Tag: software
-
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL’s open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software’s spacecraft and instrument command bus.The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI First…
-
What is DORA (Digital Operations Resilience Act)?
When a major software outage hits the financial system, the consequences can ripple across the whole economy. To ensure that banks, investment firms, and their … Read more First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/what-is-dora-digital-operations-resilience-act/
-
What is DORA (Digital Operations Resilience Act)?
When a major software outage hits the financial system, the consequences can ripple across the whole economy. To ensure that banks, investment firms, and their … Read more First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/what-is-dora-digital-operations-resilience-act-2/
-
More Code Equals More Exposure
AI-generated code is increasing software output faster than security teams can review it, creating a growing need for automated security tooling built for AI-scale development. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/more-code-equals-more-exposure/
-
Critical Citrix NetScaler Flaw Allows Attackers to Bypass Authentication
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler Gateway appliances. Among these, there is an authentication-bypass flaw that could expose remote-access environments to unauthenticated breaches. Citrix NetScaler Flaw The most severe issue, tracked as CVE-2026-19490, has a CVSS v4 base score of 9.3 and…
-
Critical Citrix NetScaler Flaw Allows Attackers to Bypass Authentication
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler Gateway appliances. Among these, there is an authentication-bypass flaw that could expose remote-access environments to unauthenticated breaches. Citrix NetScaler Flaw The most severe issue, tracked as CVE-2026-19490, has a CVSS v4 base score of 9.3 and…
-
CISA explores single contract for cybersecurity software purchases
First seen on scworld.com Jump to article: www.scworld.com/brief/cisa-explores-single-contract-for-cybersecurity-software-purchases
-
GitLab Code Injection Flaw Exploited in the Wild
CVE-2026-19478 Can Alter or Delete Public Projects Without Authentication. Researchers detected active exploitation of CVE-2026-19478, a critical GitLab code injection flaw that lets unauthenticated attackers alter public projects, forge merge records or delete repositories, creating a potential path to software supply-chain compromise. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/gitlab-code-injection-flaw-exploited-in-wild-a-32606
-
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-hackers-siemens-s7-devices-cisa-fbi/828321/
-
Electronic health record company CareCloud says 3.7 million people affected by breach
Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments. First seen on therecord.media Jump to article: therecord.media/electronic-health-record-company-carecloud-data-breach
-
The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. First seen on cyberscoop.com Jump to article: cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm/
-
Supply chain attack modelling using MITRE ATTCK
Supply chain risk is often discussed as a supplier problem, but for security teams it is better treated as an attack path problem. The practical question is not simply whether a supplier is trustworthy. It is how a compromise of that supplier, their software, their credentials, or their support channels could be used to reach……
-
Eigener Fehler entlarvt globale Cyberkriminelle ‘StopAndProtect”-Kampagne aufgedeckt
Check Point Research (CPR), die Sicherheitsforschungsabteilung von”¯Check Point Software Technologies “¯hat eine ungewöhnliche Entdeckung bei der Analyse einer neu identifizierten Cyber-Kampagne namens ‘StopAndProtect” gemacht. In diesem Fall erlaubten gravierende Fehler bei der Absicherung des Betriebs ihrer Software einen seltenen und tiefen Einblick in die Infrastruktur der Cyberkriminellen. ‘StopAndProtect”-Kampagne Das Wichtigste in Kürze: Ungewöhnlicher Einblick durch OPSEC-Fehler: Sicherheitsforscher stießen bei ihrer Untersuchung auf öffentlich […] First…
-
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.”The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software…
-
Oracle Releases 943 Security Patches to Fix Critical Vulnerabilities Across Enterprise Products
Oracle has released 943 security patches as part of its August 2026 Critical Security Patch Update (CSPU), addressing newly disclosed vulnerabilities across its enterprise software portfolio. This update affects Oracle products under both Premier Support and Extended Support. It includes fixes for flaws tracked by various CVE identifiers. Oracle Releases 943 Security Patches The vulnerabilities…
-
Oracle Releases 943 Security Patches to Fix Critical Vulnerabilities Across Enterprise Products
Oracle has released 943 security patches as part of its August 2026 Critical Security Patch Update (CSPU), addressing newly disclosed vulnerabilities across its enterprise software portfolio. This update affects Oracle products under both Premier Support and Extended Support. It includes fixes for flaws tracked by various CVE identifiers. Oracle Releases 943 Security Patches The vulnerabilities…
-
Oracle Releases 943 Security Patches to Fix Critical Vulnerabilities Across Enterprise Products
Oracle has released 943 security patches as part of its August 2026 Critical Security Patch Update (CSPU), addressing newly disclosed vulnerabilities across its enterprise software portfolio. This update affects Oracle products under both Premier Support and Extended Support. It includes fixes for flaws tracked by various CVE identifiers. Oracle Releases 943 Security Patches The vulnerabilities…
-
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest.The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault…

