Cybersecurity
1,855 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
2026-09-23, Version 22.23.3 'Jod' (LTS), @aduh95 prepared by @juanarbol
Notable Changes [fe2a6b2be8] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746 [871167ddfd] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #65653 [b816fc8958] - de...
Cybersecurity 2 versions -
NVIDIA security advisory (AV26-957)
Serial number: AV26-957Date: September 23, 2026 As of September 22, 2026, NVIDIA is affected by vulnerabilities in the following products: Infrastructure Controller Versions 0 to 1.9 NeMo Speech Ve...
-
GitHub security advisory (AV26-956)
Serial Number: AV26-956Date: September 23, 2026 As of September 22, 2026, GitHub is affected by vulnerabilities in the following product: Enterprise Server 3.17.0 Prior to 3.17.21 3.18.0 Prior to 3...
-
Google Chrome security advisory (AV26-955)
Serial number: AV26-955Date: September 23, 2026 As of September 22, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop...
-
Ubiquiti security advisory (AV26-954)
Serial number: AV26-954Date: September 23, 2026 As of September 22, 2026, Ubiquiti Inc is affected by vulnerabilities in the following products: Cloud Gateways Prior to 5.1.31 Dream Machines Prior ...
-
VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or ov...
-
Adobe security advisory (AV26-953)
Serial number: AV26-953Date: September 23, 2026 As of September 22, 2026, Adobe is affected by vulnerabilities in the following products: AEM 6.5 Forms JEE Prior to or equal to 6.5.25 AEM 6.5 LTS F...
-
Perú lidera la Operación Lumen, iniciativa contra la piratería digital que logró bloquear más de 300 webs en cinco países de América Latina
Por primera vez, el Perú encabezó una iniciativa internacional de lucha contra la piratería digital: la Operación Lumen, concebida y liderada por el Indecopi, que permitió bloquear 317 sitios web v...
Announcement Cybersecurity -
Active Exploitation of High-Severity Vulnerability in WordPress
Attackers are exploiting a high-severity vulnerability in WordPress to achieve remote code execution under specific conditions. Patch immediately.
Announcement Cybersecurity -
Your architecture diagram is not your resilience
For years, resilience was something you set up once. That kept the lights on, but it treated resilience as a project with an end date rather than a property you maintain. The post Your architecture...
-
WordPress security advisory (AV26-952) – Update 1
Serial number: AV26-952Date: September 23, 2026Updated: September 25, 2026 As of September 22, 2026, WordPress is affected by a vulnerability in the following product: WordPress Prior to 7.1.2 Open...
Cybersecurity 2 versions -
HPE security advisory (AV26-951)
Serial number: AV26-951Date: September 23, 2026 As of September 22, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: Analytics and Location Engine (A...
-
CISA BOD 26-04 Timelines for Three Linux Kernel CVEs
Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day r...
-
SolarWinds security advisory (AV26-950)
Serial number: AV26-950Date: September 23, 2026 As of September 22, 2026, SolarWinds is affected by vulnerabilities in the following product: SolarWinds Observability Self-Hosted Prior to 2026.2.3 ...
-
EU-funded project The Gaming Police strengthens child safety online
The EU-funded project The Gaming Police brings Finnish police into digital spaces, reaching vulnerable young people through the gaming communities they already use and trust. It focuses on preventi...
Announcement Cybersecurity -
Notepad++: disponibili PoC per 6 vulnerabilità
Disponibili Proof of Concept (PoC) per lo sfruttamento di 6 vulnerabilità, di cui 4 con gravità “alta”, in Notepad++. Tali vulnerabilità potrebbero consentire ad un attaccante di eseguire codice ar...
Advisory Cybersecurity -
How dynamic application security testing validates risk at runtime
Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce t...
Cybersecurity 2 versions -
D-Link: PoC pubblico per lo sfruttamento della CVE-2026-95675
Disponibile Proof of Concept (PoC) per lo sfruttamento di una vulnerabilità presente nei dispositivi D-Link DAP-1360 non più supportati. Tale vulnerabilità potrebbe consentire ad un utente malinten...
Advisory Cybersecurity -
Varsler vedtak i BankID-saken
Nkom har konkludert med at seks tidligere BankID-utstedere ikke har oppfylt kravene til sikkerhetsnivå «høyt». Det varslede vedtaket får ingen konsekvenser for brukere av BankID.
Announcement Cybersecurity -
Vulnerabilità in Moodle
Rilevate due nuove vulnerabilità in Moodle, nota piattaforma open source tipicamente utilizzata per l'erogazione di corsi in modalità e-learning. Tali vulnerabilità, qualora sfruttate, potrebbero c...
Advisory Cybersecurity -
Slovenska podjetja vse pogosteje tarče spletnih prevar
V zadnjih mesecih na SI-CERT beležimo porast prijav vrivanja v poslovno komunikacijo (BEC oz. Business Email Compromise), direktorskih in drugih prevar, ki ciljajo na podjetja in javne ustanove, ko...
Announcement Cybersecurity -
OAuth Token Theft Through Microsoft's Front Door
A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.
Cybersecurity 2 versions -
Podatność w oprogramowaniu WEBCON BPS
W oprogramowaniu WEBCON BPS wykryto podatność błędnego uwierzytelniania (CVE-2026-92419).
Announcement Cybersecurity -
Risolte vulnerabilità in Google Chrome
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 108 nuove vulnerabilità di sicurezza, di cui 11 con gravità “critica” e 25 con gravità “alta”.
