Cybersecurity
1,877 publications from 84 organizations filed under Cybersecurity.
Filed by publisher, not by subject — these are everything those organizations published, not everything published about Cybersecurity. See the 1,610 publications Officially classified as Cybersecurity instead.
-
Adobe security advisory (AV26-953)
Serial number: AV26-953Date: September 23, 2026 As of September 22, 2026, Adobe is affected by vulnerabilities in the following products: AEM 6.5 Forms JEE Prior to or equal to 6.5.25 AEM 6.5 LTS F...
-
Macfinger ClickFix campaign, (Tue, Sep 22nd)
2 versions -
Active Exploitation of High-Severity Vulnerability in WordPress
Attackers are exploiting a high-severity vulnerability in WordPress to achieve remote code execution under specific conditions. Patch immediately.
Announcement -
Your architecture diagram is not your resilience
For years, resilience was something you set up once. That kept the lights on, but it treated resilience as a project with an end date rather than a property you maintain. The post Your architecture...
-
WordPress security advisory (AV26-952) – Update 1
Serial number: AV26-952Date: September 23, 2026Updated: September 25, 2026 As of September 22, 2026, WordPress is affected by a vulnerability in the following product: WordPress Prior to 7.1.2 Open...
Cybersecurity 2 versions -
HPE security advisory (AV26-951)
Serial number: AV26-951Date: September 23, 2026 As of September 22, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: Analytics and Location Engine (A...
-
Designing agent-first platforms: What changes when agents do the work
The organizations pulling ahead are not simply adding AI to what they already have. They are designing for a different kind of software. The post Designing agent-first platforms: What changes when ...
-
CISA BOD 26-04 Timelines for Three Linux Kernel CVEs
Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day r...
-
SolarWinds security advisory (AV26-950)
Serial number: AV26-950Date: September 23, 2026 As of September 22, 2026, SolarWinds is affected by vulnerabilities in the following product: SolarWinds Observability Self-Hosted Prior to 2026.2.3 ...
-
Notepad++: disponibili PoC per 6 vulnerabilità
Disponibili Proof of Concept (PoC) per lo sfruttamento di 6 vulnerabilità, di cui 4 con gravità “alta”, in Notepad++. Tali vulnerabilità potrebbero consentire ad un attaccante di eseguire codice ar...
Advisory Cybersecurity -
How dynamic application security testing validates risk at runtime
Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce t...
Cybersecurity 2 versions -
D-Link: PoC pubblico per lo sfruttamento della CVE-2026-95675
Disponibile Proof of Concept (PoC) per lo sfruttamento di una vulnerabilità presente nei dispositivi D-Link DAP-1360 non più supportati. Tale vulnerabilità potrebbe consentire ad un utente malinten...
Advisory Cybersecurity -
Vulnerabilità in Moodle
Rilevate due nuove vulnerabilità in Moodle, nota piattaforma open source tipicamente utilizzata per l'erogazione di corsi in modalità e-learning. Tali vulnerabilità, qualora sfruttate, potrebbero c...
Advisory Cybersecurity -
Slovenska podjetja vse pogosteje tarče spletnih prevar
V zadnjih mesecih na SI-CERT beležimo porast prijav vrivanja v poslovno komunikacijo (BEC oz. Business Email Compromise), direktorskih in drugih prevar, ki ciljajo na podjetja in javne ustanove, ko...
Announcement Cybersecurity -
Six arrests for smuggling migrants via Schengen airports
Europol supported a migrant smuggling investigation involving law enforcement authorities from 17 countries. The criminal network was also engaged in document fraud and money laundering. The action...
Announcement Sanctions -
OAuth Token Theft Through Microsoft's Front Door
A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.
Cybersecurity 2 versions -
Podatność w oprogramowaniu WEBCON BPS
W oprogramowaniu WEBCON BPS wykryto podatność błędnego uwierzytelniania (CVE-2026-92419).
Announcement Cybersecurity -
Risolte vulnerabilità in Google Chrome
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 108 nuove vulnerabilità di sicurezza, di cui 11 con gravità “critica” e 25 con gravità “alta”.
Advisory Cybersecurity -
Fake Claude Max giveaway hides a Google account phishing trap
A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.
-
Risolte vulnerabilità su GitHub Enterprise Server
GitHub ha rilasciato aggiornamenti di sicurezza per risolvere 3 vulnerabilità, di cui 1 con gravità "critica" e 1 con gravità "alta", in GitHub Enterprise Server. Tali vulnerabilità, qualora sfrutt...
Advisory Cybersecurity -
ShinyHunters claims FBI breach was revenge for “false” report
The extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.
