| Date | Area | Title | Description | Source |
|---|---|---|---|---|
|
Must read
IAM
|
McKesson discloses breach after ShinyHunters claims patient data theft | Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...] | BleepingComputerEditorial | |
|
Must read
Critical vulns
|
PaperCut releases second emergency patch for exploited flaws | PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...] | BleepingComputerEditorial | |
|
Must read
Critical vulns
|
Over 8,300 Gitea servers vulnerable to code execution attacks | Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...] | BleepingComputerEditorial | |
|
Must read
DS
|
Toy-making giant Hasbro disclose data breach affecting employees | Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...] | BleepingComputerEditorial | |
|
Must read
Critical vulns
|
ServiceNow warns of three max severity security vulnerabilities | ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...] | BleepingComputerEditorial | |
|
Must read
Market activity
|
White House bans foreign-made equipment for power generation over cyber backdoor concerns | The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology. | The RecordEditorial | |
|
Must read
Market activity
|
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others | The arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software. | TechCrunch SecurityEditorial | |
|
Must read
Market activity
|
CISA confirms hackers targeted over 100 US water systems during July | The federal cyber agency's warning comes amid a wave of suspected Iran-backed cyberattacks targeting critical water systems across the United States. | TechCrunch SecurityEditorial | |
|
Must read
ES
|
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution | Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42 . | Palo Alto Unit 42First party research | |
|
Must read
ES
|
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain | Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42 . | Palo Alto Unit 42First party research | |
|
Must read
DS
|
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants | The private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies. | TechCrunch SecurityEditorial | |
|
Must read
Market activity
|
AI data giant Alation confirms cyberattack | The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach. | TechCrunch SecurityEditorial | |
|
Must read
Market activity
|
US says hackers are targeting vulnerable water systems with the help of AI | Hackers are targeting internet-connected Siemens controllers used in water facilities around the United States. | TechCrunch SecurityEditorial | |
|
Must read
Market activity
|
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | The U.S. phone provider escaped a large-scale breach of its network after identifying Chinese-backed hackers early on. | TechCrunch SecurityEditorial | |
|
Must read
SC
|
Terabytes of credentials leaked in massive supply-chain attack | The data was scraped and exfiltrated from 2,500 users of a compromised AI package. | Ars Technica Technology LabEditorial | |
|
Must read · Urgent
Critical vulns
|
Microsoft Plugs Nearly 400 Security Holes | Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. | Krebs on SecurityEditorial | |
|
Watch
Critical vulns
|
GiveWP WordPress donation plugin flaw lets hackers execute server commands | A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...] | BleepingComputerEditorial | |
|
Watch
Critical vulns
|
CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent | Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devices, on-premises servers, and virtual machines (VMs). Amazon-ssm-agent makes it possible for Systems Manager to update, manage, and configure these resources. We identified CVE-2026-81849, where an improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code) | Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT Description: awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the intended cache directory, to any path writable by the user running awsdac. Depending on the file written… | AWS Security BulletinsPrimary | |
|
Watch
Market activity
|
More Americans oppose police license plate cameras than support them: survey | The backlash against license plate readers comes amid a wave of police abuses of surveillance cameras. | TechCrunch SecurityEditorial | |
|
Watch
Critical vulns
|
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up? | AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...] | BleepingComputerEditorial | |
|
Watch
SC
|
Authorities arrest 2 alleged members of prolific hacking group TeamPCP | The group infected more than 1,000 organizations in a relentless supply-chain attack campaign. | Ars Technica Technology LabEditorial | |
|
Watch
AI Sec
|
Nearly 700 rogue AI agents coordinated in the Hugging Face attack | New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...] | BleepingComputerEditorial | |
|
Watch
Market activity
|
ATF declares ‘major incident’ as ransomware gang claims hack | The ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity. | TechCrunch SecurityEditorial | |
|
Watch
Critical vulns
|
PaperCut warns of NG, MF flaw exploited in zero-day attacks | PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...] | BleepingComputerEditorial | |
|
Watch
Market activity
|
Here’s all the times AI has gone rogue and hacked other companies | A recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet. | TechCrunch SecurityEditorial | |
|
Watch
AI Sec
|
Claude, Codex, and Hermes installed unowned code inside corporate networks | 227 install commands were found in corporate docs pointing at code nobody owns. | Ars Technica Technology LabEditorial | |
