Cybersecurity
1,806 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Bulletin ID: 2026-102-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/08/2026 12:30 PM PDT Description: A stored cross-site scripting (XSS) issue in the Vega expres...
-
CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and m...
-
CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector
Bulletin ID: 2026-087-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 12:30 PM PDT Description: Amazon Athena is a serverless, interactive query service tha...
-
CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service
Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion da...
Security notice Cybersecurity -
CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
Bulletin ID: 2026-096-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 11:00 AM PDT Description: The AWS FPGA Developer Kit is a hardware-software developmen...
-
CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope
Bulletin ID: 2026-101-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 13:00 PM PDT Description: We have identified CVE-2026-85787, an incomplete list of dis...
-
CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent
Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon softw...
-
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT awsdac (diagram-as-code) is a CLI tool that generates AWS architecture di...
-
CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin
Bulletin ID: 2026-079-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:45 AM PDT Description: OpenSearch is a community-driven, open-source search and ana...
-
CVE-2026-85788 - Issue with awslabs mysql-mcp-server
Bulletin ID: 2026-103-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/09/2026 09:30 AM PDT Description: We identified an issue in awslabs.mysql-mcp-server (an open-...
-
CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents....
-
CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
Bulletin ID: 2026-094-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/02/2026 13:30 AM PDT Description: Amazon Ion-C (ion-c) is the C implementation of the Amazon I...
-
CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL q...
-
CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT Description: The Amazon EFS CSI Driver is an open-source Kubernetes Conta...
-
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for m...
-
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT Description: Amazon CodeCatalyst blueprints are reusable project template...
-
CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin
Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT Description: OpenSearch is a community-driven, open-source search and ana...
-
AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 - Update 1
Number: AL26-019Date: September 4, 2026Updated: September 9, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recen...
-
Citrix security advisory (AV26-833) - Update 1
Serial Number: AV26-833Date: August 19, 2026Updated: September 9, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13...
-
Cisco security advisory (AV26-197) – Update 3
Serial number: AV26-197Date: March 5, 2026Updated: September 9, 2026 On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included w...
-
Fortinet security advisory (AV26-023) - Update 1
Serial number: AV26-023Date: January 13, 2026Updated: September 9, 2026 On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Includ...
-
Google security advisory (AV26-904)
Serial Number: AV26-904Date: September 9, 2026 As of September 8, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.37 Google is aware that an exploit...
-
Attorney General Jeff Jackson Leads Bipartisan Coalition Pushing Federal Government to Strengthen ‘Know Your Upstream Provider Rules’ to Combat Illegal Robocalls
FOR IMMEDIATE RELEASE Wednesday, September 9, 2026 Contact: [email protected] 919-538-2809 RALEIGH — Attorney General Jeff Jackson is leading a bipartisan coalition of 49 attorneys general pushing th...
Announcement Cybersecurity -
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
-
Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them. Every scan begins with the same question: which ports on this host a...
Cybersecurity 2 versions -
The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords
The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaw...
-
Kwetsbaarheden in Adobe Photoshop Desktop met risico op misbruik: update direct
Er zijn meerdere kwetsbaarheden gevonden in Adobe Photoshop Desktop met een CVSS-score tot 8,6. Deze kwetsbaarheden zijn beoordeeld als van normale urgentie om te handelen. Er zijn geen meldingen v...
-
Kwetsbaarheden in Adobe Commerce met risico op misbruik: update onmiddellijk
Er zijn meerdere kwetsbaarheden gevonden in Adobe Commerce. Het NCSC beoordeelt de kans op misbruik als middelmatig en de mogelijke schade als hoog. Het advies is om de beschikbare updates van Adob...
-
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.
Cybersecurity 3 versions -
Srednjeevropsko sodelovanje za močnejšo kibernetsko varnost v Evropi
Urad Vlade Republike Slovenije za informacijsko varnost (URSIV) je v Mariboru gostil srečanje predstavnikov pristojnih nacionalnih organov za kibernetsko varnost držav, povezanih v Srednjeevropsko ...
Announcement Cybersecurity -
2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CV...
-
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
See how a browser-in-the-browser phishing attack led to rogue ScreenConnect persistence and evasion tactics Huntress caught in the act.
Cybersecurity 3 versions -
Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange regi...
Cybersecurity 2 versions -
Actief misbruik zero-day kwetsbaarheid in Google Chrome V8 - update nu
Er is een zero-day kwetsbaarheid gevonden in de V8 JavaScript engine van Google Chrome. Deze kwetsbaarheid, bekend als CVE-2026-87491, wordt actief misbruikt en kan ernstige schade veroorzaken. Het...
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behin...
-
Retention of electronic communications data: CJEU Advocate General issues opinion on the criteria for assessing the compatibility of national legislation with EU law
Retention of electronic communications data: CJEU Advocate General issues opinion on the criteria for assessing the compatibility of national legislation with EU law 09 September 2026 ...
Announcement Cybersecurity -
Microsoft verhelpt ernstige kwetsbaarheden in Windows en Office
Deze Patch Tuesday heeft Microsoft een groot aantal kwetsbaarheden verholpen in verschillende producten. Microsoft meldt dat twee kwetsbaarheden in Windows worden misbruikt. Een aanvaller moet hier...
-
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
Cybersecurity 3 versions -
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut that hit 440 instances across 48 countries.
-
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
-
Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings ...
Cybersecurity 2 versions -
AG Labrador’s ICAC Unit Arrests Three, Including Police Sergeant, in August Child Exploitation Cases
BOISE, ID — Attorney General Raúl Labrador has announced that investigators with his Idaho Internet Crimes Against Children (ICAC) Unit arrested three individuals in August for alleged child s...
Announcement Cybersecurity -
Microsoft patchetirsdag september 2026
Microsoft har offentliggjort sine månedlige sikkerhetsoppdateringer1.
Announcement Cybersecurity