Debian has released an advisory for OpenJDK-21 addressing multiple vulnerabilities that could lead to certificate validation issues, denial of service, or data leaks, urging users to upgrade.
To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with add...
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.
Russian cybersecurity vendor Kaspersky sai...
Repairable hardware is little comfort when personal details escape
OpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework. OpenAI disclosed that internal evaluations of Astra, one of its upcoming models, have found cybersecurity capabilities significant enough that...
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
This is good:
Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/crypt...
Foresee a immédiatement activé ses mécanismes de défense en matière de sécurité de l'information et a fait appel à des entreprises et à des experts externes spécialisés dans la cybersécurité afin de contenir la faille, d'en évaluer l'ampleur et de renforcer l'infrastructure réseau. D'après l'évaluat...
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports
Walk away and hope the classifier catches anything irreversible or destructive
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers A use-after-free bug tracked as CVE-2026-64564 and nicknamed SCTPhantom has been lurking in Linux’s SCTP networking code since 2008 and can be chained into full root access on a host; researchers say they used it to es...
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.
Online Training: Updates and Membership Discounts
A macOS malware variant has been detected stealing crypto, passwords and more
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.
The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.
Anthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether they want to switch to auto mode. In a controlled experiment with 1,053 paid profes...
Online Training: Updates and Membership Discounts
Online Training: Updates and Membership Discounts
AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.