|
Watch
AI Sec
|
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face | Without authorization, 1,200 OpenAI agents conspired among themselves to game a test. | Ars Technica Technology LabEditorial | |
|
Watch
SC
|
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia | Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old su… | Krebs on SecurityEditorial | |
|
Watch
AI Sec
|
AI agents meant to replace Meta workers made “large-scale, disruptive actions” | Report shows Meta's challenges replacing people with AI agents. | Ars Technica Technology LabEditorial | |
|
Watch
Market activity
|
Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations | The company won't say if medical devices are affected or if any customer data was exfiltrated. | TechCrunch SecurityEditorial | |
|
Watch
Market activity
|
US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate | The Justice Department said that the domain seizures made the botnet and its command and control servers "inoperable," as the domains were hardcoded into the botnet's code and were critical for the botnet's communication and essential operations. | TechCrunch SecurityEditorial | |
|
Watch
SC
|
CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool | Bulletin ID: 2026-089-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/25/2026 12:00 PM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the python_repl tool, which executes Python code on the agent's host, and the batch tool, which invokes several other tools in a single call. Before executing code, python_repl prompts the operator for approval. We identified CVE-2026-78379, a consent bypass in the python_repl tool. Improper… | AWS Security BulletinsPrimary | |
|
Watch
Market activity
|
That fake Grand Theft Auto VI demo is actually just malware | Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack. | TechCrunch SecurityEditorial | |
|
Watch
Cloud/SaaS
|
Apple rescues Hide My Email feature from the privacy scrap heap | Apple says it will no longer ditch using its icloud.com domain for hiding people's email addresses. | TechCrunch SecurityEditorial | |
|
Watch
Market activity
|
WhatsApp tightens account security with stronger two-step verification and more | WhatsApp’s two-step verification previously relied on a six-digit PIN, but now users can choose a longer, alphanumeric password with special characters. | TechCrunch SecurityEditorial | |
|
Watch
Market activity
|
Alabama launches investigation into OpenAI’s hack of Hugging Face | Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s attorney general announced an investigation into the incident. | TechCrunch SecurityEditorial | |
|
Watch
Market activity
|
Instinct’s powerful AI assistant is raising privacy and security concerns | Early testers are raving about what Instinct can do, but some say the AI assistant’s sweeping access, broad terms and ability to act on users’ behalf come with uncomfortable trade-offs. | TechCrunch SecurityEditorial | |
|
Watch
Market activity
|
Frontier AI labs still won’t say how they’d contain a rogue model | A new study finds leading AI labs have few publicly documented plans for containing rogue models, raising questions about preparedness as AI systems increasingly demonstrate unexpected and potentially dangerous behavior. | TechCrunch SecurityEditorial | |
|
Watch
ES
|
CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards | Bulletin ID: 2026-088-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 13:00 PM PDT Description: Amazon OpenSearch Service is a managed service that makes it easy to deploy, operate, and scale OpenSearch clusters. We identified CVE-2026-77811, a stored cross-site scripting issue in the dashboards-observability plugin in OpenSearch Dashboards. Improper input validation in the integrations static file endpoint allows a remote authenticated actor with write permissions to OpenSearch Dashboards saved objects to upload a custom integration containing arbitra… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector | Bulletin ID: 2026-087-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 12:30 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-77810, in the Neptune connector where a user… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237 | Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small microprocessors. AWS identified four issues with FreeRTOS-Kernel, affecting multiple versions. - CVE-2026-77234: This issue affects configurations that use the FreeRTOS MPU together with software timers; applications that do not use the FreeRTOS MPU are not affected. - CVE-2026-77235: This issue affects ARM TrustZone (ARMv8-M) configurations; applications that do not use AR… | AWS Security BulletinsPrimary | |
|
Watch
GRC
|
Waymo doubles spending on lobbying in robotaxi battle with Uber | Alphabet-owned company is seeking to persuade US regulators to clear a path for fully autonomous taxi services. | Ars Technica Technology LabEditorial | |
|
Watch
Market activity
|
Senator asks US government watchdog to review how feds use hacking tools | Senator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans. | TechCrunch SecurityEditorial | |
|
Watch
ES
|
CVE-2026-16317 and CVE-2026-16318: Issues with s2n-tls: an open-source implementation of the TLS/SSL protocols | Bulletin ID: 2026-062-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/21/2026 13:15 PM PDT Description: s2n-tls is an open source C99 implementation of the TLS/SSL protocol. We have identified two distinct issues: - CVE-2026-16317: Silent Drop of TLS 1.3 Encrypted Records in s2n-tls Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently drop individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer content… | AWS Security BulletinsPrimary | |
