115Articles
9Categories
2026-03-27Date
🚨
CISA Adds Critical Aquasecurity Trivy Scanner Vulnerability to KEV CatalogThe Cybersecurity and Infrastructure Security Agency (CISA) has urgently added a critical flaw affecting Aquasecurity’s Trivy scanner to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-33634, this security weakness involves embedded malicious code that targ…
KEV
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-53521 F5 BIG-IP Remote Code Execution Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and…
KEV
πŸ›
ISC Issues Critical Warning Over Kea DHCP Vulnerability That Could Remotely Crash Services
πŸ›
Windows Error Reporting Vulnerability Exposes Systems to Privilege Escalation, Allowing SYSTEM Access
πŸ›
CVE-2026-28753 NGINX ngx_mail_proxy_module vulnerability
πŸ›
CVE-2026-32647 NGINX ngx_http_mp4_module vulnerability
πŸ›
CVE-2026-23398 icmp: fix NULL pointer dereference in icmp_tag_validation()
πŸ›
CVE-2026-23396 wifi: mac80211: fix NULL deref in mesh_matches_local()
πŸ›
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions
πŸ›
CVE-2026-34085
πŸ›
CVE-2026-33526 Squid vulnerable to Denial of Service in ICP Request handling
πŸ›
CVE-2026-33515 Squid has issues in ICP message handling
πŸ›
CVE-2026-32748 Squid has Denial of Service in ICP Response handling
πŸ›
CVE-2026-27651 NGINX ngx_mail_auth_http_module vulnerability
πŸ›
CVE-2026-27654 NGINX ngx_http_dav_module vulnerability
πŸ›
CVE-2026-27784 NGINX ngx_http_mp4_module vulnerability
πŸ›
CVE-2026-28755 NGINX ngx_stream_ssl_module vulnerability
πŸ›
CVE-2026-23397 nfnetlink_osf: validate individual option lengths in fingerprints
πŸ›
CVE-2026-4647 Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
πŸ›
CVE-2026-4746 Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton
πŸ›
CVE-2026-4775 Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
πŸ›
CVE-2026-23068 spi: spi-sprd-adi: Fix double free in probe error path
πŸ›
CVE-2025-71183 btrfs: always detect conflicting inodes when logging inode refs
πŸ›
CVE-2025-71184 btrfs: fix NULL dereference on root when tracing inode eviction
πŸ›
CVE-2026-23004 dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()
πŸ›
CISA Flags Critical PTC Vulnerability That Had German Police Mobilized
πŸ›
Attackers exploit critical Langflow RCE within hours as CISA sounds alarm
KEV
πŸ›
Rapid Exploitation of CVE-2026-21962 Hits Oracle WebLogic - Infosecurity Magazine
πŸ›
Chromium: CVE-2026-4673 Heap buffer overflow in WebAudio
πŸ›
Chromium: CVE-2026-4680 Use after free in FedCM
πŸ›
Chromium: CVE-2026-4677 Out of bounds read in WebAudio
πŸ›
Chromium: CVE-2026-4675 Heap buffer overflow in WebGL
πŸ›
Chromium: CVE-2026-4679 Integer overflow in Fonts
πŸ›
Chromium: CVE-2026-4674 Out of bounds read in CSS
πŸ›
Chromium: CVE-2026-4442 Heap buffer overflow in CSS
πŸ›
CVE-2026-32187 Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
⚠️
Google: The quantum apocalypse is coming sooner than we thought
⚠️
BreachForums Verion 5 - 339,778 breached accounts
⚠️
Red Hat Warns of Malware Embedded in Popular Linux Tool, Opening Doors for Unauthorized Access
⚠️
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
⚠️
TeamPCP Hackers Focus on AI Developers, Planting Malicious Code to Disrupt Projects
⚠️
8 steps CISOs can take to empower their teams
⚠️
Coruna iOS Exploit Kit Likely an Update to Operation Triangulation
⚠️
CISA: New Langflow flaw actively exploited to hijack AI workflows
KEV
⚠️
BIND 9 Security Flaws Allow Attackers to Bypass Security Controls and Crash Servers
⚠️
A forensic intelligence suite for Matrix investigators
⚠️
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
⚠️
Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits
⚠️
A Matrix forensic intelligence suite for investigators
⚠️
Custom Fonts Can Trick AI Assistants Into Approving Phishing Sites
⚠️
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets
⚠️
European Commission data stolen in a cyberattack on the infrastructure hosting its web sites
⚠️
Spot Scam Red Flags Fast
πŸ“’
WatchGuard security advisory (AV26-289)
πŸ“’
Ericsson security advisory (AV26-292)
πŸ“’
FreeBSD security advisory (AV26-291)
πŸ“’
[Control systems] Siemens security advisory (AV26-290)
πŸ“’
Microsoft Edge security advisory (AV26-293)
πŸ”₯
