Aggregator
Vatican’s Click to Pray App Exposes 700,000 Users Through Unauthenticated API Flaw
The Vatican’s official Click to Pray app has exposed the personal information of more than 700,000 users through an unauthenticated API flaw. The issue allowed anyone with a web browser to retrieve account data without needing to sign in. Click to Pray offers daily prayers and papal content through its website and mobile applications. Users […]
The post Vatican’s Click to Pray App Exposes 700,000 Users Through Unauthenticated API Flaw appeared first on Cyber Security News.
DentaQuest disclosed a data breach that impacted +23 million individuals
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
We’re open-sourcing our privacy proxy CLI
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech.
The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.
Wrench Attacks Bypass Encryption by Forcing Victims to Unlock Crypto Wallets
Cryptocurrency theft is increasingly moving beyond the screen. Criminals are using violence, threats, home invasions, and kidnapping attempts to force victims to unlock wallets or approve transfers while under pressure. These incidents are known as wrench attacks, a term that describes bypassing strong encryption by targeting the person who controls the keys. Instead of defeating […]
The post Wrench Attacks Bypass Encryption by Forcing Victims to Unlock Crypto Wallets appeared first on Cyber Security News.
Booz Allen expands Vellox Suite with AI-driven threat detection platform
Booz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen’s proprietary agentic AI framework, that identify exploitable paths and vulnerabilities based on the actual state of an enterprise’s infrastructure. This automation helps protect the systems that matter most and reduces the risk of operational disruption, limits how long attackers can remain undetected in an environment … More →
The post Booz Allen expands Vellox Suite with AI-driven threat detection platform appeared first on Help Net Security.
SEO для LLM в кибербезопасности. Как попасть в ответы ИИ
Protect your devices from SMS blasters (ITSAP.00.104)
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
日本作家东野圭吾因癌症去世,享年 68 岁
Сеансы, привязка клиентов, общие хранилища — все это уйдет в прошлое. MCP становится «обычным» веб-протоколом
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS is a Microsoft Windows Server role that lets an organization run its own Public Key Infrastructure (PKI). It acts as a Certificate Authority (CA), issuing and managing digital certificates used for authentication, encryption, and signing across … More →
The post PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) appeared first on Help Net Security.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Hackers used autonomous AI agent to spy on Thailand's finance ministry
Е-сим против вас: мошенники научились красть номера без пароля и смс
Europol Launches Project COMPASS to Disrupt ‘The Com’ Cybercrime Network Targeting Minors
Europol has launched Project COMPASS, a coordinated transnational initiative aimed at disrupting “The Com,” a highly dangerous cybercrime and nihilistic extremist network that systematically targets minors and vulnerable young people across digital platforms. The Com operates as a sprawling transnational virtual network (TVN), utilizing social media, messaging apps, music platforms, and online games to recruit, […]
The post Europol Launches Project COMPASS to Disrupt ‘The Com’ Cybercrime Network Targeting Minors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.