#cybersecuritynews — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cybersecuritynews, aggregated by home.social.
-
North Korean Hangro VPN Uses Identical Management Certificate on Pyongyang and Russian Servers
North Korea’s Hangro VPN and mail platform has deployed a new management certificate across infrastructure in Pyongyang and…
#EuropeSays #Korea #KR #Pyongyang #CyberSecurityNews
https://www.europesays.com/korea/165991/ -
SAP Security Patch Day Fixes 19 New Vulnerabilities Across NetWeaver, S/4HANA and Cloud Products
SAP has released 19 new Security Notes as part of its September 2026 Security Patch Day, addressing vulnerabilities…
#Germany #DE #Europe #EU #Europa #SAP #CyberSecurity #Cybersecuritynews #sap
https://www.europesays.com/germany/87944/ -
‼️ FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests
Source: https://cybersecuritynews.com/fortisandbox-vulnerability-access-sensitive-data/
The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS all share, and it has been assigned a CVSS v3.1 score of 8.9, placing it firmly in the high-severity category.
FortiSandbox is widely deployed across enterprise and government networks as an advanced threat detection appliance, using sandboxing techniques to analyze suspicious files and network traffic for zero-day malware and other advanced threats.
-
‼️ FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests
Source: https://cybersecuritynews.com/fortisandbox-vulnerability-access-sensitive-data/
The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS all share, and it has been assigned a CVSS v3.1 score of 8.9, placing it firmly in the high-severity category.
FortiSandbox is widely deployed across enterprise and government networks as an advanced threat detection appliance, using sandboxing techniques to analyze suspicious files and network traffic for zero-day malware and other advanced threats.
-
SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws
SAP released 19 new Security Notes addressing four critical vulnerabilities and 15 additional flaws throughout its enterprise portfolio.…
#Germany #DE #Europe #EU #Europa #SAP #CyberSecurity #Cybersecuritynews #sap #Vulnerability
https://www.europesays.com/germany/87522/ -
The EU Will Make You Report What It Hasn’t Yet Made You Fix
In eleven days, on September 11, manufacturers of products with digital elements sold into the European …
#Europe #EU #ComputerSecurity #cyberattacks #cybernews #Cybersecuritynews #cybersecuritynewstoday #cybersecurityupdates #cyberupdates #databreach #EuropeanUnion #hackernews #hackingnews #howtohack #informationsecurity #Networksecurity #ransomwaremalware #softwarevulnerability #thehackernews
https://www.europesays.com/europe/126878/ -
Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks
A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate reconnaissance, vulnerability…
#France #FR #Europe #EU #Hermès #cybersecurity #CyberSecurityNews
https://www.europesays.com/france/68444/ -
NSA and CISA Warn of Active Cyber Threat Targeting Siemens S7 PLCs
The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency have issued a joint cybersecurity advisory warning…
#Germany #DE #Europe #EU #Europa #Siemens #CyberSecurity #Cybersecuritynews #siemens
https://www.europesays.com/germany/76188/ -
iOS 26.6.1 & 18.7.10 Update: Fix iPhone Bugs Now
#TycoonWorld #iOS26 #iOS2661 #iOS18710 #Apple #AppleSecurity #iPhone #iPhoneUsers #iPhoneSecurity #iOSUpdate #AppleUpdate #SecurityUpdate #CyberSecurity #CybersecurityNews #WebKit #KernelSecurity #ImageIO #ZeroClickAttack #Spyware #MobileSecurity #AppleNews #TechNews #TechnologyNews #iPhoneUpdate #SoftwareUpdate #SecurityFlaws #Privacy #DigitalSecurity #CyberThreats #TechUpdates #LatestTechNews