Iran Targeted by Self-Propagating Malware in Supply-Chain Cyberattacks
πŸ”₯
Anonymous Tip System Breach May Expose Tipsters
πŸ”₯
Dutch Police discloses security breach after phishing attack
πŸ”₯
Silver Fox Cyberattack Targets Japanese Businesses with Tax-Themed Phishing Scams
πŸ”₯
Bearlyfy Hits 70+ Russian Firms with Custom GenieLocker Ransomware
πŸ”₯
Cyberangriff auf die Linke
πŸ”₯
European Commission investigating breach after Amazon cloud hack
πŸ”₯
Hightower Holding Data Breach Impacts 130,000 - SecurityWeek
πŸ”₯
In Other News: Palo Alto Recruiter Scam, Anti-Deepfake Chip, Google Sets 2029 Quantum Deadline
πŸ”₯
TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)
πŸ”₯
Apple says no one using Lockdown Mode has been hacked with spyware
πŸ”₯
Iranian hackers claim breach of FBI director Kash Patel’s personal email account
πŸ”₯
European Commission investigating breach after Amazon cloud account hack
πŸ”₯
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
πŸ”₯
Lloyds Bank reveals how IT bug exposed transaction data
πŸ”₯
European Commission confirms cyberattack after hackers claim data breach
πŸ”₯
The telnyx packages on PyPI have been compromised
πŸ”₯
Compromised telnyx on PyPI: WAV Steganography and Credential Theft
πŸ”₯
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
πŸ”₯
Iranian-linked hackers claimed responsibility for the breach of FBI Direct Kash Patel’s personal email account
πŸ”₯
Iranian-linked hackers claimed responsibility for the breach of FBI Direct Kash Patel’s personal email account
πŸ”₯
Iranian-linked hackers claimed responsibility for the breach of FBI Direct Kash Patel’s personal email account
πŸ•΅οΈ
ISC Stormcast For Friday, March 27th, 2026 https://isc.sans.edu/podcastdetail/9868, (Fri, Mar 27th)
πŸ•΅οΈ
Off-Topic Friday
πŸ•΅οΈ
Fake Cloudflare CAPTCHA Pages Deliver Infiniti Stealer Malware on macOS
πŸ•΅οΈ
Hackers Implant Stealthy BPFdoor Backdoors in Telecom Networks for Persistent Access
πŸ•΅οΈ
Phishing ZIP Files Used to Deploy PXA Stealer Targeting Financial Firms
πŸ•΅οΈ
Hackers Deploy USB Malware, RATs, and Stealers in Southeast Asian Government Attacks
πŸ•΅οΈ
Hackers Target South Asian Financial Firm with BRUSHWORM and BRUSHLOGGER Attacks
πŸ•΅οΈ
RSAC 2026 Conference Announcements Summary (Days 3-4)
πŸ•΅οΈ
TP-Link Patches High-Severity Router Vulnerabilities
πŸ•΅οΈ
How Adaptive Email Security Helps Navigate Threats in the Age of AI
πŸ•΅οΈ
Invoice Fraud Costs UK Construction Sector Millions, NCA Warns - Infosecurity Magazine
πŸ•΅οΈ
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
πŸ•΅οΈ
NYC Health Notifying Patients of 2 Third-Party Hacks
πŸ•΅οΈ
OpenAI Launches Bug Bounty Program for Abuse and Safety Risks
πŸ•΅οΈ
The Post-Quantum Visibility Problem
πŸ•΅οΈ
Pro-Iranian Hacking group Claims Credit for Hack of FBI Director Kash Patel’s Personal Account
πŸ•΅οΈ
Hackers have exposed more than 8.3 million supposedly confidential reports to tip lines like Crime Stoppers
πŸ•΅οΈ
Hackers have exposed more than 8.3 million supposedly confidential reports to tip lines like Crime Stoppers
πŸ•΅οΈ
Hackers have exposed more than 8.3 million supposedly confidential reports to tip lines like Crime Stoppers
πŸ•΅οΈ
Introducing Our KnowBe4 AI Agents
πŸ•΅οΈ
Friday Squid Blogging: Bioluminescent Bacteria in Squid
πŸ•΅οΈ
How Microsoft Defender protects high-value assets in real-world attack scenarios
πŸ•΅οΈ
Scam Baiting, AI, and the New Grift Economy, Part 2 - Rinoa Poison - SWN #567
πŸ•΅οΈ
RSAC 2026: No easy fixes for expanding AI attack surface, but a coordinated response is emerging
🌐
Fake VS Code alerts on GitHub spread malware to developers
🌐
Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER
πŸŽ™οΈ
Soap Box: Red teaming AI systems with SpecterOps
πŸ“‘
Windows 11 KB5079391 update rolls out Smart App Control improvements
πŸ“‘
Anti-piracy coalition takes down AnimePlay app with 5 million users
πŸ“‘
We Are At War
πŸ“‘
Agentic GRC: Teams Get the Tech. The Mindset Shift Is What's Missing.
πŸ“‘
Most notable supply-chain attacks of 2025 | Kaspersky official blog
πŸ“‘
RSAC 2026 wrap-up – Week in security with Tony Anscombe
πŸ“‘
A cunning predator: How Silver Fox preys on Japanese firms this tax season
πŸ“‘
How AI Agents Are Redefining the Insider Risk Threat Model