CERT
WIEDZA Z SIECI
Newsy
Talos
Securing the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.Czytaj całość ↵Źródło — otwiera w nowej karcieCERT
Vulnerabilities in Alior Bank "raty" module for PrestaShop
CERT Polska has received a report about 2 SQL Injection vulnerabilities (CVE-2026-7848 and CVE-2026-15600) found in Alior Bank "raty" module for PrestaShop.Czytaj całość ↵Źródło — otwiera w nowej karcieTalos
We've got one word for it, and it's usually the wrong one
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.Czytaj całość ↵Źródło — otwiera w nowej karcieCERT
Vulnerability in drEryk Gabinet software
Use of Hard-coded Credentials vulnerability (CVE-2026-17038) has been found in drEryk Gabinet software.Czytaj całość ↵Źródło — otwiera w nowej karcieTalos
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.Czytaj całość ↵Źródło — otwiera w nowej karcieTalos
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Czytaj całość ↵Źródło — otwiera w nowej karciekrebs
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.Czytaj całość ↵Źródło — otwiera w nowej karcieTalos
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.Czytaj całość ↵Źródło — otwiera w nowej karcieTalos
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.Czytaj całość ↵Źródło — otwiera w nowej karcieproject zero
Testing race conditions with memory access tracing and stack-based delay injection
Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have been discovered manually or through static analysis. Regression tests: After fixing a race condition bug, there is often no good way to write a regression test that reliably triggers the bug as part of a test suite. Automatic bug discovery, such as fuzzing: It is hard for a fuzzer to exercise all interesting interleavings of concurrent operations, or reach code paths th…Czytaj całość ↵Źródło — otwiera w nowej karcieCERT
Vulnerabilities in Mikrotik RouterOS software
CERT Polska has found 6 vulnerabilities (from CVE-2026-67276 to CVE-2026-67279, CVE-2026-67281 and CVE-2026-86060) in Mikrotik RouterOS software.Czytaj całość ↵Źródło — otwiera w nowej karcieCERT
Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended
The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from the internet. We recommend immediately updating devices to the patched versions and verifying the configuration for signs of compromise.Czytaj całość ↵Źródło — otwiera w nowej karcieTalos
The story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.Czytaj całość ↵Źródło — otwiera w nowej karcieCERT
Vulnerability in OptimiDoc Server (On-Premise) software
Plaintext Storage of a Password vulnerability (CVE-2026-15933) has been found in OptimiDoc Server (On-Premise) software.Czytaj całość ↵Źródło — otwiera w nowej karciekrebs
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.Czytaj całość ↵Źródło — otwiera w nowej karcieTalos
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.Czytaj całość ↵Źródło — otwiera w nowej karcieCERT
Vulnerabilities in dool software
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-56651 and CVE-2026-56652) found in dool software.Czytaj całość ↵Źródło — otwiera w nowej karciekrebs
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old sus…Czytaj całość ↵Źródło — otwiera w nowej karcieTalos