Information and Guidance
- Joint guidance on minimum elements for a software bill of materials
- Joint guidance on isolating vital systems
- Protect your devices from SMS blasters (ITSAP.00.104)
- Joint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmail
- What is voice phishing (vishing)? - ITSAP.00.102
- Social engineering – ITSAP.00.166
- Securely deploying AI at the network edge - ITSP.80.101
- Guidance on securely configuring authorization and authentication frameworks - ITSP.40.063
- Joint guidance on improving router hygiene to protect against Russian state-sponsored targeting
- SharpViewStateKing: The stealthy implant framework
The Hacker News RSS Feed
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
- Mythos Asks the Right Question. It Doesn't Answer It.
- Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
- 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
- Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
News
- Adobe security advisory (AV26-756)
- Progress security advisory (AV26-755)
- Vercel security advisory (AV26-754)
- Apple security advisory (AV26-753)
- JetBrains security advisory (AV26-752)
- Arista Networks security advisory (AV26-751)
- Apache security advisory (AV26-749)
- Erlang security advisory (AV26-750)
- Fortinet security advisory (AV26-109) – Update 1
- Redis security advisory (AV26-748)
