Latest news
-
Vulnerabilities via Canadian Centre for Cyber Security
Arista Networks security advisory (AV26-940)
Serial number: AV26-940 Date: September 18, 2026 As of September 9, 2026, Arista Networks is affected by vulnerabilities in the following product: EOS Multiple versions…
-
Threat Intel via Cloudflare
Saving another 100TB of RAM with math (and Rust)
Cloudflare operates at a scale so big that even after working here for years, it doesn’t seem real. We have thousands of servers all over the world with petabytes of RAM…
-
AI Security via CyberScoop
Researchers use AI to find widespread software decoder flaw
Researchers said they used Anthropic’s Claude and OpenAI’s Codex to identify a damaging flaw embedded in a popular software decoding tool that could leave major internet…
-
AI Security via The Register
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
Talk about your competitor getting through the door. Security researchers used Anthropic's Claude to help hack into OpenAI employees’ ChatGPT accounts. A trio of bug…
-
Breaches via Security Affairs
Gyazo Data Breach Exposes 23 Million User Records
A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is…
-
Threat Intel via SentinelLABS
Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
Executive Summary Following disclosure of the TraderTraitor attack against LayerZero in April 2026, SentinelOne identified an additional victim with the same macOS…
-
Vulnerabilities via Chrome Releases
Chrome Dev for Android Update
Hi everyone! We've just released Chrome Dev 156 (156.0.8063.0) for Android. It's now available on Google Play.
-
Vulnerabilities via The Hacker News
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in…
-
Threat Intel via The Register
North Korea's fake job interviews infected 30,000 devices
North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters…
-
Threat Intel via Flashpoint
The Flashpoint Threat Intelligence Brief: Middle East
Blogs Blog The Flashpoint Threat Intelligence Brief: Middle East Flashpoint’s weekly analysis tracks shifting kinetic and cyber threat radiuses, geopolitical…
-
Breaches via HIPAA Journal
HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud
Each year, millions of taxpayers’ dollars are lost to Medicare and Medicaid fraud, with fraud related to durable medical equipment, prosthetics, orthotics, and supplies…
-
Vulnerabilities via Chrome Releases
Chrome Dev for Desktop Update
The Dev channel has been updated to 156.0.8063.3 for Windows, Mac and Linux. A partial list of changes is available in the Git log. Interested in switching release…
-
Ransomware via RansomLook
forus.cl By lockbit5
Founded in 1980 and headquartered in Santiago, Chile, Forus is a provider of apparel. The company pr...
-
Ransomware via RansomLook
Anderson Industries By akira
Anderson Industries is a cutting-edge engineering and manufacturing company that assists forward-thinking businesses in bringing innovative products to market. They…
-
Vulnerabilities via oss-security
CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely
Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: When Neethi fetches a…
-
Vulnerabilities via oss-security
CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service
Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: A specially crafted…
-
Vulnerabilities via oss-security
CVE-2026-91865: Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service
Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: A small WS-Policy…
-
Ransomware via RansomLook
ANYTHINGIT By spirals
https://www.anythingit.com/ Certified IT Asset Disposition (ITAD) and e-waste management for federal agencies, defense contractors, and enterprise organizations…
-
Ransomware via The Register
FBI: Fake cop and government impersonation scams cost victims $1.6B
Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s Internet Crime…
-
Vulnerabilities via oss-security
CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion
Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: A specially crafted…
