Cybersecurity
1,610 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
GCP-2026-056
Published: 2026-08-26Description Description Severity Notes An Improper Input Validation vulnerability was discovered in the JDBC driver in BigQuery Data Transfer Service versions prior to May 1, 2...
-
GCP-2026-057
Published: 2026-08-26Description Description Severity Notes A series of vulnerabilities were discovered in Envoy Proxy. For instructions and more details, see the Cloud Service Mesh security bullet...
-
GCP-2026-058
Published: 2026-09-02Description Description Severity Notes A missing project permission check in GKE Multi-Cloud (CreateAttachedCluster, CreateAwsCluster, CreateAzureCluster) APIs allowed an attac...
-
GCP-2026-059
Published: 2026-09-04Description Description Severity Notes A Missing Authorization vulnerability was discovered in the HTTP Connector in Integration Connectors versions prior to December 11, 2025....
-
GCP-2026-060
Published: 2026-09-04Updated: 2026-09-08Description Description Severity Notes 2026-09-08 Update: Added link to the Cluster Toolkit security bulletin. A security flaw in the Slurm sbcast tool (CVE-...
-
GCP-2026-061
Published: 2026-09-09Description Description Severity Notes A security vulnerability (GHSA-p7v4-vr35-mj6f, CVE assignment pending) in containerd's CRI implementation allows a container restored fro...
-
GCP-2026-062
Published: 2026-09-11Description Description Severity Notes Multiple security vulnerabilities were discovered in Slurm that affect Cluster Toolkit blueprints that reference specific image versions....
-
MongoDB security advisory (AV26-911)
Serial Number: AV26-911Date: September 11, 2026 As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products: Java Driver Prior to 5.11.1 Laravel MongoDB (PHP) Prior t...
-
Metasploit Wrap Up: This One Goes to Sixteen!
Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules,...
Cybersecurity 2 versions -
The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment
The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of speci...
Cybersecurity 2 versions -
Spēkā stājas Kibernoturības aktā noteiktās ziņošanas prasības ražotājiem
No 2026. gada 11. septembra ražotājiem ir spēkā pienākums ziņot par ievainojamībām un nopietniem incidentiem, kas ietekmē Eiropas Savienības tirgū laistos produktus ar digitāliem elementiem.
Announcement Cybersecurity -
HashiCorp security advisory (AV26-910)
Serial Number: AV26-910Date: September 11, 2026 As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Consul Prior to 2.0.4 Consul Enterprise 1.0 Prior to 1....
-
CYBER_CON 2026 přivedl do Brna stovky odborníků. Hlavním tématem letošního ročníku byla kybernetická odolnost
Téměř 900 účastníků, bezmála 70 řečníků, desítky odborných přednášek, workshopů a diskusí. Takový byl 12. …
Announcement Cybersecurity -
CERT.LV kopā ar partneriem stiprinās Latvijas kiberdrošības ekosistēmu
Aizsardzības ministrija sadarbībā ar partneriem – Centrālo finanšu un līgumu aģentūru, Rīgas Tehnisko universitāti un Kiberincidentu novēršanas institūciju CERT.LV – septembrī ir uzsākusi īstenot p...
Announcement Cybersecurity -
Introducing automatic remediation policies with Cloudflare CASB
Cloudflare CASB policies introduce a native automation engine built directly on the Cloudflare developer platform to remediate SaaS risks automatically. Security teams can now design event-driven l...
-
CERT-SE:s veckobrev v.37
I veckans brev kan du läsa om EU:s Cyber Resilience Act (CRA), där de första kraven träder i kraft idag. Du kan även läsa om cybersäkerhetskonferensen Svensk cyber 2026 som arrangeras av NCSC i nov...
Announcement Cybersecurity -
Stärkt brottsbekämpning genom särskilda provokativa åtgärder
Regeringen har beslutat om en lagrådsremiss med förslag som ger brottsbekämpande myndigheter bättre möjligheter att utreda och lagföra svårutredd och allvarlig brottslighet. Förslagen innebär bland...
Announcement Cybersecurity -
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
-
Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR
Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 17 (Right to erasure ‘right to be forgotten’) EXTI...
-
Mikrotik security advisory (AV26-887) – Update 2
Serial Number: AV26-887Date: September 8, 2026Updated: September 25, 2026 As of September 3, 2026, Mikrotik is affected by vulnerabilities in the following product: RouterOS Prior to 6.49...