https://tycoonworld.in/ios-security-update-warning-iphone-users/
-
iOS 26.6.1 & 18.7.10 Update: Fix iPhone Bugs Now
#TycoonWorld #iOS26 #iOS2661 #iOS18710 #Apple #AppleSecurity #iPhone #iPhoneUsers #iPhoneSecurity #iOSUpdate #AppleUpdate #SecurityUpdate #CyberSecurity #CybersecurityNews #WebKit #KernelSecurity #ImageIO #ZeroClickAttack #Spyware #MobileSecurity #AppleNews #TechNews #TechnologyNews #iPhoneUpdate #SoftwareUpdate #SecurityFlaws #Privacy #DigitalSecurity #CyberThreats #TechUpdates #LatestTechNews
https://tycoonworld.in/ios-security-update-warning-iphone-users/
-
iOS 26.6.1 & 18.7.10 Update: Fix iPhone Bugs Now
#TycoonWorld #iOS26 #iOS2661 #iOS18710 #Apple #AppleSecurity #iPhone #iPhoneUsers #iPhoneSecurity #iOSUpdate #AppleUpdate #SecurityUpdate #CyberSecurity #CybersecurityNews #WebKit #KernelSecurity #ImageIO #ZeroClickAttack #Spyware #MobileSecurity #AppleNews #TechNews #TechnologyNews #iPhoneUpdate #SoftwareUpdate #SecurityFlaws #Privacy #DigitalSecurity #CyberThreats #TechUpdates #LatestTechNews
https://tycoonworld.in/ios-security-update-warning-iphone-users/
-
iOS 26.6.1 & 18.7.10 Update: Fix iPhone Bugs Now
#TycoonWorld #iOS26 #iOS2661 #iOS18710 #Apple #AppleSecurity #iPhone #iPhoneUsers #iPhoneSecurity #iOSUpdate #AppleUpdate #SecurityUpdate #CyberSecurity #CybersecurityNews #WebKit #KernelSecurity #ImageIO #ZeroClickAttack #Spyware #MobileSecurity #AppleNews #TechNews #TechnologyNews #iPhoneUpdate #SoftwareUpdate #SecurityFlaws #Privacy #DigitalSecurity #CyberThreats #TechUpdates #LatestTechNews
https://tycoonworld.in/ios-security-update-warning-iphone-users/
-
Critical SAP Commerce Cloud RCE Vulnerability Actively Exploited in the Wild
Defused, a threat intelligence provider, reported exploitation attempts targeting CVE-2026-58231, a critical unauthenticated remote code execution vulnerability affecting…
#Germany #DE #Europe #EU #Europa #SAP #CyberSecurity #Cybersecuritynews #sap #Vulnerability
https://www.europesays.com/germany/73634/ -
We have updated https://www.valtersit.com/methodology/ with the actual information #CVE #Dokploy #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta
-
We have updated https://www.valtersit.com/methodology/ with the actual information #CVE #Dokploy #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta
-
We have updated https://www.valtersit.com/methodology/ with the actual information #CVE #Dokploy #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta
-
🤖💀 Anthropic's Mythos 5 didn't just solve a cyber test... it went rogue, contacted real people, and tried to plant malware in the wild. Here's what AISI found.
More Details: https://cybersecuritynews.com/mythos-5-and-gpt-5-6-sol-security-incident/
-
🤖💀 Anthropic's Mythos 5 didn't just solve a cyber test... it went rogue, contacted real people, and tried to plant malware in the wild. Here's what AISI found.
More Details: https://cybersecuritynews.com/mythos-5-and-gpt-5-6-sol-security-incident/
-
🚨 Telegram just VANISHED from the App Store worldwide — and nobody knows why. 👀
Source: https://cybersecuritynews.com/telegram-apples-app-store/
-
🚨 Telegram just VANISHED from the App Store worldwide — and nobody knows why. 👀
Source: https://cybersecuritynews.com/telegram-apples-app-store/
-
🚨 Claude didn’t escape with a zero-day. It walked out an open door — and hacked 3 real organizations during a “safe” security test.
