Software

HPE patches critical ArubaOS-CX remote code execution flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges. “Multiple vulnerabilities […]

HPE patches critical ArubaOS-CX remote code execution flaw Read More »

Coder’s registry infrastructure compromised to push malicious modules

Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications. The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz,

Coder’s registry infrastructure compromised to push malicious modules Read More »

French hospital fined €500,000 after breach exposes data of 727,000

France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as

French hospital fined €500,000 after breach exposes data of 727,000 Read More »

Norway considers ban on camera-enabled wearable ‘pervert glasses’

Norway is considering a ban on smart glasses and other camera-enabled wearable headsets as it seeks to regulate the controversial technology amid privacy concerns. The country’s digital minister Karianne Tung, as quoted by the AFP news agency, said that the government is looking to regulate the use of camera-enabled wearables, such as those made by

Norway considers ban on camera-enabled wearable ‘pervert glasses’ Read More »

Dropbox accounts breached through Lenovo email verification flaw

Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs. Although some affected users did not have Lenovo accounts, the cloud-storage provider said it uses Lenovo Identity Provider Services as part of its authentication infrastructure. This allows users to

Dropbox accounts breached through Lenovo email verification flaw Read More »

Microsoft Defender flags legitimate Google search links as malicious

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly flag legitimate Google search links as malicious. The company first acknowledged the incident (tracked under MO1465962) at 10:30 AM UTC and says affected users are seeing “Opening this website might not be safe” warnings when trying to open the blocked

Microsoft Defender flags legitimate Google search links as malicious Read More »

US charges Russian for infecting 80,000 freelancers with malware

A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. 40-year-old Searzhudin Tamirlanovich Aktulaev was extradited to the United States after being arrested in Cyprus at Larnaca Airport in May 2025. According to court documents filed in June

US charges Russian for infecting 80,000 freelancers with malware Read More »

Sality botnet infrastructure dismantled in joint global takedown

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. As part of this operation, the U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while law enforcement partners in Bulgaria, Hungary, and

Sality botnet infrastructure dismantled in joint global takedown Read More »

SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The first is a maximum-severity command injection flaw (CVE-2026-83548) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness. This actively exploited zero-day chain also targets a command injection vulnerability (CVE-2026-83549)

SonicWall warns of actively exploited SMA1000 zero-day flaws Read More »

Why Even the Best Edge Security Still Misses High-Risk Sessions

Security teams have more edge controls at their disposal than ever, and each plays an important role. Yet, despite the best request inspection, credential validation, device fingerprinting, and automation signals available, attackers still successfully hide inside traffic that looks remarkably similar to legitimate user activity. One reason for this is that each security control focuses

Why Even the Best Edge Security Still Misses High-Risk Sessions Read More »