Cybersecurity 2 versions -
Skal sikre smartprodukter bedre – fra nå gjelder nye krav til rapportering
Fra 11. september må sårbarheter i produkter som kan kobles til internett, rapporteres i tråd med EUs Cyber Resilience Act (CRA). Nasjonal kommunikasjonsmyndighet (Nkom) ber både produsenter og imp...
Announcement Cybersecurity -
Kritiskas ievainojamības GitLab programmatūrā
GitLab ir publicējis informāciju par divām kritiskām ievainojamībām - CVE-2026-85706 (ar CVSS novērtējumu 10.0) un CVE-2026-87719 (ar CVSS novērtējumu 9.9).
Announcement Cybersecurity -
Kā sabojāt uzbrucējam dienu? Ar MFA (daudzfaktoru autentifikāciju) | OUCH! septembris 2026
Daudzfaktoru autentifikācija jeb MFA ir vienkāršs veids kā bezmaksas pievienot papildu drošības līmeni saviem kontiem. Tā vietā, lai paļautos tikai uz paroli, daudzpakāpju autentifikācija (MFA) izm...
Announcement Cybersecurity -
Cyber Resilience Act: Meldepflicht startet
Für Hersteller von Produkten mit digitalen Elementen gelten auf dem Binnenmarkt der EU ab dem 11. September 2026 die Meldepflichten des CRA. Hersteller müssen aktiv ausgenutzte Schwachstellen sowie...
Announcement Cybersecurity -
The SOC Just Gained a Capability It Never Had
Agentic investigation is the shift your SOC could never staff. Here is how the always-on AI, the evolved analyst, and the expert on call now fit together.
-
“Eye” spy: Cyclops Blink returns with extended capabilities
Upgraded modular malware observed in attacks on Cisco Firewall Management Center (FMC) devices
-
AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060
Number: AL26-020Date: September 10, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that ma...
-
Tech Talk Recap: A Practitioner’s Guide to CRA Readiness
The EU Cyber Resilience Act is no longer a distant regulatory concept. With vulnerability reporting obligations to ENISA arriving on September 11 and the full weight of the law landing in December ...
-
CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is software that runs ...
-
HPE security advisory (AV26-909)
Serial number: AV26-909Date: September 10, 2026 As of September 9, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: ClearPass Policy Manage...
-
We've got one word for it, and it's usually the wrong one
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address...
-
VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physic...
-
WebPros security advisory (AV26-908)
Serial number: AV26-908Date: September 10, 2026 As of September 10, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Pri...
-
CVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library
Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic J...
-
Adobe security advisory (AV26-808) – Update 2
Serial number: AV26-808Date: August 12, 2026Updated: September 24, 2026 As of August 11, 2026, Adobe is affected by vulnerabilities in the following products: Prior to or equal to ACC v7:...
Cybersecurity 2 versions -
The future of infrastructure resiliency starts with modernization
Modernization only succeeds when organizations have confidence that their infrastructure can withstand disruption and continue supporting critical operations. The post The future of infrastruc...
-
Credential Theft: How Attackers Steal & Use Stolen Credentials
Learn what credential theft is, how attackers steal credentials, and how to prevent credential-based attacks with identity-focused defenses from Huntress.
Cybersecurity 3 versions -
BlueMoon exploit kit turns Chrome and Windows flaws into attacks
Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.
-
Best Practices for Good Endpoint Hardening | Huntress
Learn what endpoint hardening is, why it matters, and best practices to reduce attack surface, control access, & stop common intrusion paths.
Cybersecurity 3 versions -
PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A polic...
-
[Control systems] Advantech security advisory (AV26-907)
Serial number: AV26-907Date: September 10, 2026 As of September 10, 2026, Advantech is affected by vulnerabilities in the following product: Advantech WISE-6610 industrial gateway Multipl...
-
Google je izdao zakrpe za 230 ranjivosti. Ažurirajte Chrome preglednik.
Google je objavio sigurnosno ažuriranje kojim se otklanja ukupno 230 ranjivosti, među kojima se nalazi i ranjivost nultog dana Chrome preglednika koja se aktivno iskorištava u napadima. Google je p...
Announcement Cybersecurity -
35 Actionable Password Statistics for Businesses in 2026 | Huntress
The top password statistics might surprise you. Learn how common poor password hygiene is, plus tips to better protect your precious credentials.
Cybersecurity 3 versions -
The 20 Most Common Passwords Hackers Target in 2026
See this year's most common passwords, why they're so easy to crack, and how a stronger password (or passphrase) habit keeps your accounts protected.
Cybersecurity 3 versions -
The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails
Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environment AI models can q...
Cybersecurity 2 versions -
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.