-
Rogue RMM Abuse: How Attackers Exploit Remote Access Tools
The Huntress SOC uncovered phishing attacks that trick employees into installing rogue RMM tools like ScreenConnect for persistent access. Learn how to spot it.
-
Adobe: aggiornamenti di sicurezza
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 9 con gravità "critica" e 17 con gravità "alta", nei prodotti InDesign, Content Credentials Rust SDK, C...
Advisory Cybersecurity -
Siete nuevos avisos de seguridad
Múltiples vulnerabilidades en el panel de administración de Microweber Validación incorrecta de datos de entrada en VeloCloud Orchestrator de Arista Path traversal en productos de Check Point Múlti...
-
Rilevate vulnerabilità in Erlang/OTP
Rilevate tre nuove vulnerabilità, di cui una con gravità "critica" e due con gravità "alta", in Erlang/OTP, piattaforma open source basata sul linguaggio Erlang e sul relativo set di librerie OTP, ...
Advisory Cybersecurity -
Fałszywe reklamy i złośliwe aplikacje - analiza operacji toll fraud
CERT Polska wykrył fałszywe reklamy na platformach Meta, które prowadziły do złośliwych aplikacji dostępnych w Google Play. Operacja toll fraud wymierzona była w polskich użytkowników Androida. Z 1...
Announcement Cybersecurity -
Eerste ICT-dienstverleners gecertificeerd voor keurmerk Digitale Basisveiligheid MKB
Twee ICT-dienstverleners zijn als eerste gecertificeerd voor het Keurmerk Digitale Basisveiligheid MKB. Dit vorig jaar gelanceerde keurmerk helpt mkb’ers bij het kiezen van een ICT-dienstverlener d...
-
Risolte vulnerabilità in prodotti ManageEngine
Aggiornamenti di sicurezza Zoho sanano 2 vulnerabilità in ManageEngine ADSelfService Plus, soluzione per la gestione sicura degli account in ambienti Active Directory. Tali vulnerabilità potrebbero...
Advisory Cybersecurity -
F5 informerar om kritisk sårbarhet i BIG-IP APM
F5 har publicerat information om en kritisk sårbarhet, CVE-2026-94127, i BIG-IP APM. Sårbarheten kan resultera i att en oautentiserad angripare kan fjärrexekvera godtycklig kod.
Announcement Cybersecurity -
Vulnerabilità in prodotti SolarWinds
Aggiornamenti di sicurezza SolarWinds sanano 2 vulnerabilità, di cui 1 con gravità "critica" e 1 con gravità "alta", presenti in Observability Self-Hosted, piattaforma per il monitoraggio e l'osser...
Advisory Cybersecurity -
WordPress: PoC pubbliche per lo sfruttamento di nuove vulnerabilità
Disponibili Proof of Concept (PoC) per lo sfruttamento di tre vulnerabilità, già sanate dal vendor, che interessano il prodotto WordPress Core.
Advisory Cybersecurity -
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability ha...
Cybersecurity 2 versions -
Changing|CGServiSign - OS Command Injection
Announcement -
Kritiska WordPress ievainojamība CVE-2026-87902
Vairākās WordPress versijās atklāta kritiska ievainojamība CVE-2026-87902 ar CVSS v4.0 vērtējumu 9,2 . Tā neautentificētam uzbrucējam ļauj panākt, ka get_page_template() funkcija lapas veidnes note...
Announcement Cybersecurity -
F5 BIG-IP Remote Code Execution Vulnerability
Announcement -
Google Chrome Multiple Vulnerabilities
Announcement -
WordPress 제품 보안 업데이트 권고
Announcement -
Check Point 제품 보안 업데이트 권고
Announcement -
DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer
DarkMe, an APT-linked VB6 RAT known for using zero day exploits, turned up in two Huntress incidents stripped down to a plain .pif infostealer malware.
2 versions -
Check Point security advisory (AV26-902) – Update 2
Serial Number: AV26-902Date: September 9, 2026Updated: September 22, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple ve...
Cybersecurity 3 versions -
F5 security advisory (AV26-949) - Update 1
Serial number: AV26-949Date: September 22, 2026 As of September 22, 2026, F5 is affected by a vulnerability in the following product: BIG-IP APM Versions 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30....
Cybersecurity 3 versions -
Arista Networks security advisory (AV26-947) – Update 1
Serial number: AV26-947Date: September 22, 2026 As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product: VeloCloud Orchestrator (VCO) On-Prem Versions 5.2....
Cybersecurity 2 versions -
CVE-2026-11400 and CVE-2026-11401
Security notice Cybersecurity -
CVE-2026-13769 – Insecure file permissions in AWS CLI
Security notice Cybersecurity