101Articles
7Categories
2026-03-17Date
๐Ÿ›
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
KEV
๐Ÿ›
CVE-2026-32775
๐Ÿ›
CVE-2026-23941 Request smuggling via first-wins Content-Length parsing in inets httpd
๐Ÿ›
CVE-2026-23943 Pre-auth SSH DoS via unbounded zlib inflate
๐Ÿ›
CVE-2025-69647
๐Ÿ›
CVE-2025-69648
๐Ÿ›
CVE-2026-32249 NFA regex engine NULL pointer dereference affects Vim < 9.2.0137
๐Ÿ›
CVE-2026-32776
๐Ÿ›
CVE-2026-32778
๐Ÿ›
CVE-2026-32777
๐Ÿ›
CVE-2026-23942 SFTP root escape via component-agnostic prefix check in ssh_sftpd
๐Ÿ›
CVE-2026-4111 Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive
๐Ÿ›
CVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group
๐Ÿ›
CVE-2026-4105 Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method
๐Ÿ›
CVE-2026-23066 rxrpc: Fix recvmsg() unconditional requeue
๐Ÿ›
CVE-2026-1703 Limited path traversal when installing wheel archives
๐Ÿ›
CVE-2026-23069 vsock/virtio: fix potential underflow in virtio_transport_get_credit()
๐Ÿ›
Angular XSS Vulnerability Threatens Thousands of Web Applications
๐Ÿ›
CISA Flags Year-Old Wing FTP Vulnerability as Exploited
๐Ÿ›
Nvidia NemoClaw promises to run OpenClaw agents securely
๐Ÿ›
Apple pushes first Background Security Improvements update to fix WebKit flaw
๐Ÿ›
ZDI-26-216: (Pwn2Own) QNAP TS-453E smbd domain_name Argument Injection Authentication Bypass Vulnerability
โš ๏ธ
GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
โš ๏ธ
New CondiBot Variant and โ€˜Monacoโ€™ Miner Target More Network Devices
โš ๏ธ
CISA Alerts Users to Exploited Chrome 0-Day Flaws
KEV
โš ๏ธ
Runtime: The new frontier of AI agent security
โš ๏ธ
WebFiling Flaw at UK Companies House Exposed Director Data for Months
โš ๏ธ
CISA Issues Alert on Wing FTP Server Vulnerability Used in Attacks
KEV
โš ๏ธ
Creating Better Security Guidance and Code with LLMs - Mark Curphey - ASW #374
โš ๏ธ
South Korean Police Accidentally Post Cryptocurrency Wallet Password
โš ๏ธ
Microsoft Launches AI-Driven Troubleshooting for Purview Data Lifecycle Tools
โš ๏ธ
AWS Bedrockโ€™s โ€˜isolatedโ€™ sandbox comes with a DNS escape hatch
โš ๏ธ
GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
โš ๏ธ
LeakNet ransomware uses ClickFix and Deno runtime for stealthy attacks
โš ๏ธ
CISA flags Wing FTP Server flaw as actively exploited in attacks
KEV
โš ๏ธ
174 Vulnerabilities Targeted by RondoDox Botnet
โš ๏ธ
Iranian Hackers Use Compromised Cameras for Regional Surveillance
โš ๏ธ
Microsoft stops force-installing the Microsoft 365 Copilot app
โš ๏ธ
Outdated OWASP Advice
โš ๏ธ
UK Companies House Exposed Details of Millions of Firms
โš ๏ธ
Tech Giants Invest $12.5 Million in Open Source Security
โš ๏ธ
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
โš ๏ธ
End / Collapse: New Code, New Risks
โš ๏ธ
Apple rolls out first โ€˜background securityโ€™ update for iPhones, iPads, and Macs to fix Safari bug
โš ๏ธ
Antonโ€™s Vibe Coding Experience: A Reflection on Risk Decisions
โš ๏ธ
Malware Hiding on Steam
โš ๏ธ
LABScon25 Replay | Your Apps May Be Gone, But the Hackers Made $9 Billion and Theyโ€™re Still Here
โš ๏ธ
Investing in the people shaping open source and securing the future together
โš ๏ธ
Get started with Elastic Security from your AI agent
๐Ÿ“ข
Windows 11 25H2/24H2 Update Addresses Bluetooth Device Visibility Issues
๐Ÿ“ข
Spring security advisory (AV26-245)
๐Ÿ“ข
Stryker says itโ€™s restoring systems after pro-Iran hackers wiped thousands of employee devices
๐Ÿ“ข
GitHub security advisory (AV26-246)
๐Ÿ”ฅ
Weekly Update 495
๐Ÿ”ฅ
Stryker Targeted by Large-Scale Wiper Attack, Tens of Thousands of Devices Lost
๐Ÿ”ฅ
Hackers Abuse Trusted Websites in New Attacks on Microsoft Teams Users
๐Ÿ”ฅ
Payload ransomware hits Windows and ESXi with Babuk-style encryption
๐Ÿ”ฅ
AI, APIs and DDoS Collide in New Era of Coordinated Cyberattacks
๐Ÿ”ฅ
Google Warns Ransomware Groups Shift to Data Theft as Profits Decline
๐Ÿ”ฅ
Robotic Surgery Giant Intuitive Discloses Cyberattack
๐Ÿ”ฅ
LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader
๐Ÿ”ฅ
Europe sanctions Chinese and Iranian firms for cyberattacks
๐Ÿ•ต๏ธ
ISC Stormcast For Tuesday, March 17th, 2026 https://isc.sans.edu/podcastdetail/9852, (Tue, Mar 17th)
๐Ÿ•ต๏ธ
LiveChat Support Tools Abused in SaaS Phishing Scheme
๐Ÿ•ต๏ธ
Malicious NPM Packages Spread PylangGhost RAT in Supply Chain Attack
๐Ÿ•ต๏ธ
Researchers Uncover Ways to Decrypt Palo Alto Cortex XDR BIOC Rules for Evasion
๐Ÿ•ต๏ธ
Hackers Leverage Safe Links and URL Rewriting to Evade Detection
๐Ÿ•ต๏ธ
What is Integrated Cloud Email Security (ICES) and Why do you Need It?
