Cybersecurity
1,133 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Countries adopt global blueprint to tackle fast-evolving crime in digital age
Countries adopted on Saturday a new global blueprint for tackling rapidly evolving forms of crime, as the UN’s largest gathering on crime prevention and criminal justice opened in Abu Dhabi with a ...
-
Boletín de vulnerabilidades
Boletín de vulnerabilidades Vulnerabilidades con productos recientemente documentados:No hay vulnerabilidades nuevas para los productos a los que está suscrito.Otras vulnerabilidades de los product...
Advisory Cybersecurity -
3 Consulting Myths Debunked by Unit 42 Experts
Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked...
-
Zimbra security advisory (AV26-964)
Serial Number: AV26-964Date: September 25, 2026 As of September 25, 2026, Zimbra is affected by vulnerabilities in the following product: Zimbra Collaboration Suite (ZCS) (Daffodil) Prior to 10.1.2...
-
VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exp...
Advisory Cybersecurity -
Kothamine malware uses Tailscale’s tailcat to evade network detection
Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.
-
Case Study: How Does IBM Turn Open Source Participation Into Enterprise and Career Value?
IBM’s Jamie Thomas explains how intentional participation in open source communities and OpenSSF drives business strategy, improves software supply chain security, and creates career growth opportu...
Cybersecurity 2 versions -
Risolte vulnerabilità in prodotti Elastic
Elastic ha rilevato nuove vulnerabilità nei propri prodotti, di cui una con gravità "alta", in Kibana. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di ele...
Advisory Cybersecurity -
Agents can now set up your website’s security with Turnstile Spin
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verificat...
-
ServiceNow security advisory (AV26-963)
Serial number: AV26-963Date: September 25, 2026 As of September 24, 2026, ServiceNow is affected by vulnerabilities in the following product: ServiceNow AI Platform Versions prior to Australia Patc...
-
Criminals turn placeholder domain into ClickFix trap
A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command.
-
GitLab security advisory (AV26-962)
Serial number: AV26-962Date: September 25, 2026 As of September 23, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.2.7 Prior to 19.3.3 Prior to 19.4.1 The ...
-
Wazuh: PoC pubblico per lo sfruttamento della CVE-2026-71540
Disponibile un Proof of Concept (PoC) per lo sfruttamento della CVE-2026-71540 – già sanata dal vendor – presente in Wazuh, piattaforma open-source con funzionalità di Security Information and Even...
Advisory Cybersecurity -
Risolte vulnerabilità in prodotti Dell
Aggiornamenti di sicurezza Dell risolvono molteplici vulnerabilità, di cui 5 con gravità "alta" nei prodotti Boot Optimized Server Storage (BOSS), Rugged Control Center (RCC), Trusted Device Client...
Advisory Cybersecurity -
Call for proposals to fund projects supporting Digital Investigations and Standardisation
The European Commission published a call for proposals under the Internal Security Fund (ISF) to co-fund projects supporting Digital Investigations and Standardisation. This call has a budget of EU...
Announcement Cybersecurity -
Risolte vulnerabilità in ServiceNow
Rilasciati aggiornamenti di sicurezza che risolvono 5 vulnerabilità, di cui 2 con gravità "critica" e 3 con gravità "alta", in ServiceNow AI Platform, piattaforma di intelligenza artificiale e auto...
Advisory Cybersecurity -
Rilevate vulnerabilità in prodotti MongoDB
MongoDB ha rilasciato aggiornamenti di sicurezza per risolvere 5 vulnerabilità con gravità "alta" nei prodotti Python Driver (PyMongo), C Driver, Compass e Laravel MongoDB. Tali vulnerabilità, qual...
Advisory Cybersecurity -
CEOs from sensitive sectors to receive briefings on Russia threats
CEOs from the most sensitive sectors of the economy will receive closed-door briefings on threats posed by Russia
-
Is that vibe coded app safe? 5 checks before you download
As AI lets anyone build software, here’s how to vet that shiny new app before it exposes your data
-
Press release: Remote biometric identification in policing - public security benefits depend on robust fundamental rights safeguards
Press release: Remote biometric identification in policing - public security benefits depend on robust fundamental rights safeguards tmorris Fri, 09/25/2026 - 10:55 Document FRA press release: Remo...
-
Press release: Remote biometric identification in policing - public security benefits depend on robust fundamental rights safeguards
Press release: Remote biometric identification in policing - public security benefits depend on robust fundamental rights safeguards tmorris Fri, 09/25/2026 - 10:55 Document FRA press release: Remo...
-
Un nuevo aviso de seguridad
API y el panel de gestión de StockAgile. INCIBE ha coordinado la publicación de 7 vulnerabilidades de severidades medias que afecta a la API y el panel de gestión de StockAgile, software para tiend...
Advisory Cybersecurity -
Boletín de vulnerabilidades
Vulnerabilidades con productos recientemente documentados: No hay vulnerabilidades nuevas para los productos a los que está suscrito. Otras vulnerabilidades de los productos a los que usted está su...
