home.social

Search

22 results for “beyondmachines1”

  1. South Korean Megachurches Investigate Suspected AI-Assisted Cyberattacks

    Yoido Full Gospel Church and Sarang Church are investigating cyberattacks that exposed personal and internal data linked to hundreds of thousands of members. Oasis Security found stolen data and attack records on an overseas server, including signs that AI tools may have supported parts of the intrusions.

    ****

    beyondmachines.net/event_detai

  2. Osaka Metropolitan University Suspends Classes Following Attack on 500 Servers

    Osaka Metropolitan University suspended classes and shut down 500 servers following a ransomware attack that potentially exposed the personal and financial data of 130,000 individuals. The university is working with law enforcement and cybersecurity specialists to restore systems and investigate the extent of the data breach.

    ****

    beyondmachines.net/event_detai

  3. GMO Research & AI Reports Data Breach Affecting 948,498 infoQ Members

    GMO Research & AI suffered a data breach affecting nearly 950,000 infoQ members after attackers exploited a software vulnerability to access the member database and steal reward points. The company suspended the service, hired a cybersecurity firm for investigation, and promised to reimburse affected users.

    ****

    beyondmachines.net/event_detai

  4. LibreOffice and OpenOffice Patch Critical Remote Code Execution Vulnerabilities

    LibreOffice and Apache OpenOffice patched several critical vulnerabilities, including a remote code execution flaw (CVE-2026-63277) that allows attackers to run malicious Java code via manipulated spreadsheet documents.

    **If you use LibreOffice, update it to version 26.2.5 or 26.8.0 ASAP, and until you do, don't open documents from unknown senders or unexpected sources. If you use Apache OpenOffice, there's no fix yet, so turn off Java in the program's options now and install version 4.1.17 as soon as it's released. Or better yet, switch to the patched LibreOffice.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  5. Google Releases October 2026 Android Security Bulletin Fixing 25 Vulnerabilities

    Google's October 2026 Android Security Bulletin resolves 25 vulnerabilities, including seven critical flaws that allow local privilege escalation and remote denial-of-service without user interaction.

    **If you have an Android phone or tablet, go to Settings > System update and check for the October 2026 security update. Google phones will receive the update first, for your vendor and model you need to wait for the appropriate vendor release.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  6. AWS Labs Patches Critical Authentication Bypass in Loom AI Agent Platform

    AWS Labs fixed a critical CVSS 10.0 vulnerability in Loom that allowed unauthenticated users to gain super-admin access to AI agent control planes. The update also patches SSRF and credential disclosure flaws.

    **If you use AWS Loom to manage AI agents, update to version 1.7.0 ASAP, because a public exploit lets anyone on the network take full control of it and your AWS environment. After updating, assume you may have been breached: rotate all OAuth2 secrets, access tokens and IAM credentials, and review CloudTrail logs for suspicious activity.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  7. ASOS Investigates Unauthorized App Notifications Following Snowflake Breach Claim

    ASOS is investigating a possible security incident after attackers used its official mobile app to send unauthorized extortion messages to customers. The group claims it compromised the retailer’s Snowflake environment, although ASOS has not confirmed that customer data was accessed or stolen.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  8. Restorative Therapies Discloses Data Breach as AiLock Claims 145GB Data Stolen

    Restorative Therapies disclosed a data breach involving medical records after the AiLock ransomware group claimed it stole 145GB of data from the company. The total number of affected individuals has not been publicly disclosed, and Restorative Therapies is offering complimentary identity monitoring through Kroll.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  9. Trump Mobile Customer Data Leaked as BYOD Claims Third-Party Compromise

    The BYOD cybercrime group published data reportedly linked to 3,615 Trump Mobile customers, including names, contact details, addresses, and order information. BYOD claims it gained access through a compromised Liberty Mobile employee, but Trump Mobile has not publicly confirmed the breach or the reported entry point.

    ****
    #cybersecurity #infosec #incident #ransomware
    beyondmachines.net/event_detai

  10. Southern Company Data Breach Affects Approximately 400,000 Utility Customer Accounts

    Southern Company disclosed a data breach affecting approximately 400,000 customer accounts after an unauthorized third party accessed information through its online portal. The affected information includes names, addresses, contact details, and the last four digits of Social Security numbers, and the company is offering complimentary credit monitoring to affected customers.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  11. Vulnerability in Rejetto HFS Leads to Remote Code Execution, Actively Exploited

    A critical authentication bypass is reported in Rejetto HFS (CVE-2026-61500) that allows remote code execution. Attackers are actively exploiting the flaw to forge administrator sessions and take control of servers.

    **If you run Rejetto HTTP File Server (versions 3.0.0 to 3.2.0), update to version 3.2.1 or later right away. Attackers are already using this flaw to take full control of servers. Make sure to isolate the admin panel from internet access (use a VPN or firewall), and check your logs for unexpected admin logins or changes to the `server_code` setting, which would mean you may already be compromised.**
    #cybersecurity #infosec #attack #activeexploit
    beyondmachines.net/event_detai

  12. Blackstone Inc. Reports Data Breach After Unauthorized Access to Cloud Repositories

    Blackstone Inc. disclosed a breach where attackers used stolen employee credentials to access cloud repositories and exfiltrate Social Security numbers and financial data.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  13. University of Illinois Chicago College of Medicine Hit by Booba Ransomware Attack

    The University of Illinois Chicago College of Medicine suffered a ransomware attack by the Booba Project, resulting in the claimed theft of 344 GB of personal, academic, and research data. Systems have been restored and patient care was not affected. The university is investigating the breach and plans to notify impacted individuals.