|
Watch
ES
|
CVE-2026-15737 - Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK | Bulletin ID: 2026-058-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/16/2026 10:15 AM PDT Description: Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. We identified CVE-2026-15737 in the OpenTelemetry instrumentation of the SDK. Affected versions wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWat… | AWS Security BulletinsPrimary | |
|
Watch
ES
|
CVE-2026-4269 - Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit | Bulletin ID: 2026-008-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/16 11:15 AM PDT Description: A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. Impacted versions: All versions of Bedrock AgentCore Starter Toolkit versions before v0.1.13. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build the Toolkit after September 24, 2025. Any user… | AWS Security BulletinsPrimary | |
|
Watch
ES
|
CVE-2026-11393 - Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import | Bulletin ID: 2026-040-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/08/2026 11:45 AM PDT Description: The AWS AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. We identified CVE-2026-11393 in which improper neutralization of triple-quote characters during Python code generation may allow an authenticated user in the same AWS account to inject arbitrary Python code into the source file generated by the "agentcore add agent ‐‐type import" command. Specifically, the collaborationInstructi… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-15895: OS command injection in jsii-diff in AWS jsii | Bulletin ID: 2026-057-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 12:00 PM PDT Description: jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. We identified CVE-2026-15895, an issue where specially formatted command line arguments can be used to execute shell commands via this tool. Impacted versions: < 1.131.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP | Bulletin ID: 2026-022-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:20 PM PDT Description: FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424, where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware reset). Impacted versions: FreeRTOS-Plus-TCP >=V4.0.0 AND <=V4.2.5, >=V4.3.0 AND <= V4.4.0 Please refer t… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-12043 - Heap double-free in AWS Common Runtime aws-c-http | Bulletin ID: 2026-043-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/12/2026 11:45 AM PDT Description: AWS Common Runtime aws-c-http is a HTTP client library used by AWS SDKs for handling http requests to AWS services. We identified CVE-2026-12043, an issue where improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS fra… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin | Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT Description: OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-19311, a missing authorization issue in the Execute Monitor API of the OpenSearch Alerting plugin. This issue may allow an authenticated user with the alerting_full_access role to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters. Impacted versions: OpenSearch Alerting Plugi… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
Dirty Frag and other issues in Amazon Linux kernels | Bulletin ID: 2026-027-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/07 19:45 PM PDT Description: Amazon is aware of a class of issues in the Linux kernel related to the original issue (CVE-2026-31431). The issues commonly referred to as "DirtyFrag" are present in a number of loadable modules, including xfrm_user/esp4/esp6 and ipcomp4/ipcomp6. On systems that allow unprivileged users to create sockets directly or through CAP_NET_ADMIN, or allow the creation of unprivileged user namespaces (user+net), an actor may gain access to kernel memory and thus esc… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
Issues in tough library and tuftool CLI utility | Bulletin ID: 2026-019-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/24 13:30 AM PDT Description: Multiple security issues have been identified in the tough library and tuftool CLI utility. tough is a Rust library used for generating, signing, and managing TUF (The Update Framework) repositories, and tuftool is the command-line interface for repository management Operations. The following issues have been identified: - CVE-2026-6966 - CVE-2026-6967 - CVE-2026-6968 Impacted versions: - tough: versions 0.1.0 through 0.21.x (inclusive) - tuftool: versions 0… | AWS Security BulletinsPrimary | |
|
Watch
ES
|
CVE-2026-12530 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() | Bulletin ID: 2026-044-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/17/2026 14:15 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source SDK that enables developers to build, deploy, and manage agents on AWS Bedrock AgentCore. We identified CVE-2026-12530, an issue in the install_packages() method of the Code Interpreter client. The method applied an incomplete blocklist to sanitize package name arguments before constructing a 'pip install' shell command executed within the Code Interpreter sandbox. This allowed crafte… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-1386 - Arbitrary Host File Overwrite via Symlink in Firecracker Jailer | Bulletin ID: 2026-003-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/01/23 12:30 PM PST Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. Firecracker runs in user space and uses the Linux Kernel-based Virtual Machine (KVM) to create microVMs. Each Firecracker microVM is further isolated with common Linux user-space security barriers by a companion program called "jailer". The jailer provides a second line of defense in case a user e… | AWS Security BulletinsPrimary | |
