home.social

BeyondMachines :verified: bot

Enabling Good Cybersecurity for Everyone:
Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes.
Because cybersecurity shouldn't be an enterprise feature.

Sometimes a bot, sometimes not.

Posts
9,504
Followers
2,475
Following
707
Joined 2023-05-22 · View on infosec.exchange →
  1. ASOS Investigates Unauthorized App Notifications Following Snowflake Breach Claim

    ASOS is investigating a possible security incident after attackers used its official mobile app to send unauthorized extortion messages to customers. The group claims it compromised the retailer’s Snowflake environment, although ASOS has not confirmed that customer data was accessed or stolen.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  2. Restorative Therapies Discloses Data Breach as AiLock Claims 145GB Data Stolen

    Restorative Therapies disclosed a data breach involving medical records after the AiLock ransomware group claimed it stole 145GB of data from the company. The total number of affected individuals has not been publicly disclosed, and Restorative Therapies is offering complimentary identity monitoring through Kroll.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  3. Trump Mobile Customer Data Leaked as BYOD Claims Third-Party Compromise

    The BYOD cybercrime group published data reportedly linked to 3,615 Trump Mobile customers, including names, contact details, addresses, and order information. BYOD claims it gained access through a compromised Liberty Mobile employee, but Trump Mobile has not publicly confirmed the breach or the reported entry point.

    ****
    #cybersecurity #infosec #incident #ransomware
    beyondmachines.net/event_detai

  4. Southern Company Data Breach Affects Approximately 400,000 Utility Customer Accounts

    Southern Company disclosed a data breach affecting approximately 400,000 customer accounts after an unauthorized third party accessed information through its online portal. The affected information includes names, addresses, contact details, and the last four digits of Social Security numbers, and the company is offering complimentary credit monitoring to affected customers.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  5. Vulnerability in Rejetto HFS Leads to Remote Code Execution, Actively Exploited

    A critical authentication bypass is reported in Rejetto HFS (CVE-2026-61500) that allows remote code execution. Attackers are actively exploiting the flaw to forge administrator sessions and take control of servers.

    **If you run Rejetto HTTP File Server (versions 3.0.0 to 3.2.0), update to version 3.2.1 or later right away. Attackers are already using this flaw to take full control of servers. Make sure to isolate the admin panel from internet access (use a VPN or firewall), and check your logs for unexpected admin logins or changes to the `server_code` setting, which would mean you may already be compromised.**
    #cybersecurity #infosec #attack #activeexploit
    beyondmachines.net/event_detai

  6. Blackstone Inc. Reports Data Breach After Unauthorized Access to Cloud Repositories

    Blackstone Inc. disclosed a breach where attackers used stolen employee credentials to access cloud repositories and exfiltrate Social Security numbers and financial data.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  7. University of Illinois Chicago College of Medicine Hit by Booba Ransomware Attack

    The University of Illinois Chicago College of Medicine suffered a ransomware attack by the Booba Project, resulting in the claimed theft of 344 GB of personal, academic, and research data. Systems have been restored and patient care was not affected. The university is investigating the breach and plans to notify impacted individuals.

    ****
    #cybersecurity #infosec #incident #ransomware
    beyondmachines.net/event_detai

  8. Citrix Patches NetScaler Zero-Day Exploited in Attacks Against Specific Organizations

    Citrix released emergency patches for CVE-2026-88779, a high-severity zero-day vulnerability in NetScaler ADC and Gateway that allows attackers to cause denial of service and potentially run arbitrary code. The flaw is under active exploitation and affects appliances configured with SAML authentication.

    **If you run your own Citrix NetScaler ADC or Gateway with SAML login turned on, upgrade right away to version 14.1-73.41 or 13.1-64.28 (or later). Do this even if you already patched in September. Attackers are actively exploiting this flaw. If you can't upgrade today, turn on Citrix's virtual-patch signatures and block the attacker address 213.209.159.55 as a stopgap. Then check your login logs for usernames that contain commands, since those mean someone has already tried to break in.**
    #cybersecurity #infosec #attack #activeexploit
    beyondmachines.net/event_detai

  9. State of (in)security - Week 40, 2026

    In week 40 of 2026 (Sept. 28 - Oct. 5), incidents rose to 26 while advisories dipped to 15. The incidents exposed about 7.7 million individuals, led by attacks on Tokyo Metro and Times Car that alone affected 6.66 million. Unauthorized access and ransomware were the top causes, and healthcare was the hardest-hit sector. Several actively exploited zero-days also emerged that week, in Apple, Cisco, Fortinet, GitLab and Roundcube products, alongside critical flaws from vendors such as WatchGuard, Microsoft Exchange and Dell.

