Cybersecurity
1,235 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Rogue RMM Abuse: How Attackers Exploit Remote Access Tools
The Huntress SOC uncovered phishing attacks that trick employees into installing rogue RMM tools like ScreenConnect for persistent access. Learn how to spot it.
-
Amendes RGPD et interaction avec le règlement sur les services numériques : retour sur la plénière du CEPD du 17 septembre 2026
Le 17 septembre 2026, le CEPD a adopté des lignes directrices sur le pouvoir des autorités de protection des données d’infliger des amendes administratives et la version finale de ses lignes direct...
Guidance Cybersecurity -
Adobe: aggiornamenti di sicurezza
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 9 con gravità "critica" e 17 con gravità "alta", nei prodotti InDesign, Content Credentials Rust SDK, C...
Advisory Cybersecurity -
Siete nuevos avisos de seguridad
Múltiples vulnerabilidades en el panel de administración de Microweber Validación incorrecta de datos de entrada en VeloCloud Orchestrator de Arista Path traversal en productos de Check Point Múlti...
-
Rilevate vulnerabilità in Erlang/OTP
Rilevate tre nuove vulnerabilità, di cui una con gravità "critica" e due con gravità "alta", in Erlang/OTP, piattaforma open source basata sul linguaggio Erlang e sul relativo set di librerie OTP, ...
Advisory Cybersecurity -
Fałszywe reklamy i złośliwe aplikacje - analiza operacji toll fraud
CERT Polska wykrył fałszywe reklamy na platformach Meta, które prowadziły do złośliwych aplikacji dostępnych w Google Play. Operacja toll fraud wymierzona była w polskich użytkowników Androida. Z 1...
Announcement Cybersecurity -
Eerste ICT-dienstverleners gecertificeerd voor keurmerk Digitale Basisveiligheid MKB
Twee ICT-dienstverleners zijn als eerste gecertificeerd voor het Keurmerk Digitale Basisveiligheid MKB. Dit vorig jaar gelanceerde keurmerk helpt mkb’ers bij het kiezen van een ICT-dienstverlener d...
-
Risolte vulnerabilità in prodotti ManageEngine
Aggiornamenti di sicurezza Zoho sanano 2 vulnerabilità in ManageEngine ADSelfService Plus, soluzione per la gestione sicura degli account in ambienti Active Directory. Tali vulnerabilità potrebbero...
Advisory Cybersecurity -
Vulnerabilità in prodotti SolarWinds
Aggiornamenti di sicurezza SolarWinds sanano 2 vulnerabilità, di cui 1 con gravità "critica" e 1 con gravità "alta", presenti in Observability Self-Hosted, piattaforma per il monitoraggio e l'osser...
Advisory Cybersecurity -
WordPress: PoC pubbliche per lo sfruttamento di nuove vulnerabilità
Disponibili Proof of Concept (PoC) per lo sfruttamento di tre vulnerabilità, già sanate dal vendor, che interessano il prodotto WordPress Core.
Advisory Cybersecurity -
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability ha...
Cybersecurity 2 versions -
How an ITU security lab advances trust in digital financial services
Digital financial services have expanded rapidly around the world, especially as mobile money innovations bring financial services to millions of people for the very first time. This growth in oppo...
Announcement Cybersecurity -
RAF launches first ever space squadron dedicated to defending Britain's satellites
The RAF has launched No. III Space Effects Squadron, its first dedicated unit to counter hostile threats to UK satellites.
-
ESAs call for vigilance over external dependencies, cyber threats and private credit risks
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have identified external dependencies, emerging technologies and private credit as key vulnerabilities for the EU financia...
-
Check Point security advisory (AV26-902) – Update 2
Serial Number: AV26-902Date: September 9, 2026Updated: September 22, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple ve...
Cybersecurity 3 versions -
F5 security advisory (AV26-949) - Update 1
Serial number: AV26-949Date: September 22, 2026 As of September 22, 2026, F5 is affected by a vulnerability in the following product: BIG-IP APM Versions 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30....
Cybersecurity 3 versions -
Arista Networks security advisory (AV26-947) – Update 1
Serial number: AV26-947Date: September 22, 2026 As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product: VeloCloud Orchestrator (VCO) On-Prem Versions 5.2....
Cybersecurity 2 versions -
CVE-2026-11400 and CVE-2026-11401
Security notice Cybersecurity -
CVE-2026-13769 – Insecure file permissions in AWS CLI
Security notice Cybersecurity -
AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127
Number: AL26-022Date: September 22, 2026 This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyb...
Cybersecurity 2 versions -
VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass
Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate...
-
Kwetsbaarheid in F5 Networks BIG-IP APM met actief misbruik
Er is een ernstige kwetsbaarheid gevonden in F5 Networks BIG-IP Access Policy Manager (APM) met een CVSS-score van 9,8. Deze kwetsbaarheid wordt actief misbruikt en kan aanzienlijke schade veroorza...