|
Watch
ES
|
Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer Underflow | Bulletin ID: 2026-021-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:00 PM PDT Description: FreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. - CVE-2026-7422: Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own registered endpoints. - CVE-2026-7423: Integer underflow in the ICMP and ICMPv6 echo reply handlers allo… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-5429 - Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme | Bulletin ID: 2026-012-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/02 11:30 AM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. We identified CVE-2026-5429, where unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a maliciously crafted color theme name when a local user opens the workspace. This issue requires the user… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-14904 - Improper Link Resolution in Auth.GetUserPrivateKey in AWS Research and Engineering Studio | Bulletin ID: 2026-053-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/07/2026 09:45 AM PDT Description: AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. We identified an improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic li… | AWS Security BulletinsPrimary | |
|
Watch
ES
|
CVE-2026-15643 - AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL | Bulletin ID: 2026-054-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:00 PM PDT Description: AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. We identified CVE-2026-15643, a server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted… | AWS Security BulletinsPrimary | |
|
Watch
ES
|
CVE-2026-9133 - Arbitrary file read in rabbitmq-aws plugin | Bulletin ID: 2026-034-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/20/2026 12:45 PM PDT Description: rabbitmq-aws is a RabbitMQ plugin that resolves AWS ARNs in broker configuration at startup, fetching secrets (e.g., TLS certificates, private keys, passwords) from AWS services (Secrets Manager, S3, ACM Private CA) and passing them in-memory to RabbitMQ. We identified CVE-2026-9133, an active debug code issue in the plugin's ARN resolver. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-10584 - HTTPS Fallback to HTTP in Graph Explorer | Bulletin ID: 2026-038-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/02/2026 12:15 PM PDT Description: Graph Explorer is an open source application that provides visualization and exploration of data in graph databases such as Amazon Neptune. We identified CVE-2026-10584 where, under certain circumstances, the server silently falls back to HTTP when HTTPS is enabled but certificates are unavailable, resulting in cleartext transmission of sensitive information. Impacted versions: >= 1.1.0 AND < 3.0.1 Please refer to the article below for the most up-to-date an… | AWS Security BulletinsPrimary | |
|
Watch
ES
|
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection | Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655, an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth acce… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-8838 - Remote Code Execution in amazon-redshift-python-driver | Bulletin ID: 2026-033-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/18/2026 13:45 PM PDT Description: amazon-redshift-python-driver is the official Python connector for Amazon Redshift. We identified a code injection issue in versions 2.1.13 and earlier that could allow a rogue server or man-in-the-middle to execute arbitrary code on the client. Impacted versions: <=2.1.13 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server | Bulletin ID: 2026-076-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 13:00 PM PDT Description: Amazon DocumentDB MCP Server is an open-source Model Context Protocol (MCP) server that enables AI assistants to interact with Amazon DocumentDB databases. We identified CVE-2026-18954, an incorrect authorization issue where write-capable aggregation pipeline stages ($out, $merge) bypass the read-only mode enforcement logic, potentially allowing an authenticated MCP client to perform write operations on the connected database. Impacted versions: < 1.0.12 Ple… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel | Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 18:45 PM PDT This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of CVE-2026-46300, a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag, copy.fail class of issues (CVE-2026-43284). The proof of concept uses a vector via the loadable module espintcp. Amazon Linux does not provide this module, and is not a… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route | Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and management UI for OpenSearch, and ships as part of Amazon OpenSearch Service. We identified CVE-2026-75897, an improper input validation in the capabilities route handler in OpenSearch Dashboards. The handler does not bound the size of the request payload, which might allow remote attackers to cause a denial of service via a crafted HTTP request. Affected Products and Versions: OpenSearch "Plugin Typ… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-6437 - Mount Option Injection