134Articles
9Categories
2026-04-17Date
🚨
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active ExploitationA recently disclosed high-severity security flaw in Apache ActiveMQ Classic has come under active exploitation in the wild, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA). To that end, the agency has added the vulnerability, tracked as CV…
KEV
🚨
U.S. CISA adds a flaw in Apache ActiveMQ to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Apache ActiveMQ to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Apache ActiveMQ, tracked as CVE-2026-34197 (CVSS score o…
KEV
🐛
Cisco Warns Webex Customers Of Critical SSO Problem
🐛
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions
🐛
CVE-2026-33948 jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input
🐛
CVE-2026-40164 jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
🐛
CVE-2026-35469 SpdyStream: DOS on CRI
🐛
CVE-2026-39956 jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure
🐛
CVE-2026-32316 jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow
🐛
CVE-2026-33947 jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()
🐛
CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
🐛
CVE-2026-41035
🐛
CVE-2026-35199 SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation
🐛
CVE-2025-14821 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows
🐛
CVE-2026-40179 Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer
🐛
PoC Released for FortiSandbox Flaw Enabling Arbitrary Command Execution
🐛
Weaponized CVE-2026-39987 Pushes Blockchain Backdoor Through Hugging Face
🐛
Another Microsoft Defender privilege escalation bug emerges days after patch
🐛
TP-Link Routers Hit by Mirai in CVE-2023-33538 Attacks
🐛
NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities - Infosecurity Magazine
🐛
Chromium: CVE-2026-6296 Heap buffer overflow in ANGLE
🐛
Chromium: CVE-2026-6363 Type Confusion in V8
🐛
Chromium: CVE-2026-6359 Use after free in Video
🐛
Chromium: CVE-2026-6364 Out of bounds read in Skia
🐛
Chromium: CVE-2026-6362 Use after free in Codecs
🐛
Chromium: CVE-2026-6313 Insufficient policy enforcement in CORS
🐛
Chromium: CVE-2026-6314 Out of bounds write in GPU
🐛
Chromium: CVE-2026-6318 Use after free in Codecs
🐛
Chromium: CVE-2026-6361 Heap buffer overflow in PDFium
🐛
Chromium: CVE-2026-6310 Use after free in Dawn
🐛
Chromium: CVE-2026-6360 Use after free in FileSystem
🐛
Chromium: CVE-2026-6316 Use after free in Forms
🐛
Chromium: CVE-2026-6309 Use after free in Viz
🐛
Chromium: CVE-2026-6311 Uninitialized Use in Accessibility
🐛
Chromium: CVE-2026-6307 Type Confusion in Turbofan
🐛
Chromium: CVE-2026-6306 Heap buffer overflow in PDFium
🐛
Chromium: CVE-2026-6303 Use after free in Codecs
🐛
Chromium: CVE-2026-6308 Out of bounds read in Media
🐛
Chromium: CVE-2026-6302 Use after free in Video
🐛
Chromium: CVE-2026-6300 Use after free in CSS
🐛
Chromium: CVE-2026-6304 Use after free in Graphite
🐛
Chromium: CVE-2026-6305 Heap buffer overflow in PDFium
🐛
Chromium: CVE-2026-6301 Type Confusion in Turbofan
🐛
Chromium: CVE-2026-6317 Use after free in Cast
🐛
Chromium: CVE-2026-6312 Insufficient policy enforcement in Passwords
🐛
Chromium: CVE-2026-6298 Heap buffer overflow in Skia
🐛
Chromium: CVE-2026-6297 Use after free in Proxy
🐛
Chromium: CVE-2026-6299 Use after free in Prerender
🐛
Critical sandbox bypass fixed in popular Thymeleaf Java template engine
⚠️
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts
⚠️
Fake Zoom SDK Update Spreads Sapphire Sleet Malware in New macOS Attack Chain
⚠️
Critical Flowise Flaw Enables Remote Command Execution via MCP Adapters
⚠️
Google Deploys Gemini AI to Stop Threat Actors, Blocking 8.3 Billion Ads
⚠️
Amtrak - 2,147,679 breached accounts
⚠️
Local area network anonymity hardening tool for Linux
⚠️
Palo Alto’s Helmut Reisinger sees a cyber sea change ahead as AI advances
⚠️
Mythos and Cybersecurity
⚠️
Tails 7.6.2 patches vulnerability that could expose saved files - Help Net Security
⚠️
We beat Google’s zero-knowledge proof of quantum cryptanalysis
⚠️
SEO Poisoning Attack Uses Microsoft Binary to Install RMM Tool
⚠️
Operation PowerOFF Knocks Out 75,000 DDoS Attackers and Over 50 Service Domains
⚠️
White House moves to give federal agencies access to Anthropic’s Claude Mythos
⚠️
Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face
⚠️
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
KEV
⚠️
PowMix botnet targets Czech workforce
⚠️
Operation PowerOFF: 53 DDoS domains seized and 3 Million criminal accounts uncovered
⚠️
Pen Test Took Down Campus WiFi
⚠️
We Reproduced Anthropic's Mythos Findings With Public Models
⚠️
Inditex confirms third-party breach as hackers threaten Zara data leak
⚠️
New “RedSun” Windows Defender zero-day exploited in the wild
KEV
⚠️
Hackers are abusing unpatched Windows security flaws to hack into organizations
⚠️
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
KEV
⚠️
Flawed Cisco update threatens to stop APs from getting further patches
⚠️
Temporary fix for Section 702.
