Also: How Non-Human Identities Redefine Security; the Delinea-StrongDM Deal In this week's panel, four editors discussed how deepfakes are reshaping digital Know Your Customer practices, what the rise of non-human identities means for CISOs and what Delinea's acquisition of StrongDM tells us about where the privileged access market is heading.
FBI Accessed Encrypted Windows Devices Via BitLocker Keys, Microsoft Says Microsoft confirmed it handed over BitLocker recovery keys to the FBI in 2025 under court order, raising concerns over cloud-stored encryption keys and whether default designs that prioritize recovery convenience and efficiency weaken user control and security.
Partnership With Israeli Startup Brings Real-World Threat Labs to Security Training ISMG has teamed with CyCube to strengthen CyberEd.io's hands-on cyber training platform. The strategic investment aims to deliver personalized, adaptive labs and assessments that help security teams respond to evolving threats fueled by generative and agentic AI.
'WhisperPair' Flaw Likely to Endure for Years A hacker could secretly record phone conversations, track users' locations and blast music through headphones due to a flaw in implementations of a Google-developed low-energy technology for discovering nearby Bluetooth devices.
A vulnerability labeled as problematic has been found in chattermate chat up to 1.0.8. Affected by this issue is some unknown functionality of the component LocalStorage Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-24399. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in Salesforce Marketing Cloud Engagement. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in use of hard-coded cryptographic key
.
This vulnerability is identified as CVE-2026-22586. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Salesforce Marketing Cloud Engagement. Affected is an unknown function. Such manipulation leads to risky cryptographic algorithm.
This vulnerability is referenced as CVE-2026-22585. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Salesforce Marketing Cloud Engagement. It has been rated as critical. This impacts an unknown function of the component CloudPagesUrl. This manipulation causes argument injection.
The identification of this vulnerability is CVE-2026-22583. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Salesforce Marketing Cloud Engagement. It has been declared as critical. This affects an unknown function of the component MicrositeUrl. The manipulation results in argument injection.
This vulnerability was named CVE-2026-22582. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
Critical telnetd flaw CVE-2026-24061 (CVSS 9.8) affects all GNU InetUtils versions 1.9.3–2.7 and went unnoticed for nearly 11 years. A critical vulnerability, tracked as CVE-2026-24061 (CVSS score of 9.8), in the GNU InetUtils telnet daemon (telnetd) impacts all versions from 1.9.3 to 2.7. The vulnerability can be exploited to gain root access on affected systems. […]
A vulnerability was found in DioxusLabs components. It has been classified as critical. The impacted element is the function use_animated_open. The manipulation leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is uniquely identified as CVE-2026-24474. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in franklioxygen MyTube up to 1.7.78 and classified as critical. The affected element is an unknown function of the component Database Export Endpoint. Executing a manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2026-24139. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.