in Amazon EFS CSI Driver | Bulletin ID: 2026-016-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/17 11:15 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-6437, where an actor with PersistentVolume creation privileges can inject arbitrary mount options via two unsanitized fields: the Access Point ID in volumeHandle and the mounttargetip volumeAttribute. In both cases, appending comma-separated values causes the mount utility to parse them as separate mount… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF | Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT Description: AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763, which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF. CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required. CVE-2026-13763 affects AWS WAF deployment with AWS Application L… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-5747 - Out-of-bounds Write in Firecracker virtio-pci Transport | Bulletin ID: 2026-015-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/07 15:30 PM PDT Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. We identified CVE-2026-5747, an out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 that might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the hos… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
Issues with Amazon Athena ODBC Driver | Bulletin ID: 2026-013-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/03 13:00 PM PDT Description: The Amazon Athena ODBC driver implements standard ODBC application program interfaces (APIs). The ODBC driver provides access to Amazon Athena from any C/C++ application. The Amazon Athena ODBC driver provides 64-bit ODBC drivers for Windows, Linux and MAC operating systems. We identified the following: - CVE-2026-5485: OS command injection in browser-based authentication component (Linux only, fixed in 2.0.5.1) - CVE-2026-35558: Improper neutralization of s… | AWS Security BulletinsPrimary | |
|
Watch
Critical vulns
|
CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service | Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion data format specification. We identified CVE-2026-75935, memory-amplification denial of service via declared-length preallocation, and CVE-2026-75936, memory-amplification denial of service via highly compressed data expansion. Affected versions: < 1.12.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. | AWS Security BulletinsPrimary | |
|
Watch
ES
|
CVE-2026-7191- Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS | Bulletin ID: 2026-020-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/27 13:15 PM PDT Description: QnABot on AWS is an open-source solution that provides a multi-channel, multi-language conversational interface powered by Amazon Lex, Amazon OpenSearch Service, and optionally Amazon Bedrock. We identified CVE-2026-7191, where the improper use of the static-eval npm package may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context. By injecting a crafted conditional chaining expression via the Content… | AWS Security BulletinsPrimary | |
|
Watch
Market activity
|
Someone targeted security researchers using a fake crypto conference as a lure | A hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware. | TechCrunch SecurityEditorial | |
|
Watch
IAM
|
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia | Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additional two distinct suspected Russian clusters, UNC7005 and UNC5976, which conduct phishing, abuse OAut… | Google Threat IntelligenceFirst party research | |
|
Watch
AI Sec
|
Grok exfiltrates user data when malicious instructions are encrypted | Cryptographic Context Injection is only the latest way to break an LLM safety guardrail. | Ars Technica Technology LabEditorial | |
|
Watch
Critical vulns
|
Researchers say OpenAI revoked their access to limited cyber program | The idea behind OpenAI's Trusted Access for Cyber program is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster. | TechCrunch SecurityEditorial | |
|
Watch
ES
|
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 | Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microsoft Security Blog . | Microsoft SecurityFirst party research | |
|
Watch
Critical vulns
|
Staying Ahead of Adversarial AI Through Agentic Source Code Review | Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy. Combining AI models with a deeply structured, human expert-driven orchestration layer to tip the scales… | Google Threat IntelligenceFirst party research | |
|
Watch
Critical vulns
|
Vulnerability giving attackers full control of Macs is under active exploitation | Screen-sharing bug lets remote hackers log in without a password. | Ars Technica Technology LabEditorial | |
|
Watch
Cloud/SaaS
|
PBS station fears losing 50TB of data after being ghosted by cloud storage provider | "We don't have access to the data on the hardware/servers," Iron Mountain told Ars. | Ars Technica Technology LabEditorial | |
|
Watch
TI
|
The Model Is the Malware | What Four Agentic Intrusions Tell Defenders | OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions. | SentinelLabsFirst party research | |
|
Watch
IAM
|
Chrome adopts what may be the best protection yet against account takeovers | Device-bound session credentials thwart an increasingly common form of account takeover. | Ars Technica Technology LabEditorial | |
|
Watch
IAM
|
New Pass-ta-key attack reveals all the things we didn't know about passkeys | Why passkey apps treat Windows differently than other operating systems. | Ars Technica Technology LabEditorial |
No items match these filters.