Skip to content
category — security

ls ./category/security --page 4

Security

Breaches, vulnerabilities, malware and the patches that matter.

page 4 of 9 — 211 articles

N-able's two documents disagreed about exploitation. CISA has settled it

2026-09-07

CVE-2026-86218 is a CVSS 10.0 pre-authentication RCE in N-central, patched in the fourth hotfix in five weeks. For two days the vendor's release notes and its incident notice said opposite things about whether it was being exploited. CISA added it to the KEV catalogue on 8 September with a three-day federal deadline.

The deletion was contractual, confirmed in writing, and did not happen

2026-09-07

Trezor says it repeatedly asked its logistics provider to delete customer data and repeatedly received written confirmation that it had been. On 5 September it disclosed that 67,000 US customers' names, phone numbers and home addresses from 2019 to 2021 were in a breach at that provider — matched, in every case, to the purchase of a hardware wallet.

A Chrome V8 zero-day paid $1,000. The lowest published tier is $7,000

2026-09-07

CVE-2026-85046 is a V8 type confusion, rated 8.8, exploited in the wild, and the sixth actively exploited Chrome zero-day of 2026. It was reported on 4 August and awarded $1,000 — an amount that does not appear anywhere on Chrome's published memory-corruption reward schedule. Several explanations fit. Google has offered none.

The print server held the LDAP bind credentials. That is what they came for

2026-09-07

Arctic Wolf has published what attackers do after exploiting the two PaperCut zero-days against schools and universities: create an account, dump the SAM hives, and grep the PaperCut config for the strings password, secret, ldap, bind and token. The print server is domain-joined and nobody's threat model has it on the list.

REPLICATION was never a read-only privilege. For twelve years it was a shell

2026-09-07

CVE-2026-6471 lets any account holding PostgreSQL's REPLICATION attribute load an arbitrary library as a logical decoding plugin and run code as the postgres user. It has been there since logical decoding shipped in 9.4 in 2014, and REPLICATION is the privilege every CDC pipeline in your estate already has.

A court seals a record by order. The order did not travel with the backup copy

2026-09-06

West Publishing says an intruder sat in Thomson Reuters' cloud from 1 March to 29 June, and that confidential, redacted or sealed court information may have been affected. Thomson Reuters' reassurance is that C-Track had no operational disruption and is safe to keep using — which answers a question nobody asked.

The backdoor was compiled into HAProxy. That is not an HAProxy vulnerability

2026-09-06

Rapid7 found a Linux implant built into the HAProxy binaries of two South Korean organisations, intercepting traffic and erasing its own requests from the proxy's own logs. Every headline calls it an HAProxy backdoor. Installing it requires already owning the host, which makes patching HAProxy the one response that changes nothing.

Three tools are called God's Eye. Only one of them publishes what it cannot see

2026-09-05

An MIT-licensed OSINT globe with 17.7k stars refuses to add person tracking and warns its own data may be wrong. A facial recognition product with the same name claims to unmask faces, detect sex changes and score attractiveness as trafficking risk, and publishes no accuracy figure at all. The name is identical. The honesty is not.