uk
Feedback

Не попадись на ботовода! Telemetrio знаходить і позначає такі канали мітками 👉 Хочеш бачити мітку, оформляй підписку 👈

Vulnerability News

Vulnerability News

Відкрити в Telegram

Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup

Показати більше
5 447
Підписники
+324 години
+317 днів
+16930 днів
Архів дописів
Atlassian Patches Critical Vulnerability Affecting 8 Products Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory. The post Atlassian Patches Critical Vulnerability Affecting 8 Products appeared first on SecurityWeek. https://www.securityweek.com/atlassian-patches-critical-vulnerability-affecting-8-products/

Android’s October 2026 Updates Patch 25 Vulnerabilities The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation. The post Android’s October 2026 Updates Patch 25 Vulnerabilities appeared first on SecurityWeek. https://www.securityweek.com/androids-october-2026-updates-patch-25-vulnerabilities/

Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations The post Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies appeared first on SecurityWeek. https://www.securityweek.com/wikimedia-says-rogue-openai-agents-tried-to-turn-its-tools-into-proxies/

ASOS Confirms Cyberattack, Data Breach Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users. The post ASOS Confirms Cyberattack, Data Breach appeared first on SecurityWeek. https://www.securityweek.com/asos-confirms-cyberattack-data-breach/

Anthropic Introduces 3-Tier Cyber Verification Program for AI Access Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models. The post Anthropic Introduces 3-Tier Cyber Verification Program for AI Access appeared first on SecurityWeek. https://www.securityweek.com/anthropic-introduces-3-tier-cyber-verification-program-for-ai-access/

Chrome 155 Update Patches 247 Vulnerabilities Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track. The post Chrome 155 Update Patches 247 Vulnerabilities appeared first on SecurityWeek. https://www.securityweek.com/chrome-155-update-patches-247-vulnerabilities/

Advantest Discloses Data Breach Months After Ransomware Attack The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack. The post Advantest Discloses Data Breach Months After Ransomware Attack appeared first on SecurityWeek. https://www.securityweek.com/advantest-discloses-data-breach-months-after-ransomware-attack/

Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers. The post Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform appeared first on SecurityWeek. https://www.securityweek.com/hadrian-raises-40-million-to-expand-autonomous-offensive-security-platform/

Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany The individual was detained in May and has been extradited to Germany to face hacking charges. The post Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany appeared first on SecurityWeek. https://www.securityweek.com/qilin-ransomware-suspect-arrested-in-japan-extradited-to-germany/

Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts Southern Company is notifying customers that their utility account information was accessed by hackers. The post Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts appeared first on SecurityWeek. https://www.securityweek.com/georgia-power-alabama-power-data-breach-hits-400000-accounts/

ShinyHunters Extorted Boeing Spin-off Prior to Arrests A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle "Rey," was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's father -- Royal Jordanian Airlines. https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/

Advantest confirms personal information stolen in ransomware attack Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. [...] https://www.bleepingcomputer.com/news/security/advantest-confirms-personal-information-stolen-in-ransomware-attack/

Musician sent to prison for $10 million streaming fraud using AI bots A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music, and YouTube Music in a massive streaming royalty fraud scheme. [...] https://www.bleepingcomputer.com/news/security/musician-gets-18-months-in-prison-for-10-million-streaming-fraud-using-ai-bots/

SonicWall warns of max severity SSRF flaw in SMA1000 gateways SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. [...] https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/

Hackers exploit critical Atlassian flaw after public PoC release A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. [...] https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/

Ransomware has a new target. Is your backup ready? Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why organizations need isolated, immutable, and regularly tested backups that attackers cannot easily reach. [...] https://www.bleepingcomputer.com/news/security/ransomware-has-a-new-target-is-your-backup-ready/

PoeLLM malware infects exposed AI servers in cryptomining attacks A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...] https://www.bleepingcomputer.com/news/security/poellm-malware-infects-exposed-ai-servers-in-cryptomining-attacks/

Microsoft Outlook to block MSIX attachments starting November Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. [...] https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-to-block-msix-attachments-used-in-attacks/

Hackers hijack Google domains after breaching ccTLD registries Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. [...] https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/

FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...] https://www.bleepingcomputer.com/news/security/fbi-ongoing-fortibleed-attacks-lock-out-fortigate-vpn-admins/