๐Ÿ•ต๏ธ
Packagist Themes Deliver Trojanized jQuery in OphimCMS Supply Chain Attack
๐Ÿ•ต๏ธ
Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware
๐Ÿ•ต๏ธ
Glassworm Malware Infects Popular React Native npm Packages
๐Ÿ•ต๏ธ
Microsoft Issues Emergency Patch for Critical Windows 11 RRAS Vulnerabilities
๐Ÿ•ต๏ธ
IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th)
๐Ÿ•ต๏ธ
Tracebit Raises $20M for Cloud-Native Deception Technology
๐Ÿ•ต๏ธ
Microsoft shares fix for Windows C: drive access issues on Samsung PCs
๐Ÿ•ต๏ธ
Google, Meta, Microsoft Among Signatories of Pact to Combat Scams
๐Ÿ•ต๏ธ
Security Flaw in AWS Bedrock Code Interpreter Raises Alarms - Infosecurity Magazine
๐Ÿ•ต๏ธ
Cyber-Attacken fluten Eon-Netz: Angriffe verzehnfacht
๐Ÿ•ต๏ธ
UK Agency Exposed Corporate Executive Data - BankInfoSecurity
๐Ÿ•ต๏ธ
GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub
๐Ÿ•ต๏ธ
Orchid Security Recognized by Gartnerยฎ as a Representative Vendor of Guardian Agents
๐Ÿ•ต๏ธ
Surf AI Raises $57 Million for Agentic Security Operations Platform
๐Ÿ•ต๏ธ
CyberheistNews Vol 16 #11 9 Must-Know Best Practices for Email Security
๐Ÿ•ต๏ธ
We don't need to hack your AI Agent to hack your AI Agent - SRLabs Research
๐Ÿ•ต๏ธ
We don't need to hack your AI Agent to hack your AI Agent - SRLabs Research
๐Ÿ•ต๏ธ
Switzerland built an alternative to BGP. Nobody noticed
๐Ÿ•ต๏ธ
Switzerland built an alternative to BGP. Nobody noticed
๐Ÿ•ต๏ธ
From Windows to macOS: ClickFix attacks shift tactics with ChatGPT-based lures
๐Ÿ•ต๏ธ
New font-rendering trick hides malicious commands from AI tools
๐Ÿ•ต๏ธ
From Phishing to AI Agents: Can We Design for Digital Mindfulness?
๐Ÿ•ต๏ธ
So Many AI Attacks, It Made Quantum Seem Easy
๐Ÿ•ต๏ธ
AI Spicy Mode, Steam, Glassworm, Samsung, Stryker, Waymo, Cole Porter, and More - SWN #564
๐ŸŒ
AI is Everywhere, But CISOs are Still Securing It with Yesterday's Skills and Tools, Study Finds
๐ŸŒ
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
๐Ÿ“ก
Microsoft: Enabling Teams Meeting add-in breaks Outlook Classic
๐Ÿ“ก
New Windows 11 hotpatch fixes Bluetooth device visibility issue
๐Ÿ“ก
New font-rendering trick hides malicious commands from AI tools
๐Ÿ“ก
Top 5 Things CISOs Need to Do Today to Secure AI Agents
๐Ÿ“ก
Researchers disclose vulnerabilities in IP KVMs from four manufacturers
๐Ÿ“ก
How World ID wants to put a unique human identity on every AI agent
๐Ÿ“ก
AWS completes the second GDV community audit with participant insurers in Germany