis: access that expires can’t be stolen later. Who This Guide Is For Security teams dismantling standing admin rights, cloud platform owners drowning in over-privileged IAM roles, and IT leads whose access-request queue lives in tickets nobody loves.
Apple Maps blurring alleged detention centers in China, claims local laws require it
The data provider for Apple Maps in China has reportedly begun blurring more than just military facilities, leaving Apple in the wake of another potential mapping-related scandal. Apple Maps may have another controversy on its hands After decades of building up supply chains and manufacturing in China, Apple is not new to dealing with the controversial authoritarian regime running the country. The latest problem to emerge echoes other recent troubles Apple has faced in the United States. According to the BBC , Apple Maps has begun blurring locations throughout China. However, while the primary function of the blurred locations appears to be military-related, some are tied to detention facilities linked to alleged human rights abuses . Continue Reading on AppleInsider • Discuss on our Forums
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [... ]
Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.
Some cheap smart glasses are a security disaster
Apart from the privacy concerns around smart glasses , researchers have found that some cheap brands come with barely any security at all. ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs, costing A$60 and A$110 (around US$42 and US$78), and found more than a dozen flaws across the smart glasses themselves, their app, and an associated website. The main problem they uncovered was insecure Bluetooth pairing: If the glasses were powered on and not connected to their owner’s phone, an attacker could connect first, with no password or meaningful pairing confirmation. After connecting, an attacker could reportedly control the glasses to capture photos or recordings, copy existing media, and intercept data moving between the glasses and the phone.
ZTE SmartLife flaws allow account takeover without reset code
Security researcher Mina Nageh Salama disclosed a chain of vulnerabilities in ZTE’s SmartLife platform that lets attackers take over user accounts by resetting passwords without a verification code. ZTE confirmed four flaws, issued CVE identifiers, and said it fully patched the vulnerabilities on September 3, 2026. However, users must apply security updates to protect their … The post ZTE SmartLife flaws allow account takeover without reset code appeared first on CyberInsider .
InfoSec News Nuggets – 09/22/2026
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE SolarWinds has shipped security updates for Access Rights Manager after discovering a hard-coded static cryptographic key that could let an attacker execute code on a managed host without authentication. Tracked as CVE-2026-28326 with a CVSS score of 8. 8, the flaw affects all ARM versions 2026. 2 and earlier and was privately reported by a security researcher rather than found through active exploitation. Administrators are urged to upgrade to ARM 2026. 2. 1, which also resolves a batch of other recently disclosed flaws in the company’s Web Help Desk and Serv-U products.
Researchers used Claude to hack OpenAI
We’ve heard of OpenAI’s AI agents running amok and hacking other companies . Now, a cybersecurity company has turned the tables on the ChatGPT operator by using AI to help hack OpenAI itself. The hack, which also exposed a bug affecting dozens of other major online services, was conducted as security research. OpenAI paid the researchers for reporting a flaw in its systems through its bug bounty program. Researchers at cybersecurity tools vendor Hacktron wrote up their adventures in mid-September. A few months earlier, they had begun looking for security flaws at companies developing frontier AI models, which are highly capable models such as those powering ChatGPT and Claude. Using Anthropic’s Claude, the researchers went from investigating an image-processing flaw to accessing an internal OpenAI software repository in less than 72 hours.
Cheap smart glasses flaws let strangers take control - Cybernews
Cheap smart glasses flaws let strangers take control Cybernews
CISA alerts of active exploitation of three Linux kernel flaws
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [... ]
The AI plot to scan and destroy books (Lock and Code S07E19)
This week on the Lock and Code podcast… If you want AI to tell you a story, it will. If you want that story to sound like one of your favorite authors, it can. And if you’re one of the authors that AI can imitate, you might be a little upset at what feels like theft. In 2024, the authors Andrea Bartz, Charles Graeber, and Kirk Wallace Johnson sued Anthropic, the creator of Claude, alleging that the company had wrongfully digested millions of copyrighted works—including some of their very own—to train its AI models. The lawsuit grew to include more than 300,000 writers, and in September 2025, Anthropic agreed to pay $1. 5 billion to settle the claims . That headline-worthy payout, however, would eventually be paired with more startling news. In January 2026, a district court judge unsealed thousands of documents related to the litigation.
