Tag: advisory
-
The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act
Tags: access, advisory, ai, application-security, breach, crypto, cyber, korea, malware, north-koreaThis weekly roundup covers a brazen breach claim against the FBI’s recruitment portal, a multinational advisory exposing North Korea’s fake-recruiter malware operation, a sweeping EU proposal to reshape children’s access to social media, a conversation on application security in the age of AI agents, a short-lived Discord ban in the Philippines, and a multimillion-dollar hot-wallet…
-
ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
ServiceNow has disclosed five vulnerabilities affecting its AI Platform, including two critical flaws that could allow unauthenticated attackers to execute arbitrary SQL commands, extract sensitive instance data, modify records, and escalate privileges. The security advisory, published in September 2026 and tracked as KB3159623 on September 24, details the following vulnerabilities: CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and…
-
Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication
A highly severe vulnerability in Roundcube Webmail is being actively exploited, posing risks to unpatched email servers through unauthenticated SQL injection attacks. This vulnerability, tracked as CVE-2026-48842, affects Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. On September 21, the Canadian Center for Cyber Security updated advisory AV26-503, warning that reports from the…
-
D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
D-Link has announced a critical stack-based buffer overflow vulnerability affecting the non-US DIR-822A router, identified as CVE-2026-86296. This vulnerability has received a maximum CVSS v3.1 score of 10.0 and a CVSS v4.0 score of 10.0. Furthermore, a public proof-of-concept (PoC) exploit is reportedly available. The company published advisory SAP10516 on September 18 and updated it…
-
Contagious Interview: 30,000 devices infected by a fake job interview
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview.…
-
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/
-
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum”, a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. First seen on therecord.media Jump to article: therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
-
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.Unbound 1.26.1, released the same day, fixes the bug, tracked as…
-
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the…
-
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Daily OT Security News: September 16, 2026
Today’s updates include multiple CISA ICS advisories for high-risk vulnerabilities in surveillance, maritime, and industrial management products, plus a reported exploitation campaign that targeted internet-facing Gitea instances and impacted industrial software repositories. CISA issues advisory for Digital Watchdog VMAX DVR… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-16-2026/
-
Threat Intelligence Alone Won’t Close the Exploitation Gap
Tags: advisory, ai, breach, credentials, data-breach, exploit, intelligence, marketplace, threat, vulnerabilityA leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most…
-
Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that the campaign has targeted…
-
Iranian Hackers Dodging Corporate Defenses to Reach Critics
Joint Advisory Details Chosen Brick Spyware Used Against Iran’s Critics Abroad. Iranian state hackers are steering dissidents, activists and journalists away from corporate devices and onto personal computers to plant spyware that can capture screens, record audio and steal messages, according to a joint advisory from British, U.S. and Dutch intelligence agencies. First seen on…
-
Nintendo Switch Flaw Lets Nearby Attackers Run Code, Steal Data
A newly disclosed Nintendo Switch vulnerability is pushing owners of the original console toward an urgent firmware update, particularly those who tend to play in public spaces. Nintendo confirmed the vulnerability in Nintendo Switch systems in a PDF advisory released Sept. 10, just a day after quietly shipping firmware version 23.0.0 to address the problem.…
-
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14.On such servers, many customers’ sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access…
-
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate
-
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate
-
Daily OT Security News: September 11, 2026
Daily OT Security News: September 11, 2026, verified items below. CISA advisory release covers pipeline monitoring, satellite terminals, and medical ICS software An OpenText Cybersecurity Community roundup on September 10 reports four newly released CISA advisories covering NextGen Mirth… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-11-2026/
-
Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair
UK cybersecurity specialist Core to Cloud has appointed former Currys Group CIO Andy Gamble as Chair of its Advisory Board as the company looks to accelerate the growth of its managed security services. Gamble brings nearly 30 years of board-level technology leadership and will work with Core to Cloud on its strategic, advisory and commercial…
-
Finding and Notifying a ShinyHunters Claims Impersonation Campaign Before It Activated: 61 Domains, 48 Brands
By Adrian Cheek, Senior Cybercrime Researcher ReliaQuest Threat Research published a short public advisory about a ShinyHunters campaign on August 17, 2026. This campaign was built on domains following a company[.]claims pattern, and reported that the group had added legal… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/finding-and-notifying-a-shinyhunters-claims-impersonation-campaign-before-it-activated-61-domains-48-brands/
-
US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale extraction campaigns against US frontier models since…
-
Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions…
-
Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions…
-
ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions
ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released…
-
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw affects ACC version 4.0.0.2 and earlier, allowing for unauthenticated root access. Critical ASUS Control Center Flaw The advisory was published on September 4, 2026, and was last updated on the same day. While the…
-
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw affects ACC version 4.0.0.2 and earlier, allowing for unauthenticated root access. Critical ASUS Control Center Flaw The advisory was published on September 4, 2026, and was last updated on the same day. While the…