-
CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService
Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 10:00 AM PDT Description: Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLam...
Security notice Cybersecurity -
2026-013: Critical Vulnerability in F5 BIG-IP APM
On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking ...
Advisory Cybersecurity -
Erlang security advisory (AV26-948)
Serial Number: AV26-948Date: September 22, 2026 As of September 22, 2026, Erlang is affected by vulnerabilities in the following product: OTP 17.0 Prior to 27.3.4.18 21b8a1b Prior to afec515, ...
-
F5 BIG-IP: rilevato sfruttamento in rete della CVE-2026-94127
Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-94127, presente in BIG-IP APM. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzi...
Advisory Cybersecurity -
Some cheap smart glasses are a security disaster
Tests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.
-
What’s in the SOSS? Podcast #73 – S3E25 Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns
In this episode of What’s in the SOSS, ActiveState CEO Abby Kearns breaks down the rapidly evolving open source security landscape. The conversation explores why reactive post-build scanning fails,...
-
CheckPoint: rilevato sfruttamento in rete della CVE-2026-93616
Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-93616, presente in Check Point Management Server. La vulnerabilità potrebbe consentire a utenti malintenziona...
Advisory Cybersecurity -
MikroTrick: analiza techniczna, proces ujawnienia i zastosowanie agentów LLM
Opisujemy techniczne szczegóły łańcucha MikroTrick, złożonego z podatności CVE-2026-67279 i CVE-2026-86060, które w połączeniu pozwalały przejąć pełną kontrolę nad urządzeniem bez uwierzytelnienia....
Announcement Cybersecurity -
Detenciones relacionadas con los ciberataques contra la Agencia Tributaria francesa
En junio y julio de 2026, la Dirección General de Finanzas Públicas de Francia (DGFiP) sufrió varios accesos no autorizados basados en la suplantación de los identificadores de un agente y de un te...
-
LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to revie...
Cybersecurity 2 versions -
Risolte vulnerabilità in MISP
Aggiornamenti di sicurezza MISP risolvono molteplici vulnerabilità, tra cui sei con gravità "alta", in MISP, nota piattaforma collaborativa open source per la condivisione e l'analisi di informazio...
Advisory Cybersecurity -
EDPB harmonizuje metodiku ukládání pokut a schválil pokyny ke vztahu nařízení o digitálních službách a GDPR
Na svém posledním plenárním zasedání přijal Evropský sbor pro ochranu osobních údajů (EDPB) pokyny k uplatňování pravomoci ukládat správní pokuty ve vztahu k jiným nápravným pravomocem podle GDPR a...
Announcement Cybersecurity -
Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
A simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.
-
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in whic...
-
Introducing CAIRN: Frontier tracking for AI-integrated malware
Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.
-
Researchers used Claude to hack OpenAI
Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.
-
Looking for free Robux? Here’s what’s real, and what’s a scam
Fake giveaways, free Robux generators and lookalike login pages all target the same thing – your Roblox account
-
Un nuevo aviso de seguridad
Un nuevo aviso de seguridad Referencia directa a objetos inseguros (IDOR) en Tankuam Places de Kompini Fecha22/09/2026 Importancia5 - Crítica Recursos Afectados Tankuam Places, versiones publicadas...
Advisory Cybersecurity -
Inyección de comandos en R95 de D-Link
D-Link R95, revisión de hardware Ax y versión de firmware BE9500_1.00.16. D-Link continúa verificando si otras revisiones de hardware o versiones de firmware también están afectadas. D-Link ha publ...
-
Un nuevo aviso de SCI
Un nuevo aviso de SCI Inyección CRLF en VPN Client de Lenze Fecha22/09/2026 Importancia5 - Crítica Recursos Afectados Lenze VPN Client, versiones 1.0.0 y posteriores, pero anteriores a la 1.4.7, ut...
-
EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines
EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines 22 September 2026 During its latest plenary, the EDPB has adopted guidelines on the application of the power to i...
Announcement Cybersecurity -
21st September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Go...
-
Roundcube security advisory (AV26-503) – Update 1
Serial number: AV26-503Date: May 25, 2026Updated: September 21, 2026 On May 24, 2026, Roundcube published security advisories to address vulnerabilities in the following product: Roundcube We...
-
Zyxel security advisory (AV26-603) – Update 1
Serial number: AV26-603Date: June 16, 2026Updated: September 21, 2026 On June 16, 2026, Zyxel published a security advisory to address vulnerabilities in the following products: GS1900 se...
-
Veeam security advisory (AV26-513) – Update 1
Serial number: AV26-513Date: May 27, 2026Updated: September 21, 2026 On May 27, 2026, Veeam published security advisories to address vulnerabilities in the following products: Veeam Backu...