CERT-Bund
[UPDATE] [mittel] vim: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in vim ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.
Stories tagged security.
CERT-Bund
Ein Angreifer kann mehrere Schwachstellen in vim ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.
CERT-Bund
Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen…
Europe/UK: Tech.eu / Sifted / TNW / Silicon Republic / UKTN / Computer Weekly / heise / Golem / t3n / Maddyness / FrenchWeb
'Our models took actions we did not intend,' an OpenAI spokesperson said. Read more: OpenAI takes weeks to tell Australia about Medicare breach

ransomware.live
Arizona Vascular Medical Equipment, Inc. is a trusted provider of specialized medical devices, focusing primarily on compression therapy solutions and vascular care equipment. Headquartered in Mesa, Arizona, the company is dedicated to improving patient mobility and quality of life by delivering…
CyberScoop
New federal programs take years to launch and fund. State and local governments need cybersecurity software now. The One Big Beautiful Bill already enables tax incentives. Congress should clarify and deploy them. The post How tax policy can stop threat actors from breaching US water systems…

American Banker (headlines)
The share of American households considered "financially vulnerable" rose to 17%, the highest level since at least 2018, according to the nonprofit Financial Health Network.
CERT-Bund
Ein Angreifer kann mehrere Schwachstellen in Google Android ausnutzen, um beliebigen Code auszuführen, Berechtigungen zu erweitern, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.

ransomware.live
BMGP Groupe (Polyresine) is an established French manufacturer specializing in the formulation, production, and distribution of synthetic resins and high-performance technical polymers. Founded in 1972, the company serves a wide range of industrial sectors, providing tailored chemical formulations…

ransomware.live
Elite Industech Co., Ltd. (established in 2003) is a certified Class-A waste treatment plant based in Kaohsiung, Taiwan. The company operates within the circular economy sector, specializing in the eco-friendly processing of electronic waste (E-waste) and the recycling of rare and precious metals

ransomware.live
On August 30, HEC Group issued an official statement addressed to shareholders of TPE:3032 and other stakeholders, announcing that the company had been the target of a cyberattack. In its statement, the company claimed that the breach was detected immediately, that high-tech countermeasures were…
SecurityWeek
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.
CERT-Bund
Ein Angreifer kann mehrere Schwachstellen in Apache Sling ausnutzen, um einen Denial of Service Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.
CERT-Bund
Ein Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen und um Daten zu manipulieren.
Help Net Security
A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found. Researchers confirmed that the malware targets customers of more than 30 banks in Italy, France, Spain, Poland, Portugal, Canada…
BleepingComputer
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]
Help Net Security
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections normally associated with on-device processing. Private AI Compute is Google’s cloud platform for processing sensitive data with…

Phys.org / ScienceDaily (tech)
A rogue OpenAI model bypassed safeguards during training and hacked an Australian government website, Prime Minister Anthony Albanese said as he admonished the ChatGPT creator over an "obviously unacceptable" breach.

The Hacker News
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a…

ransomware.live
Good afternoon, We have no further comments to make regarding our PSA statement we released the other day. Our organisation is highly confident we have achieved our goal and our intentions we repeatedly made clear to journalists and in our public statements. There is 5 days remaining still. We have…
SecurityWeek
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.

Cointelegraph
OpenAI notified Australia nearly three months after its agent breached a government portal while gathering public medicine-spending data.

The Block
A court sentenced 23-year-old Ronald Spektor to four to 12 years in prison for a $15.9 million Coinbase phishing scheme.
Help Net Security
GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany web browser and a use-after-free bug in the librsvg image library. The release updates 22 modules. Users who browse with Epiphany, view SVG…
BleepingComputer
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]
Help Net Security
Apple introduced a scam-prevention feature called Impersonation Risk Detection with iOS 27 and iPadOS 27. The feature allows supported apps to request a risk assessment when a user takes an action that could be connected to an active social engineering scam. “Impersonation Risk Detection helps…
Help Net Security
Anthropic engineers made claude.ai and the Claude desktop app roughly three times faster during a two-week sprint in August, with Claude finding the bottlenecks and writing the fixes. The team merged more than 3,000 changes and says none of them caused a customer-facing incident or rollback. The…
Economic Times — Tech / Technology / Startups / ETTelecom
Australian PM Anthony Albanese said an OpenAI agent breached a government health website in July, accessing non-public Medicare data. Australia has launched an inquiry into the incident, including OpenAI’s delayed disclosure and how the breach went undetected.
Actively exploitedCritical 85JPCERT
SecurityWeek
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek.
CERT-Bund
Ein Angreifer kann mehrere Schwachstellen in Microsoft Office Produkte ausnutzen, um Dateien zu manipulieren, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.