Latest news
-
Vulnerabilities via Chrome Releases
Beta Channel Update for ChromeOS / ChromeOS Flex
The Beta channel is being updated to OS version 16820.11.0 (Browser version 155.0.8059.18) for most ChromeOS devices. If you find new issues, please let us know one of…
-
Vulnerabilities via Palo Alto Networks Unit 42
3 Consulting Myths Debunked by Unit 42 Experts
Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses.
-
Vulnerabilities via oss-security
CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
Posted by Haitam Lazaar on Sep 25 Hello oss-security, An untrusted search path vulnerability leading to Local Privilege Escalation (LPE) was identified in GNU…
-
Vulnerabilities via Debian Security
DSA-6517-1 nodejs - security update
https://security-tracker.debian.org/tracker/DSA-6517-1
-
Vulnerabilities via Debian Security
DSA-6519-1 swift - security update
https://security-tracker.debian.org/tracker/DSA-6519-1
-
Vulnerabilities via Debian Security
DSA-6518-1 incus - security update
https://security-tracker.debian.org/tracker/DSA-6518-1
-
Vulnerabilities via oss-security
CVE-2026-91206: Apache Roller: Reflected XSS in the optional LDAP comment authenticator
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-91204: Apache Roller: Stored javascript: URI in HTML comments
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-86507: Apache Roller: Stored XSS in comment moderation via comment author URL
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Breaches via Krebs on Security
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T…
-
Vulnerabilities via oss-security
CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via BleepingComputer
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving…
-
Vulnerabilities via oss-security
CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 6.5 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
Posted by David M. Johnson on Sep 25 Severity: Critical CVSS 3.1: 9.8 (critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 8.2 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Threat Intel via CyberScoop
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison, the Justice…