KEV
⚠️
Securing autonomous AI at scale with Arvind (Nitro) Nithrakashyap from Rubrik
📢
With US spy laws set to expire, lawmakers are split over protecting Americans from warrantless surveillance
📢
US House extends FISA Section 702 for ten days.
🔥
Payouts King Emerges: New Ransomware Operation Tied to Ex-BlackBasta Members
🔥
108 Chrome extensions caught stealing user data and hijacking sessions
🔥
“Your shipment has arrived” email hides remote access software
🔥
Data breach at edtech giant McGraw Hill affects 13.5 million accounts
🔥
Industrial Systems Hit by New Email-Worm Threat Wave
🔥
Amtrak data breach exposed information of 2.1 million accounts
🔥
AI Upgrades, Security Breaches, and Industry Shifts Define This Week in Tech
🔥
Man who hacked US Supreme Court filing system sentenced to probation
🔥
Kyrgyzstan-based crypto exchange Grinex shuts down after $13.7M cyber heist, blames Western Intelligence
🕵️
ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
🕵️
Hackers Deploy ATHR for Scalable AI-Driven Vishing and Credential Theft
🕵️
Anthropic Introduces Claude Opus 4.7 for Advanced Problem-Solving
🕵️
ZionSiphon Malware Hits Israeli Desalination Plants
🕵️
Censys Warns 6 Million Public-Facing FTP Servers Are Still Exposed in 2026
🕵️
Fiverr left customer files public and searchable on Google
🕵️
Top 5 Disaster Recovery Companies in 2026
🕵️
OpenAI Extends GPT-5.4-Cyber Access to Trusted Organizations Worldwide
🕵️
Microsoft Acknowledges Reboot Loop Issue on Windows Servers Following April Patches
🕵️
Identity at the Edge: How the Sixth Annual Identity Management Day Highlights the New Frontiers of Trust
🕵️
ZionSiphon malware designed to sabotage water treatment systems
🕵️
Operation PowerOFF identifies 75k DDoS users, takes down 53 domains
🕵️
North Korea Uses ClickFix to Target macOS Users' Data
🕵️
Systemic Flaw in MCP Protocol Could Expose 150 Million Downloads - Infosecurity Magazine
🕵️
Six million FTP servers exposed online | Cybernews
🕵️
Bluesky Outage: Coordinated Traffic Attack Causes Widespread Errors
🕵️
Off-Topic Friday
🕵️
Over 13M Kemper Corporation records leaked on the dark web, hackers claim | Cybernews
🕵️
Cisco patches critical bugs in Webex, ISE | news | SC Media
🕵️
New Phishing Attack Turns n8n Into On-Demand Malware Machine
🕵️
Widespread AI Use Masks a Growing Workplace Readiness Gap
🕵️
Brave to launch minimalist “Origin” browser with core privacy features
🕵️
Tor VPN for Android security audit confirms robust design
🕵️
Transform security logs into OCSF format using a configuration-driven ETL solution
🕵️
Anthropic Releases Opus 4.7, Not as ‘Broadly Capable’ as Mythos AI
🕵️
Clothing Retailer Patches Website Flaw Exposing Customer Data
🕵️
Chinese Humanoid Robots Dominate Opening Day of Canton Fair 2026
🕵️
Apple iPhone Ultra: New Leak Reveals ‘Passport’ Design, High Price Tag
🕵️
Friday Squid Blogging: New Giant Squid Video
🕵️
Dougbot, RedSun, ATHR, Vishing, Cisco, Google, Chrome, Severance, Shor, Josh Marpet.. - SWN #573
🌐
Inside ZionSiphon: politically driven malware aims at Israeli water systems
🌐
Analyse: Vom Mythos zur Vulnocalypse und was jetzt wirklich zu tun ist
🌐
Hackers leverage leaked government intelligence tools to target everyday iOS users | Kaspersky official blog
🎙️
Auslegungssache 157: Datenschutz vor Gericht
📡
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
📡
Angreifer attackieren Apache ActiveMQ Broker, Apache ActiveMQ
📡
Ärger mit aktueller NordVPN-App für macOS
📡
Amazon: Ring-Kameras jetzt mit optionaler Gesichtserkennung
📡
Windows-Updates: Unerwartete Server-Reboots und Anmeldestörungen
📡
Jetzt patchen nginx-ui! Angreifer übernehmen Kontrolle über Nginx-Server
📡
Österlicher Zertifikats-GAU bei D-Trust: Zehntausende Zertifikate ungültig
📡
YubiKey Manager: Sicherheitslücke ermöglicht Ausführung untergeschobenen Codes
📡
Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul
📡
Singer loses life savings to fake wallet downloaded from the Apple App Store
📡
Android 13 erreicht Support-Ende: Millionen Geräte betroffen
📡
This old-school scam is still working
📡
DraftKings hacker sentenced to prison, ordered to pay $1.4 Million
📡
EU-App zur Altersprüfung: Experten knacken „Sorglos-Paket“ in Minuten