Latest news

  1. Vulnerabilities via Canadian Centre for Cyber Security

    Arista Networks security advisory (AV26-940)

    Serial number: AV26-940 Date: September 18, 2026 As of September 9, 2026, Arista Networks is affected by vulnerabilities in the following product: EOS Multiple versions…

  2. Threat Intel via Cloudflare

    Saving another 100TB of RAM with math (and Rust)

    Cloudflare operates at a scale so big that even after working here for years, it doesn’t seem real. We have thousands of servers all over the world with petabytes of RAM…

  3. AI Security via CyberScoop

    Researchers use AI to find widespread software decoder flaw

    Researchers said they used Anthropic’s Claude and OpenAI’s Codex to identify a damaging flaw embedded in a popular software decoding tool that could leave major internet…

  4. AI Security via The Register

    Researchers used Claude to hack OpenAI employees' ChatGPT accounts

    Talk about your competitor getting through the door. Security researchers used Anthropic's Claude to help hack into OpenAI employees’ ChatGPT accounts. A trio of bug…

  5. Breaches via Security Affairs

    Gyazo Data Breach Exposes 23 Million User Records

    A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is…

  6. Threat Intel via SentinelLABS

    Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

    Executive Summary Following disclosure of the TraderTraitor attack against LayerZero in April 2026, SentinelOne identified an additional victim with the same macOS…

  7. Vulnerabilities via Chrome Releases

    Chrome Dev for Android Update

    Hi everyone! We've just released Chrome Dev 156 (156.0.8063.0) for Android. It's now available on Google Play.

  8. Vulnerabilities via The Hacker News

    New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

    WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in…

  9. Threat Intel via The Register

    North Korea's fake job interviews infected 30,000 devices

    North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters…

  10. Threat Intel via Flashpoint

    The Flashpoint Threat Intelligence Brief: Middle East

    Blogs Blog The Flashpoint Threat Intelligence Brief: Middle East Flashpoint’s weekly analysis tracks shifting kinetic and cyber threat radiuses, geopolitical…

  11. Breaches via HIPAA Journal

    HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud

    Each year, millions of taxpayers’ dollars are lost to Medicare and Medicaid fraud, with fraud related to durable medical equipment, prosthetics, orthotics, and supplies…

  12. Vulnerabilities via Chrome Releases

    Chrome Dev for Desktop Update

    The Dev channel has been updated to 156.0.8063.3 for Windows, Mac and Linux. A partial list of changes is available in the Git log. Interested in switching release…

  13. Ransomware via RansomLook

    forus.cl By lockbit5

    Founded in 1980 and headquartered in Santiago, Chile, Forus is a provider of apparel. The company pr...

  14. Ransomware via RansomLook

    Anderson Industries By akira

    Anderson Industries is a cutting-edge engineering and manufacturing company that assists forward-thinking businesses in bringing innovative products to market. They…

  15. Vulnerabilities via oss-security

    CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely

    Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: When Neethi fetches a…

  16. Vulnerabilities via oss-security

    CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service

    Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: A specially crafted…

  17. Vulnerabilities via oss-security

    CVE-2026-91865: Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service

    Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: A small WS-Policy…

  18. Ransomware via RansomLook

    ANYTHINGIT By spirals

    https://www.anythingit.com/ Certified IT Asset Disposition (ITAD) and e-waste management for federal agencies, defense contractors, and enterprise organizations…

  19. Ransomware via The Register

    FBI: Fake cop and government impersonation scams cost victims $1.6B

    Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s Internet Crime…

  20. Vulnerabilities via oss-security

    CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion

    Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: A specially crafted…