Latest news
-
Vulnerabilities via NCSC-NL
NCSC-2026-0384 [1.00] [M/H] Kwetsbaarheid verholpen in Check Point's Security Management and Log Servers
Check Point heeft een kwetsbaarheid verholpen in Check Point's Security Management and Log Servers. De kwetsbaarheid betreft een stack overflow die optreedt tijdens het…
-
Vulnerabilities via Ubuntu Security
USN-8714-3: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following…
-
Ransomware via Infosecurity Magazine
Manufacturing Accounts for 22% of all Ransomware Victims
Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026
-
Vulnerabilities via Security Affairs
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point…
-
Threat Intel via Malwarebytes Labs
Fake parcel delivery messages steal your card and bank details
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a…
-
Vulnerabilities via BleepingComputer
Microsoft fixes broken copy and paste for Excel 2016 users
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update.
-
AI Security via SecurityWeek
MIND Secures $72 Million for AI-Powered DLP
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.
-
Vulnerabilities via SecurityWeek
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
-
Breaches via HIPAA Journal
Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic testing and clinical genomics company…
-
AI Security via Dark Reading
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.
-
Threat Intel via The Hacker News
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial…
-
Breaches via HIPAA Journal
McKesson Cyberattack: Stolen Data Includes 6.4 Million Unique Email Addresses
McKesson, a major U.S. wholesale medical supplies & equipment, pharmaceutical distribution, and healthcare technology solutions company, continues to investigate a…
-
Vulnerabilities via Help Net Security
Abandoned IoT apps keep sending sensitive data to broken servers
Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving…
-
AI Security via Help Net Security
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to…
-
Breaches via Help Net Security
98% of fraudulent hires have company credentials by the time they’re caught
A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this…
-
Vulnerabilities via Zero Day Initiative
ZDI-CAN-31049: RARLAB
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Landon Peng (Lunbun LLC)' was reported to the affected vendor on: 2026-09-18…
