Information and Guidance
- Joint guidance on isolating vital systems
- Protect your devices from SMS blasters (ITSAP.00.104)
- Joint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmail
- What is voice phishing (vishing)? - ITSAP.00.102
- Social engineering – ITSAP.00.166
- Securely deploying AI at the network edge - ITSP.80.101
- Guidance on securely configuring authorization and authentication frameworks - ITSP.40.063
- Joint guidance on improving router hygiene to protect against Russian state-sponsored targeting
- SharpViewStateKing: The stealthy implant framework
- Obsolete products - ITSAP.00.095
The Hacker News RSS Feed
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
- OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
- 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
News
- Progress Software security advisory (AV26-755)
- Vercel security advisory (AV26-754)
- Apple security advisory (AV26-753)
- JetBrains security advisory (AV26-752)
- Arista Networks security advisory (AV26-751)
- Apache security advisory (AV26-749)
- Erlang security advisory (AV26-750)
- Fortinet security advisory (AV26-109) – Update 1
- Redis security advisory (AV26-748)
- Microsoft security advisory (AV26-747)
