CISA orders feds to patch actively exploited Drupal vulnerability
…Although BOD 22-01 applies only to U.S. federal agencies, CISA advised all defenders, including those in the private sector, to apply CVE-2026-9082 patches as soon as possible to…
Tracked topic
Keep up with the Apple ecosystem, from M5 chip performance and MacBook Neo reviews to the latest iOS 26 security updates.
…Although BOD 22-01 applies only to U.S. federal agencies, CISA advised all defenders, including those in the private sector, to apply CVE-2026-9082 patches as soon as possible to…
Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the moments where security…
…This vulnerability stems from an improper authentication weakness in the authentication subsystem, and successful exploitation enables attackers without privileges to bypass access controls and access targeted appliances, including accounts with elevated privileges…
…The first critical issue patched this month is a memory corruption security issue (tracked as CVE-2026-44747 ) stemming from an out-of-bounds write weakness in the NetWeaver Application Server ABAP…
…If the visitor clicks on the download button, they are brought to a website at openew[.]app that impersonates OpenAI's desktop application download portal. The researchers say the site uses cloaking…
…Kemp LoadMaster is a very popular Application Delivery Controller (ADC) and server load balancer used by tech companies and government entities worldwide (e.g., Amazon, U.S. Air Force) to distribute incoming…
…Internet security watchdog Shadowserver currently tracks over 380 SMA1000 appliances exposed online, although some may already have been secured against attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the…
…CISA urged security teams to closely monitor affected servers for signs of exploitation and recommended applying Microsoft's latest patches, verifying successful installation, shortening patching cycles, as well as enabling Windows Antimalware…
…Oracle WebLogic Server is an enterprise-grade Java app server used as middleware for large, multi-tier distributed applications. Tracked as CVE-2024-21182 , this security flaw can be exploited remotely by…
…AmnesiaStealer can collect data in 16 Chromium-based web browsers as well as other sensitive information, such as passwords, cryptocurrency wallets, Apple Notes and documents, and keychain data. The malware is currently…