Latest news

  1. Vulnerabilities via Chrome Releases

    Beta Channel Update for ChromeOS / ChromeOS Flex

    The Beta channel is being updated to OS version 16820.11.0 (Browser version 155.0.8059.18) for most ChromeOS devices. If you find new issues, please let us know one of…

  2. Vulnerabilities via Palo Alto Networks Unit 42

    3 Consulting Myths Debunked by Unit 42 Experts

    Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses.

  3. Vulnerabilities via oss-security

    CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX

    Posted by Haitam Lazaar on Sep 25 Hello oss-security, An untrusted search path vulnerability leading to Local Privilege Escalation (LPE) was identified in GNU…

  4. Vulnerabilities via Debian Security

    DSA-6517-1 nodejs - security update

    https://security-tracker.debian.org/tracker/DSA-6517-1

  5. Vulnerabilities via Debian Security

    DSA-6519-1 swift - security update

    https://security-tracker.debian.org/tracker/DSA-6519-1

  6. Vulnerabilities via Debian Security

    DSA-6518-1 incus - security update

    https://security-tracker.debian.org/tracker/DSA-6518-1

  7. Vulnerabilities via oss-security

    CVE-2026-91206: Apache Roller: Reflected XSS in the optional LDAP comment authenticator

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  8. Vulnerabilities via oss-security

    CVE-2026-91204: Apache Roller: Stored javascript: URI in HTML comments

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  9. Vulnerabilities via oss-security

    CVE-2026-86507: Apache Roller: Stored XSS in comment moderation via comment author URL

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  10. Breaches via Krebs on Security

    U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

    A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T…

  11. Vulnerabilities via oss-security

    CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  12. Vulnerabilities via oss-security

    CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  13. Vulnerabilities via BleepingComputer

    Kiteworks urges 6-hour server shutdown over potential zero-day attacks

    Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving…

  14. Vulnerabilities via oss-security

    CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…

  15. Vulnerabilities via oss-security

    CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 6.5 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…

  16. Vulnerabilities via oss-security

    CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint

    Posted by David M. Johnson on Sep 25 Severity: Critical CVSS 3.1: 9.8 (critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5…

  17. Vulnerabilities via oss-security

    CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 8.2 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Affected versions: - Apache Roller 6.1.5…

  18. Vulnerabilities via oss-security

    CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  19. Vulnerabilities via oss-security

    CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  20. Threat Intel via CyberScoop

    Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

    A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison, the Justice…