Full Story: https://cybersecuritynews.com/claude-hacked-3-organizations/
-
🚨 Claude didn’t escape with a zero-day. It walked out an open door — and hacked 3 real organizations during a “safe” security test.
Full Story: https://cybersecuritynews.com/claude-hacked-3-organizations/
-
DEF CON, here we go again 🏴☠️
After a massive first edition, we're back to host OS Community for the second time at DEF CON 34 🎰
If you're curious about how OS internals work or looking to optimize your own security stack, this is where you want to be 💻
Learn more about OS Community 👉 https://oscommunity.org/
#ParrotSec #ParrotOS #defcon #defcon34 #hacker #hackers #hacking #cybersec #cybersecurity #cybersecuritynews #linux #linuxdistro
-
DEF CON, here we go again 🏴☠️
After a massive first edition, we're back to host OS Community for the second time at DEF CON 34 🎰
If you're curious about how OS internals work or looking to optimize your own security stack, this is where you want to be 💻
Learn more about OS Community 👉 https://oscommunity.org/
#ParrotSec #ParrotOS #defcon #defcon34 #hacker #hackers #hacking #cybersec #cybersecurity #cybersecuritynews #linux #linuxdistro
-
DEF CON, here we go again 🏴☠️
After a massive first edition, we're back to host OS Community for the second time at DEF CON 34 🎰
If you're curious about how OS internals work or looking to optimize your own security stack, this is where you want to be 💻
Learn more about OS Community 👉 https://oscommunity.org/
#ParrotSec #ParrotOS #defcon #defcon34 #hacker #hackers #hacking #cybersec #cybersecurity #cybersecuritynews #linux #linuxdistro
-
DEF CON, here we go again 🏴☠️
After a massive first edition, we're back to host OS Community for the second time at DEF CON 34 🎰
If you're curious about how OS internals work or looking to optimize your own security stack, this is where you want to be 💻
Learn more about OS Community 👉 https://oscommunity.org/
#ParrotSec #ParrotOS #defcon #defcon34 #hacker #hackers #hacking #cybersec #cybersecurity #cybersecuritynews #linux #linuxdistro
-
‼️Microsoft Teams, Entra ID, and Copilot all sit on Cosmos DB. A single flaw called CosmosEscape could have handed attackers the keys to all of them.
Vulnerability Details: https://cybersecuritynews.com/cosmosescape-vulnerability/
-
‼️Microsoft Teams, Entra ID, and Copilot all sit on Cosmos DB. A single flaw called CosmosEscape could have handed attackers the keys to all of them.
Vulnerability Details: https://cybersecuritynews.com/cosmosescape-vulnerability/
-
WhatsApp Adds End-to-End Encryption for Voice and Video Calls
Source: https://cybersecuritynews.com/whatsapp-end-to-end-encryption-for-calls/
WhatsApp has introduced a new set of calling features alongside expanded end-to-end encryption for voice and video communications, emphasizing its commitment to secure, cross-platform communication.
This update now allows users to make encrypted calls on WhatsApp Web, enabling them to initiate and receive calls directly from a browser without needing to install the desktop application. This encryption uses the same protocol found on WhatsApp's mobile and desktop platforms, preserving the confidentiality and integrity of real-time communications.
-
WhatsApp Adds End-to-End Encryption for Voice and Video Calls
Source: https://cybersecuritynews.com/whatsapp-end-to-end-encryption-for-calls/
WhatsApp has introduced a new set of calling features alongside expanded end-to-end encryption for voice and video communications, emphasizing its commitment to secure, cross-platform communication.
This update now allows users to make encrypted calls on WhatsApp Web, enabling them to initiate and receive calls directly from a browser without needing to install the desktop application. This encryption uses the same protocol found on WhatsApp's mobile and desktop platforms, preserving the confidentiality and integrity of real-time communications.