    **Update right away to the fixes for flaws already under attack: iPhone/iPad to iOS/iPadOS 26.7.1, Mac to macOS Tahoe 26.7.1 or Sequoia 15.8.1, Roundcube Webmail to 1.6.16 or 1.7.1, and self-hosted GitLab to its latest security release (AI Gateway 19.2.4, 19.3.2 or 19.4.1). Until Cisco Catalyst SD-WAN Manager, FortiMail and WatchGuard Firebox and access points are patched (WatchGuard access points to firmware 3.4.8), make sure their management interfaces can't be reached from the internet.**
    #cybersecurity #infosec #knowledge #weeklyreport
    beyondmachines.net/event_detai

  10. Ukraine Grocery Giant ATB Hit by DataSuckers Extortion Attack

    Ukraine's largest grocery chain, ATB-Market, suffered a cyberattack by the DataSuckers group, who defaced the company's website and demanded a $400,000 ransom. The attackers claim to have stolen data belonging to 7.9 million customers and over 127,000 employees. The company denies any data compromise.

    ****
    #cybersecurity #infosec #incident #ransomware
    beyondmachines.net/event_detai

  11. ZITADEL Authentication Bypass Cluster Exposes Self-Hosted Identity Providers

    ZITADEL reports ten vulnerabilities, including seven critical flaws, that allow unauthenticated attackers to bypass authentication and take over accounts. The issues affect versions 3.x and 4.x.

    **If you use ZITADEL to manage logins, update it ASAP to version 4.17.3, because ten new flaws let attackers take over accounts and bypass passwords and MFA without logging in. If you are still on version 3.x, it will never get a fix, so move to 4.x as soon as possible and check your users for unfamiliar linked logins, passkeys or authenticators.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  12. Denmark Population Registry Breach Exposes Data of 8.8 Million Registered Individuals

    Unauthorized individuals abused a private company’s legitimate access to Denmark’s Central Person Register to run automated searches and obtain names, addresses, and CPR numbers associated with approximately 8.8 million registered individuals. Authorities disabled the company’s access and launched an investigation into the breach.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  13. Bouncy Castle Patches Identity Binding Vulnerability in Messaging Layer Security Implementation

    Bouncy Castle for Java patched a critical identity binding vulnerability (CVE-2026-71885) in its Messaging Layer Security implementation that allows attackers to spoof user identities and decrypt private group messages.

    **If your apps or servers use Bouncy Castle for Java (including Android apps and enterprise Java frameworks), update to version 1.86 or later as soon as possible, because attackers can impersonate users and read secure group messages. Ask your developers to check that their apps properly verify certificates and identities all the way back to a trusted source.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  14. Fortra Patches Command Injection Flaw in BoKS Core PAM

    Fortra fixed a command injection vulnerability (CVE-2026-9862) in its BoKS Core PAM that allows unauthenticated remote code execution. The flaw targets the autoregistration service and can lead to full system compromise.

    **If you use Fortra BoKS Core 8.1 or 9.0, apply Fortra's security update ASAP. Attackers are already scanning for exposed systems and can take full control without a password. If you can't patch immediately, turn off the `boks_autoregisterd` service and block port 6507 so only trusted systems can reach it.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  15. ASUS Patches Critical Vulnerabilities in Router Firmware Triggered by Malicious VPN Files

    ASUS patched two vulnerabilities (CVE-2026-14157 and CVE-2026-13313) in its router firmware that allow authenticated attackers to execute arbitrary commands and gain root privileges via malicious VPN configuration files or active debug code.

    **If you have an ASUS router, update its firmware ASAP from the official ASUS support page, and make sure its admin page can only be reached from your trusted internal network, never from the internet. Only import VPN configuration files from providers you trust, and if your router is on ASUS's end-of-life list, plan to replace it since it will not be patched.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  16. Wakacje.pl Data Breach Exposes Customer Passport Details and Personal Information

    Wakacje.pl suffered a data breach on September 29, 2026, after attackers gained access to corporate email accounts and customer service systems. The incident exposed sensitive personal data, including passport details, for a limited group of customers.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  17. Welcome Savings Bank Confirms Data Breach Affecting 2,200 Corporate Clients

    Welcome Savings Bank in South Korea confirmed a data breach affecting 2,200 corporate client records after a hacking attack on its internal systems. The bank reported the incident to financial authorities and is currently investigating the scope of the data leak.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  18. Hyundai Capital Data Breach Exposes National ID Numbers of 146 Loan Agents

    Hyundai Capital suffered an information-scraping attack on a public agent-verification portal, resulting in the exposure of sensitive personal data, including national ID numbers, for 146 housing-loan agents. The company blocked the attacking IP, isolated the affected systems and notified regulators.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  19. Roundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation

    Roundcube Webmail high-severity SQL injection vulnerability (CVE-2026-48842) in its virtuser_query plugin is being actively exploited, allowing unauthenticated attackers to compromise databases and steal sensitive email data.

    **If you run Roundcube Webmail (common in cPanel and other web hosting), update immediately to version 1.6.16 or 1.7.1. The flaw is actively exploited to steal mail, passwords and accounts. If you can't update right away, disable the `virtuser_query` plugin, and check your database logs for anything unusual, since you may already have been breached.**
    #cybersecurity #infosec #attack #activeexploit
    beyondmachines.net/event_detai

Share on Mastodon

Enter the server where you have an account.