Advisory Cybersecurity -
Fake Claude Max giveaway hides a Google account phishing trap
A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.
-
Risolte vulnerabilità su GitHub Enterprise Server
GitHub ha rilasciato aggiornamenti di sicurezza per risolvere 3 vulnerabilità, di cui 1 con gravità "critica" e 1 con gravità "alta", in GitHub Enterprise Server. Tali vulnerabilità, qualora sfrutt...
Advisory Cybersecurity -
Poskusi prevare z lažnim elektronskim sporočilom
Nekateri zavezanci ponovno prejemajo prevarantska elektronska sporočila. Finančna uprava zavezancev ne obvešča na takšen način.
Announcement Cybersecurity -
ShinyHunters claims FBI breach was revenge for “false” report
The extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.
-
Rogue RMM Abuse: How Attackers Exploit Remote Access Tools
The Huntress SOC uncovered phishing attacks that trick employees into installing rogue RMM tools like ScreenConnect for persistent access. Learn how to spot it.
-
Amendes RGPD et interaction avec le règlement sur les services numériques : retour sur la plénière du CEPD du 17 septembre 2026
Le 17 septembre 2026, le CEPD a adopté des lignes directrices sur le pouvoir des autorités de protection des données d’infliger des amendes administratives et la version finale de ses lignes direct...
Guidance Cybersecurity -
Adobe: aggiornamenti di sicurezza
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 9 con gravità "critica" e 17 con gravità "alta", nei prodotti InDesign, Content Credentials Rust SDK, C...
Advisory Cybersecurity -
Siete nuevos avisos de seguridad
Múltiples vulnerabilidades en el panel de administración de Microweber Validación incorrecta de datos de entrada en VeloCloud Orchestrator de Arista Path traversal en productos de Check Point Múlti...
-
Rilevate vulnerabilità in Erlang/OTP
Rilevate tre nuove vulnerabilità, di cui una con gravità "critica" e due con gravità "alta", in Erlang/OTP, piattaforma open source basata sul linguaggio Erlang e sul relativo set di librerie OTP, ...
Advisory Cybersecurity -
Fałszywe reklamy i złośliwe aplikacje - analiza operacji toll fraud
CERT Polska wykrył fałszywe reklamy na platformach Meta, które prowadziły do złośliwych aplikacji dostępnych w Google Play. Operacja toll fraud wymierzona była w polskich użytkowników Androida. Z 1...
Announcement Cybersecurity -
Eerste ICT-dienstverleners gecertificeerd voor keurmerk Digitale Basisveiligheid MKB
Twee ICT-dienstverleners zijn als eerste gecertificeerd voor het Keurmerk Digitale Basisveiligheid MKB. Dit vorig jaar gelanceerde keurmerk helpt mkb’ers bij het kiezen van een ICT-dienstverlener d...
-
Risolte vulnerabilità in prodotti ManageEngine
Aggiornamenti di sicurezza Zoho sanano 2 vulnerabilità in ManageEngine ADSelfService Plus, soluzione per la gestione sicura degli account in ambienti Active Directory. Tali vulnerabilità potrebbero...
Advisory Cybersecurity -
F5 informerar om kritisk sårbarhet i BIG-IP APM
F5 har publicerat information om en kritisk sårbarhet, CVE-2026-94127, i BIG-IP APM. Sårbarheten kan resultera i att en oautentiserad angripare kan fjärrexekvera godtycklig kod.
Announcement Cybersecurity -
Vulnerabilità in prodotti SolarWinds
Aggiornamenti di sicurezza SolarWinds sanano 2 vulnerabilità, di cui 1 con gravità "critica" e 1 con gravità "alta", presenti in Observability Self-Hosted, piattaforma per il monitoraggio e l'osser...
Advisory Cybersecurity -
WordPress: PoC pubbliche per lo sfruttamento di nuove vulnerabilità
Disponibili Proof of Concept (PoC) per lo sfruttamento di tre vulnerabilità, già sanate dal vendor, che interessano il prodotto WordPress Core.
Advisory Cybersecurity -
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability ha...
Cybersecurity 2 versions -
Changing|CGServiSign - OS Command Injection
Announcement Cybersecurity -
UG-CERT Hosts Operator Cybersecurity Training and Drill
September 22, 2026: UCC’s Uganda Computer Emergency Response Team (UgCERT), with support from the Forum of Incident Response and Security Teams (FIRST), on Tuesday commenced the Seventh Operator Cy...
Announcement Cybersecurity -
Kritiska WordPress ievainojamība CVE-2026-87902
Vairākās WordPress versijās atklāta kritiska ievainojamība CVE-2026-87902 ar CVSS v4.0 vērtējumu 9,2 . Tā neautentificētam uzbrucējam ļauj panākt, ka get_page_template() funkcija lapas veidnes note...
Announcement Cybersecurity -
How an ITU security lab advances trust in digital financial services
Digital financial services have expanded rapidly around the world, especially as mobile money innovations bring financial services to millions of people for the very first time. This growth in oppo...
Announcement Cybersecurity -
RAF launches first ever space squadron dedicated to defending Britain's satellites
The RAF has launched No. III Space Effects Squadron, its first dedicated unit to counter hostile threats to UK satellites.
-
Google Chrome Multiple Vulnerabilities
Announcement Cybersecurity -
WordPress 제품 보안 업데이트 권고
Announcement Cybersecurity -
Check Point 제품 보안 업데이트 권고
Announcement Cybersecurity