❌

Normal view

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

30 September 2026 at 15:24
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in anΒ advisoryΒ on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

30 September 2026 at 11:30
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

30 September 2026 at 08:09
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program,Β OpenSSL saidΒ on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

29 September 2026 at 17:47
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in aΒ reportΒ (in French) published on Tuesday: it worked because of weak

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

29 September 2026 at 17:20
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers,Β according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached

❌