Cybersecurity
1,758 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
Bulletin ID: 2026-093-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/01/2026 11:00 AM PDT Description: SageMaker Python SDK's @step and @remote decorator pipeline ...
Security notice Cybersecurity -
CVE-2026-87911
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Security notice Cybersecurity -
CVE-2026-85656 - OS command injection in Amazon log4j-cve-2021-44228-hotpatch
Bulletin ID: 2026-098-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:30 AM PDT Description: log4j-cve-2021-44228-hotpatch is a tool which injects a Java...
Security notice Cybersecurity -
CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
Bulletin ID: 2026-085-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:30 PM PDT Description: Improper input validation in the Time Series Visual Builder ...
Security notice Cybersecurity -
CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools
Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents....
Security notice Cybersecurity -
CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server
Bulletin ID: 2026-105-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 08:30 AM PDT Description: AWS Security Agent is a managed AWS service that provides AI...
Security notice Cybersecurity -
CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
Bulletin ID: 2026-092-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/31/2026 11:30 AM PDT Description: OpenSearch is an open-source search and analytics engine. We...
Security notice Cybersecurity -
CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards
Bulletin ID: 2026-088-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 13:00 PM PDT Description: Amazon OpenSearch Service is a managed service that makes it...
Security notice Cybersecurity -
CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
Bulletin ID: 2026-075-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 12:30 PM PDT Description: The AWS Transform MCP Server (awslabs.aws-transform-mcp-serv...
Security notice Cybersecurity -
CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector
Bulletin ID: 2026-084-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:00 PM PDT Description: Amazon Athena is a serverless, interactive query service tha...
Security notice Cybersecurity -
CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
Bulletin ID: 2026-097-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:00 AM PDT Description: Amazon awslabs.dynamodb-mcp-server is an open-source Model C...
Security notice Cybersecurity -
CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands
Bulletin ID: 2026-071-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:30 PM PDT Description: AWS Command Line Interface (AWS CLI) is a unified tool to ma...
Security notice Cybersecurity -
CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
Bulletin ID: 2026-100-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion da...
-
CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool
Bulletin ID: 2026-089-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/25/2026 12:00 PM PDT Description: Strands Agents is an open-source Python SDK for building and...
-
CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Bulletin ID: 2026-102-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/08/2026 12:30 PM PDT Description: A stored cross-site scripting (XSS) issue in the Vega expres...
-
CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and m...
-
CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector
Bulletin ID: 2026-087-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 12:30 PM PDT Description: Amazon Athena is a serverless, interactive query service tha...
-
CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service
Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion da...
Security notice Cybersecurity -
CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
Bulletin ID: 2026-096-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 11:00 AM PDT Description: The AWS FPGA Developer Kit is a hardware-software developmen...
-
CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope
Bulletin ID: 2026-101-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 13:00 PM PDT Description: We have identified CVE-2026-85787, an incomplete list of dis...
-
CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent
Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon softw...
-
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT awsdac (diagram-as-code) is a CLI tool that generates AWS architecture di...
-
CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin
Bulletin ID: 2026-079-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:45 AM PDT Description: OpenSearch is a community-driven, open-source search and ana...
-
CVE-2026-85788 - Issue with awslabs mysql-mcp-server
Bulletin ID: 2026-103-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/09/2026 09:30 AM PDT Description: We identified an issue in awslabs.mysql-mcp-server (an open-...
-
CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents....
-
CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
Bulletin ID: 2026-094-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/02/2026 13:30 AM PDT Description: Amazon Ion-C (ion-c) is the C implementation of the Amazon I...
-
CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL q...
-
CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT Description: The Amazon EFS CSI Driver is an open-source Kubernetes Conta...
-
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for m...
-
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT Description: Amazon CodeCatalyst blueprints are reusable project template...
-
CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin
Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT Description: OpenSearch is a community-driven, open-source search and ana...
-
AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 - Update 1
Number: AL26-019Date: September 4, 2026Updated: September 9, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recen...
-
Citrix security advisory (AV26-833) - Update 1
Serial Number: AV26-833Date: August 19, 2026Updated: September 9, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13...
-
Cisco security advisory (AV26-197) – Update 3
Serial number: AV26-197Date: March 5, 2026Updated: September 9, 2026 On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included w...
-
Fortinet security advisory (AV26-023) - Update 1
Serial number: AV26-023Date: January 13, 2026Updated: September 9, 2026 On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Includ...
-
Google security advisory (AV26-904)
Serial Number: AV26-904Date: September 9, 2026 As of September 8, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.37 Google is aware that an exploit...
-
Attorney General Jeff Jackson Leads Bipartisan Coalition Pushing Federal Government to Strengthen ‘Know Your Upstream Provider Rules’ to Combat Illegal Robocalls
FOR IMMEDIATE RELEASE Wednesday, September 9, 2026 Contact: [email protected] 919-538-2809 RALEIGH — Attorney General Jeff Jackson is leading a bipartisan coalition of 49 attorneys general pushing th...
Announcement Cybersecurity -
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
-
Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them. Every scan begins with the same question: which ports on this host a...
Cybersecurity 2 versions -
The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords
The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaw...
-
Kwetsbaarheden in Adobe Photoshop Desktop met risico op misbruik: update direct
Er zijn meerdere kwetsbaarheden gevonden in Adobe Photoshop Desktop met een CVSS-score tot 8,6. Deze kwetsbaarheden zijn beoordeeld als van normale urgentie om te handelen. Er zijn geen meldingen v...
-
Kwetsbaarheden in Adobe Commerce met risico op misbruik: update onmiddellijk
Er zijn meerdere kwetsbaarheden gevonden in Adobe Commerce. Het NCSC beoordeelt de kans op misbruik als middelmatig en de mogelijke schade als hoog. Het advies is om de beschikbare updates van Adob...
-
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.
Cybersecurity 3 versions -
Srednjeevropsko sodelovanje za močnejšo kibernetsko varnost v Evropi
Urad Vlade Republike Slovenije za informacijsko varnost (URSIV) je v Mariboru gostil srečanje predstavnikov pristojnih nacionalnih organov za kibernetsko varnost držav, povezanih v Srednjeevropsko ...
Announcement Cybersecurity -
2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CV...