Cybersecurity
1,855 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Fortra security advisory (AV26-906)
Serial number: AV26-906Date: September 10, 2026 As of September 9, 2026, Fortra is affected by a vulnerability in the following product: GoAnywhere MFT Endpoint Prior to 7.10.2 The Cyber ...
-
Palo Alto Networks security advisory (AV26-905)
Serial number: AV26-905Date: September 10, 2026 As of September 10, 2026, Palo Alto Networks is affected by vulnerabilities in the following products: Cloud NGFW All on AWS*, All on Azure...
-
La CNIL publie le tome 2 de L’Agence Privacy : une nouvelle enquête pour mieux comprendre la cybercriminalité
Avec « Au-delà de l’écran », l’Agence Privacy revient avec de nouvelles aventures ! Hypertrucage (deepfakes), arnaque aux sentiments, défis nocifs sur les réseaux sociaux...
Guidance Cybersecurity -
Patchtisdag september 2026 – samlad information om månadens säkerhetsuppdateringar
Flera leverantörer har släppt sina månatliga säkerhetsuppdateringar för september. Microsofts säkerhetsuppdateringar omfattar 973 sårbarheter varav 113 klassade som kritiska. Det är den i särklass ...
Announcement Cybersecurity -
Konferenca Krepitev ekosistema kibernetske varnosti v Sloveniji 2026
Konferenca 'Krepitev ekosistema kibernetske varnosti v Sloveniji 2026' bo potekala 24. novembra 2026 na Brdu pri Kranju. Namenjena bo izmenjavi izkušenj, predstavitvi konkretnih rešitev in dobrih p...
Announcement Cybersecurity -
Podatność w oprogramowaniu drEryk Gabinet
Zaszyte w kodzie poświadczenia (CVE-2026-17038) zostały wykryte w oprogramowaniu drEryk Gabinet.
Announcement Cybersecurity -
The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exp...
-
Kritieke kwetsbaarheden in Check Point VPN-producten actief misbruikt: update nu
Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoorde...
Cybersecurity 2 versions -
Kritiska ievainojamība Check Point kiberdrošības produktos
Check Point ir publicējis brīdinājumus par 2 kritiskām ievainojamībām CVE-2026-85102 un CVE-2026-85103 (abas ievainojamības ar CVSS vērtējumu 9.8), kas ietver produktus Security Gateway, Security M...
Announcement Cybersecurity -
European Commission launches Security Research and Innovation Campus
The Campus is a key element of the ProtectEU Internal Security Strategy, and it will help the EU and Member States respond to a rapidly evolving security environment and hybrid threats.
Announcement Cybersecurity -
JRC launches Security Research and Innovation Campus
The Campus brings together Europe's security community to test technologies and deploy them swiftly.
Announcement Cybersecurity -
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
-
What Is ISPM? How It Differs from IAM, PAM, IGA, and IDaaS
Key Takeaways Identity Security Posture Management (ISPM) is the continuous risk and posture layer of the identity stack not a replacement for Identity and Access Management (IAM), Privileged Acces...
-
Risolte vulnerabilità in prodotti Check Point
Check Point ha rilasciato aggiornamenti di sicurezza che risolvono 2 vulnerabilità con gravità "critica" che interessano Security Gateway, Security Management e Spark Firewall, soluzioni dedicate a...
Advisory Cybersecurity -
Kritiska ievainojamība Microsoft Windows operētājsistēmās
Microsoft brīdina par kritisku ievainojamību CVE-2026-69730 (CVSS vērtējums - 9.8) Windows DNS implementācijā, kas iekļauta Microsoft izstādātajās operētājsistēmās: Windows 10 un Windows Server. Uz...
Announcement Cybersecurity -
Open by Default After AI: The GDS Guidance and the Enforcement Question
In early May 2026, NHS England issued a reported internal guidance note, SDLC-8, mandating the removal of public access to several hundred GitHub repositories. The stated reason was AI-accelerated ...
Cybersecurity 2 versions -
2026-012: Critical Vulnerabilities in Check Point Products
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall d...
Advisory Cybersecurity -
Kwetsbaarheden in Adobe Illustrator met risico op code-uitvoering: update onmiddellijk
Er zijn 3 kwetsbaarheden gevonden in Adobe Illustrator. Deze kwetsbaarheden hebben een CVSS-score van 7,8 tot 8,6 en zijn beoordeeld als medium kans op misbruik en hoge mogelijke schade. Ze maken h...
-
AD Rights Management Service (Part 2): Extraction, Offline Decryption, and the Unrotatable Key
An AD RMS Service Group account exports the AD RMS Server Licensor Certificate private key. That 1172-byte key decrypts every document the deployment ever protected, offline, and keeps doing so aft...
Cybersecurity 3 versions -
CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
Bulletin ID: 2026-076-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 13:00 PM PDT Description: Amazon DocumentDB MCP Server is an open-source Model Context...
Security notice Cybersecurity -
CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
Bulletin ID: 2026-093-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/01/2026 11:00 AM PDT Description: SageMaker Python SDK's @step and @remote decorator pipeline ...
Security notice Cybersecurity -
CVE-2026-87911
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Security notice Cybersecurity -
CVE-2026-85656 - OS command injection in Amazon log4j-cve-2021-44228-hotpatch
Bulletin ID: 2026-098-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:30 AM PDT Description: log4j-cve-2021-44228-hotpatch is a tool which injects a Java...
Security notice Cybersecurity -
CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
Bulletin ID: 2026-085-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:30 PM PDT Description: Improper input validation in the Time Series Visual Builder ...
Security notice Cybersecurity -
CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools
Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents....
Security notice Cybersecurity -
CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server
Bulletin ID: 2026-105-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 08:30 AM PDT Description: AWS Security Agent is a managed AWS service that provides AI...
Security notice Cybersecurity -
CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
Bulletin ID: 2026-092-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/31/2026 11:30 AM PDT Description: OpenSearch is an open-source search and analytics engine. We...
Security notice Cybersecurity -
CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards
Bulletin ID: 2026-088-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 13:00 PM PDT Description: Amazon OpenSearch Service is a managed service that makes it...
Security notice Cybersecurity -
CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
Bulletin ID: 2026-075-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 12:30 PM PDT Description: The AWS Transform MCP Server (awslabs.aws-transform-mcp-serv...
Security notice Cybersecurity -
CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector
Bulletin ID: 2026-084-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:00 PM PDT Description: Amazon Athena is a serverless, interactive query service tha...
Security notice Cybersecurity -
CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
Bulletin ID: 2026-097-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:00 AM PDT Description: Amazon awslabs.dynamodb-mcp-server is an open-source Model C...
Security notice Cybersecurity -
CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands
Bulletin ID: 2026-071-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:30 PM PDT Description: AWS Command Line Interface (AWS CLI) is a unified tool to ma...
Security notice Cybersecurity -
CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
Bulletin ID: 2026-100-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion da...
-
CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool
Bulletin ID: 2026-089-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/25/2026 12:00 PM PDT Description: Strands Agents is an open-source Python SDK for building and...