2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Pytho…
P5
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are assoc…
P5
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulner…
P20
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient access control to file system resources. An attacker could exploit this vulnerability by submitting crafted values in specific UI fields. A successful exploit c…
P5
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A succ…
P5
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and str…
P30
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This vulnerability is due to an improper control with EPG contracts. An attacker could exploit this vulnerability by sending IPv4 or IPv6 packets using UDP source and destination ports that are assigned to DHCP traffic through an affected device. A successful exploit could allow the attacker …
P5
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
Multiple vulnerabilities in the Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as Next Generation OAM (NGOAM), could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to improper input validation of IP traffic when NGOAM is enabled. An attacker could exploit these vulnerabilities by sending crafted packets to an IP inte…
P20
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process…
P30
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate of UDP or TCP connections to a data plane interface on an affected device. A successful exploit could allow the attacker to cause instability to various routing and control plane …
P5
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) condition, or elevate privileges. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no…
P5
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by t…
P30
2026-10-07 15:44 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-07 16:00 UTC
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. [...]
P0
2026-10-07 15:34 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 16:15 UTC
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network
P10
2026-10-07 15:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 16:15 UTC
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including
P0
2026-10-07 15:04 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-07 15:05 UTC
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...]
P0
2026-10-07 15:00 UTC
Security Journalism
The Record · indexed 2026-10-07 15:20 UTC
How a recent Supreme Court decision on geofencing influenced a federal judge to toss a sheriff's Flock camera evidence in a drug trafficking case.
P0
2026-10-07 14:59 UTC
Community
SANS Internet Storm Center · indexed 2026-10-07 15:15 UTC
On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the web application's directory, potentially exposing sensitive information such as configuration files.
P5
2026-10-07 14:15 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-07 14:30 UTC
Southern Company is notifying customers that their utility account information was accessed by hackers. The post Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts appeared first on SecurityWeek.
P0
2026-10-07 14:03 UTC
Security Journalism
The Record · indexed 2026-10-07 14:10 UTC
The Operational Technology Cybersecurity Coalition released a white paper urging the CISA to create a new directive centered around operational technology, which is used to monitor and control critical infrastructure.
P0
2026-10-07 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Kaseya · indexed 2026-10-07 14:10 UTC
Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why organizations need isolated, immutable, and regularly tested backups that attackers cannot easily reach. [...]
P15
2026-10-07 13:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-07 14:30 UTC
FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out admins. The FBI and the U.S. Secret Service issued a joint advisory about FortiBleed, and the headline number alone is worth sitting with: more than 86,644 compromised Fortinet FortiGate devices across 194 countries, according to […]
P0
2026-10-07 13:49 UTC
Security Journalism
The Record · indexed 2026-10-07 14:10 UTC
The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for healthcare organizations.
P0
2026-10-07 13:48 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-10-07 13:55 UTC
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle "Rey," was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's…
P0
2026-10-07 13:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-07 13:50 UTC
The individual was detained in May and has been extradited to Germany to face hacking charges. The post Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany appeared first on SecurityWeek.
P15
2026-10-07 13:30 UTC
Security Journalism
The Record · indexed 2026-10-07 13:40 UTC
A report by a Labour MP and an academic argues that if the British public cannot see what Russian activity costs, it cannot weigh that burden against the cost of defending against it.
P0
2026-10-07 13:22 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-07 14:30 UTC
Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique, dressed up as Cloudflare’s standard bot check. The fake page asks you to run a command, supposedly to confirm you’re not a bot, and that command quietly downloads and installs an […]
P0
2026-10-07 13:06 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-07 13:10 UTC
Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers. The post Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform appeared first on SecurityWeek.
P0
2026-10-07 13:00 UTC
Security Journalism
Huntress · indexed 2026-10-07 13:10 UTC
A recent phishing campaign abused Microsoft Power BI links to deliver multiple rogue ScreenConnect clients.
P0
2026-10-07 12:50 UTC
Security Journalism
The Record · indexed 2026-10-07 13:10 UTC
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.
P0