-
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors,…
#Germany #DE #Europe #EU #Europa #Siemens #CyberSecurity #Cybersecuritynews #siemens
https://www.europesays.com/germany/61969/ -
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors,…
#France #FR #Europe #EU #SchneiderElectric #cybersecurity #CyberSecurityNews
https://www.europesays.com/france/57397/ -
🛡️ Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers
Source: https://cybersecuritynews.com/bing-images-vulnerability/
Three critical remote code execution (RCE) vulnerabilities in Microsoft's infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file.
Bing's reverse image search could be tricked into fetching an attacker-controlled URL from its backend, a classic server-side request forgery (SSRF) pattern that on its own looked low-impact.
Researchers confirmed the fetch by observing outbound requests from Bing infrastructure carrying a bingbot/2.0 user agent, then noticed inconsistent HTTP 500 errors that hinted the backend was doing more than just retrieving an image.
-
🛡️ Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers
Source: https://cybersecuritynews.com/bing-images-vulnerability/
Three critical remote code execution (RCE) vulnerabilities in Microsoft's infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file.
Bing's reverse image search could be tricked into fetching an attacker-controlled URL from its backend, a classic server-side request forgery (SSRF) pattern that on its own looked low-impact.
Researchers confirmed the fetch by observing outbound requests from Bing infrastructure carrying a bingbot/2.0 user agent, then noticed inconsistent HTTP 500 errors that hinted the backend was doing more than just retrieving an image.
-
⚡️ Microsoft Confirms No Bloatware Ads in Windows 11; LG Disables McAfee Pop-ups
Source: https://cybersecuritynews.com/microsoft-confirms-no-bloatware-ads-windows-11/
Microsoft has moved quickly to shut down unwanted antivirus advertising after users discovered that connecting an LG monitor could silently install companion software and trigger a McAfee trial pop-up on Windows 11.
The issue surfaced when owners of premium LG displays reported that plugging in their monitors caused Windows Update to deliver the LG Monitor App Installer.
Once installed via the Microsoft Store path, the app later surfaced a McAfee trial promotion an unexpected ad experience on machines that had never requested antivirus software.
-
⚠️ Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
Source: https://cybersecuritynews.com/acrobat-extension-flaw-whatsapp-chats/
A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage no clicks, downloads, or credential theft required.
The flaw, dubbed “HermeticReader,” and officially tracked as CVE-2026-48294 with a CVSS score of 7.4. The bug is classified as a universal cross-site scripting (UXSS) issue that lets a malicious site bypass the browser’s same-origin policy and read data tied to a victim’s active session in another tab.
-
mcpwn has a new home 🏠
We’ve officially launched mcpwn.parrotsec.ai as the central hub for everything related to the project.
mcpwn is built to give your LLM a fully functional security toolbox, and the new website contains all the resources to make that happen.
#ParrotSec #ParrotOS #linux #linuxdistro #cybersec #cybersecuritynews #pentest #hacking #hackers #mcp #llm
-
mcpwn has a new home 🏠
We’ve officially launched mcpwn.parrotsec.ai as the central hub for everything related to the project.
mcpwn is built to give your LLM a fully functional security toolbox, and the new website contains all the resources to make that happen.
#ParrotSec #ParrotOS #linux #linuxdistro #cybersec #cybersecuritynews #pentest #hacking #hackers #mcp #llm
-
mcpwn has a new home 🏠
We’ve officially launched mcpwn.parrotsec.ai as the central hub for everything related to the project.
mcpwn is built to give your LLM a fully functional security toolbox, and the new website contains all the resources to make that happen.