    ****
    #cybersecurity #infosec #incident #ransomware
    beyondmachines.net/event_detai

  14. Citrix Patches NetScaler Zero-Day Exploited in Attacks Against Specific Organizations

    Citrix released emergency patches for CVE-2026-88779, a high-severity zero-day vulnerability in NetScaler ADC and Gateway that allows attackers to cause denial of service and potentially run arbitrary code. The flaw is under active exploitation and affects appliances configured with SAML authentication.

    **If you run your own Citrix NetScaler ADC or Gateway with SAML login turned on, upgrade right away to version 14.1-73.41 or 13.1-64.28 (or later). Do this even if you already patched in September. Attackers are actively exploiting this flaw. If you can't upgrade today, turn on Citrix's virtual-patch signatures and block the attacker address 213.209.159.55 as a stopgap. Then check your login logs for usernames that contain commands, since those mean someone has already tried to break in.**
    #cybersecurity #infosec #attack #activeexploit
    beyondmachines.net/event_detai

  15. State of (in)security - Week 40, 2026

    In week 40 of 2026 (Sept. 28 - Oct. 5), incidents rose to 26 while advisories dipped to 15. The incidents exposed about 7.7 million individuals, led by attacks on Tokyo Metro and Times Car that alone affected 6.66 million. Unauthorized access and ransomware were the top causes, and healthcare was the hardest-hit sector. Several actively exploited zero-days also emerged that week, in Apple, Cisco, Fortinet, GitLab and Roundcube products, alongside critical flaws from vendors such as WatchGuard, Microsoft Exchange and Dell.

    **Update right away to the fixes for flaws already under attack: iPhone/iPad to iOS/iPadOS 26.7.1, Mac to macOS Tahoe 26.7.1 or Sequoia 15.8.1, Roundcube Webmail to 1.6.16 or 1.7.1, and self-hosted GitLab to its latest security release (AI Gateway 19.2.4, 19.3.2 or 19.4.1). Until Cisco Catalyst SD-WAN Manager, FortiMail and WatchGuard Firebox and access points are patched (WatchGuard access points to firmware 3.4.8), make sure their management interfaces can't be reached from the internet.**
    #cybersecurity #infosec #knowledge #weeklyreport
    beyondmachines.net/event_detai

  16. Ukraine Grocery Giant ATB Hit by DataSuckers Extortion Attack

    Ukraine's largest grocery chain, ATB-Market, suffered a cyberattack by the DataSuckers group, who defaced the company's website and demanded a $400,000 ransom. The attackers claim to have stolen data belonging to 7.9 million customers and over 127,000 employees. The company denies any data compromise.

    ****
    #cybersecurity #infosec #incident #ransomware
    beyondmachines.net/event_detai

  17. ZITADEL Authentication Bypass Cluster Exposes Self-Hosted Identity Providers

    ZITADEL reports ten vulnerabilities, including seven critical flaws, that allow unauthenticated attackers to bypass authentication and take over accounts. The issues affect versions 3.x and 4.x.

    **If you use ZITADEL to manage logins, update it ASAP to version 4.17.3, because ten new flaws let attackers take over accounts and bypass passwords and MFA without logging in. If you are still on version 3.x, it will never get a fix, so move to 4.x as soon as possible and check your users for unfamiliar linked logins, passkeys or authenticators.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  18. Denmark Population Registry Breach Exposes Data of 8.8 Million Registered Individuals

    Unauthorized individuals abused a private company’s legitimate access to Denmark’s Central Person Register to run automated searches and obtain names, addresses, and CPR numbers associated with approximately 8.8 million registered individuals. Authorities disabled the company’s access and launched an investigation into the breach.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  19. Bouncy Castle Patches Identity Binding Vulnerability in Messaging Layer Security Implementation

    Bouncy Castle for Java patched a critical identity binding vulnerability (CVE-2026-71885) in its Messaging Layer Security implementation that allows attackers to spoof user identities and decrypt private group messages.

    **If your apps or servers use Bouncy Castle for Java (including Android apps and enterprise Java frameworks), update to version 1.86 or later as soon as possible, because attackers can impersonate users and read secure group messages. Ask your developers to check that their apps properly verify certificates and identities all the way back to a trusted source.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  20. Fortra Patches Command Injection Flaw in BoKS Core PAM

    Fortra fixed a command injection vulnerability (CVE-2026-9862) in its BoKS Core PAM that allows unauthenticated remote code execution. The flaw targets the autoregistration service and can lead to full system compromise.

    **If you use Fortra BoKS Core 8.1 or 9.0, apply Fortra's security update ASAP. Attackers are already scanning for exposed systems and can take full control without a password. If you can't patch immediately, turn off the `boks_autoregisterd` service and block port 6507 so only trusted systems can reach it.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  21. ASUS Patches Critical Vulnerabilities in Router Firmware Triggered by Malicious VPN Files

    ASUS patched two vulnerabilities (CVE-2026-14157 and CVE-2026-13313) in its router firmware that allow authenticated attackers to execute arbitrary commands and gain root privileges via malicious VPN configuration files or active debug code.

    **If you have an ASUS router, update its firmware ASAP from the official ASUS support page, and make sure its admin page can only be reached from your trusted internal network, never from the internet. Only import VPN configuration files from providers you trust, and if your router is on ASUS's end-of-life list, plan to replace it since it will not be patched.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

Share on Mastodon

Enter the server where you have an account.