After spending billions, OpenAI still has gaps in its cybersecurity
Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable. In one incident, researchers breached OpenAI systems with the help of a rival AI developer’s tools, while another group of researchers tricked OpenAI’s Codex agent into bypassing its sandbox controls. Researchers from Hacktron chained multiple vulnerabilities to achieve remote code execution and gain access to OpenAI employee accounts and internal systems, according to a blog post detailing their findings. “On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts,” Hacktron researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini wrote .
AWS Automatically Quarantines Exposed IAM Keys Within 10 Seconds of GitHub Leak
Amazon Web Services can move from detection to containment in seconds when an Identity and Access Management access key appears in a public GitHub repository. In a controlled Unit 42 exposure test, AWS attached its AWSCompromisedKeyQuarantineV3 managed policy to the affected IAM user only 10 seconds after researchers published the credential, sharply reducing the window available for abuse. Long-term IAM access keys remain attractive initial-access vectors because they can provide programmatic access without interactive authentication. Developers may accidentally commit them to source code, configuration files, or publicly accessible environment files. GitHub secret scanning searches public repositories and other public surfaces for recognized credential patterns; through its partner integration, it reports detected AWS secrets directly to AWS so the provider can respond.
Transforming Bedrock Guardrails events into OCSF with CloudWatch
Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a guardrail identifies or blocks a prompt injection attempt or redacts sensitive data, that intervention carries additional investigative value comparable to a failed sign-in or a network intrusion alert. AWS Bedrock publishes this telemetry to AWS CloudWatch metrics and model invocation logs for operational monitoring. In this post, I show you how to transform AWS Bedrock Guardrails intervention events into structured Open Cybersecurity Schema Framework (OCSF) Detection Finding records and land them in the CloudWatch unified data store . Launched in December 2025 , the unified data store consolidates operational, security, and compliance data from AWS services and third-party sources into a single platform.
AWS agentic platform by default leaves credentials vulnerable to exfiltration - Cybernews
AWS agentic platform by default leaves credentials vulnerable to exfiltration Cybernews
From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Unit 42 .
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory. The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek .
Exim Mail Server Flaws Enable SMTP Smuggling, Heap Corruption and Data Leakage
Exim has released version 4. 100. 1 to address four security vulnerabilities affecting its mail transfer agent , including SMTP smuggling, heap corruption, stack-data leakage, and a use-after-free condition. The security release, announced on September 18, 2026, fixes issues tracked under four GCVE identifiers. Two high-severity vulnerabilities affect Exim’s handling of Proxy Protocol traffic, while a medium-severity SMTP smuggling flaw impacts all Exim versions through 4.100. Exim Mail Server Flaws The most serious issue, GCVE-25-2026-09-50-1, is an out-of-bounds write and heap-corruption vulnerability in Proxy Protocol v1 handling. It affects Exim releases from version 4. 83 through 4. 100 when the server is built and configured to use Proxy Protocol.
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added [ 1 , 2 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2025-39682 – Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability • CVE-2025-39964 Linux Kernel Race Condition Vulnerability • CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability Below are detailed descriptions of the flaws: • CVE-2025-39682 (CVSS score: 9.8) – A flaw in the TLS receive path that fails to properly handle unexpected conditions, potentially allowing authenticated local users to expose sensitive memory contents or cause a denial-of-service (DoS).
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path
Facial recognition arrest lawsuit seeks $10M from Fargo police - Cybernews
Facial recognition arrest lawsuit seeks $10M from Fargo police Cybernews
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws
🏴☠️ N0n has just published a new victim : BeLi Teacher / FSC education centers (AWS)
Education / edtech • Vietnam • The complete CRM lead database: 152,044 contact records — names, emails, +84 phone numbers, cities, study interests, engagement history; The CRM file archive (tasks, forums, comments, customer files) migrated from GetFly CRM • Publication proceeds in batches after the deadline. • [ACTIVE: deadline 2026-09-20 02:47 UTC]
Researchers used Anthropic’s Claude to hack into OpenAI
Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.