#ParrotSec #ParrotOS #linux #linuxdistro #cybersec #cybersecuritynews #pentest #hacking #hackers #mcp #llm
-
🎉✨ Breaking news: MSI's latest feature gives SYSTEM privileges to anyone with a laptop and five seconds to spare! 🙄 Apparently, cybersecurity is so last year, and MSI has decided to revolutionize the industry by making hackers' jobs effortless. Kudos, MSI – you've truly set a new standard in unintentional tech comedy! 😂👏
https://mrbruh.com/msicenter/ #MSIsecurityfail #techcomedy #cybersecuritynews #hackernews #HackerNews #ngated -
🎉✨ Breaking news: MSI's latest feature gives SYSTEM privileges to anyone with a laptop and five seconds to spare! 🙄 Apparently, cybersecurity is so last year, and MSI has decided to revolutionize the industry by making hackers' jobs effortless. Kudos, MSI – you've truly set a new standard in unintentional tech comedy! 😂👏
https://mrbruh.com/msicenter/ #MSIsecurityfail #techcomedy #cybersecuritynews #hackernews #HackerNews #ngated -
🎉✨ Breaking news: MSI's latest feature gives SYSTEM privileges to anyone with a laptop and five seconds to spare! 🙄 Apparently, cybersecurity is so last year, and MSI has decided to revolutionize the industry by making hackers' jobs effortless. Kudos, MSI – you've truly set a new standard in unintentional tech comedy! 😂👏
https://mrbruh.com/msicenter/ #MSIsecurityfail #techcomedy #cybersecuritynews #hackernews #HackerNews #ngated -
⚠️ Apple ‘Hide My Email’ Vulnerability Exposes Users' Real Email Addresses
Source: https://cybersecuritynews.com/apple-hide-my-email-vulnerability/
Apple’s “Hide My Email” feature is currently affected by an unpatched vulnerability that allows attackers to discover the real email address behind an anonymized alias. Apple’s Hide My Email, part of iCloud+, generates unique relay addresses intended to keep a user’s primary inbox private during sign‑ups and app registrations.
A flaw in this mechanism enables almost anyone with limited technical skill to uncover the underlying real email address that should remain hidden.
-
Anthropic's Claude Code Reportedly Uses Hidden Code to Detect Chinese Users
Source: https://cybersecuritynews.com/anthropic-claude-hidden-code/
A Reddit user detailed findings on June 30, 2026, claiming to have reverse-engineered Claude Code while attempting to restore a disabled remote control feature in version 2.1.196. During that process, he discovered obfuscated code that had been silently present since version 2.1.91, released on April 2, 2026, with no mention in the release notes.
According to the disclosure, the code performs a multi-factor check whenever a proxy is detected. It reads the system's timezone to determine whether it matches Asia/Shanghai or Asia/Urumqi, and simultaneously inspects the proxy URL against a hardcoded list of Chinese domains and known Chinese AI lab hostnames.
-
🛡️ Multiple AirDrop & Quick Share Vulnerabilities Allow Attackers to Crash Devices
Source: https://cybersecuritynews.com/airdrop-and-quick-share-vulnerabilities/
Multiple newly disclosed vulnerabilities in Apple’s AirDrop and Google/Samsung Quick Share proximity-sharing protocols allow attackers within wireless range to crash or disrupt nearby devices without user interaction repeatedly.
A systematic reverse-engineering and protocol-aware fuzzing study of AirDrop and Quick Share across macOS, iOS, Android, and Windows. Their research uncovered six distinct issues, several of which enable remote denial-of-service (DoS) attacks by crashing critical system daemons responsible for file-sharing and continuity features.
-
BREAKING: In response to a request for comment, 313 Team told me:
We are part of Beamed, and Beamed is part of 313 Team.
Beamed denied this.
They told me they dislike Zionists and "islamic haters", but do not support terrorism or use of their service for criminal activity.I reached out to 313 Team about Beamed's denial, and am awaiting a response.
-
BREAKING: In response to a request for comment, 313 Team told me:
We are part of Beamed, and Beamed is part of 313 Team.
Beamed denied this.
They told me they dislike Zionists and "islamic haters", but do not support terrorism or use of their service for criminal activity.I reached out to 313 Team about Beamed's denial, and am awaiting a response.