Advisory Cybersecurity -
Boletín de vulnerabilidades
Vulnerabilidades con productos recientemente documentados: No hay vulnerabilidades nuevas para los productos a los que está suscrito. Otras vulnerabilidades de los productos a los que usted está su...
Advisory Cybersecurity -
Inside the OpenSSF Summer Mentorship Showcase: How Emerging Developers Are Strengthening Supply Chain Security
At OpenSSF, securing the open source software supply chain isn’t just about writing code or establishing policies. It is about growing the community of developers who build, maintain, and innovate ...
-
VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. ViewSonic ViewBoards a...
Advisory Cybersecurity -
AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
In this blog post, I explain how to use the new fuzzing taskflow based on the GitHub Security Lab Taskflow Agent AI framework. The post AI-powered fuzzing with the GitHub Security Lab Taskflow Agen...
Security notice Cybersecurity -
Trust and the enticing consultancy offer
In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the c...
-
AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
Number: AL26-023Date: September 24, 2026 This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyb...
-
Fascículo da Cartilha de Segurança para Internet sobre IA
Novo Fascículo da Cartilha de Segurança para Internet Fascículo Inteligência Artificial IA É ASSISTENTE. O RESPONSÁVEL É VOCÊ! A IA já faz parte do dia a dia, mas os resultados podem conter erros, ...
Guidance Cybersecurity -
VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability
Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identificati...
-
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we...
-
Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 4
Serial Number: AV26-804Date: August 11, 2026Updated:September 25, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: Microsoft .NET Frame...
Cybersecurity 3 versions -
WebPros security advisory (AV26-961)
Serial number: AV26-961Date: September 24, 2026 As of September 23, 2026, WebPros is affected by vulnerabilities in the following products: Plesk Versions 18.0.34 to 18.0.80.7 Version 18.0.81.0 Ple...
-
Gran Canaria impulsa la prevención en ciberseguridad entre las empresas ante el avance de los ataques digitales
En un escenario en el que la digitalización avanza con rapidez y los ciberataques afectan cada vez más a organizaciones de todos los tamaños, Gran Canaria ha acogido hoy una nueva jornada de +Ciber...
-
Managed or Modified: Choose How Huntress Hardens Microsoft 365
Managed ISPM now offers two deployment modes. Choose fully automated hardening or full control over which Microsoft 365 controls roll out, and when. See how it works.
-
OpenAI agent breached Australian government site, took months to report it
The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening?
Cybersecurity 2 versions -
The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
Threat actors exploited Samsung MagicINFO to install AnyDesk, disable Defender, and compile a Monero miner directly on a victim endpoint. Learn the detection signals.
-
When Business Email Compromise Starts Rewriting Reality
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds...
Cybersecurity 2 versions -
Rilevata vulnerabilità in PaperCut NG/MF
Rilevate 3 vulnerabilità di sicurezza, di cui 2 con gravità "alta", in PaperCut NG/MF, software di gestione e monitoraggio della stampa per ambienti aziendali. Tali vulnerabilità, qualora sfruttate...
Advisory Cybersecurity -
New Browser Guard features add protection before and after you click
Spot dangerous sites before you click—and check for scams once you’re there.
-
Clôture de l’injonction prononcée à l’encontre de la société SOLOCAL MARKETING SERVICES
Par délibération du 17 septembre 2026, la CNIL a clôturé l’injonction prononcée le 15 mai 2025 à l’encontre de la société SOLOCAL MARKETING SERVICES.
Guidance Cybersecurity -
Update Chrome: 108 security fixes for desktop, new release for Android
Google has released Chrome 154 for desktop and begun rolling out Chrome 155 for Android. Here’s what to check on your device.
-
United Kingdom and Cambodia join forces to crackdown on online scam centres
New agreement will boost intelligence sharing between UK and Cambodian law enforcement to dismantle scam operations.
-
Kwetsbaarheid in WordPress wordt actief misbruikt: update nu
Er is een kwetsbaarheid gevonden in WordPress met het kenmerk CVE-2026-87902. Deze kwetsbaarheid kan een hoog risico vormen omdat een aanvaller zonder inloggegevens mogelijk schadelijke acties kan ...
Cybersecurity 2 versions -
Dos nuevos avisos de seguridad
Elemento de ruta de búsqueda sin controlar en Evope Collector Collector versión 1.1.6.9.0, Core: 1.1.3.2.4, Update: 1.1.0.3.6 – Models: Evope.Service.exe y wtsapi32.dll. INCIBE ha coordinado la pub...
-
MacSync under the microscope: new delivery methods and a new payload
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
-
Rilevate vulnerabilità in Apache Tomcat
Apache ha rilasciato aggiornamenti di sicurezza per risolvere 15 vulnerabilità, di cui 4 con gravità "critica" e 9 con gravità "alta", in Apache Tomcat e Apache Tomcat Native. Tali vulnerabilità, q...
Advisory Cybersecurity