Aggregator
CVE-2025-12943 | NETGEAR RAX30/RAXE300 Firmware Update certificate validation
CVE-2025-12940 | NETGEAR WAX610/WAX610Y prior 10.8.11.4 Syslog Server log file
Amazon rolls out AI bug bounty program
Select researchers and academic teams will get access to Amazon’s NOVA models next year as the tech giant continues to integrate the AI tools into its own tech stack.
The post Amazon rolls out AI bug bounty program appeared first on CyberScoop.
CVE-2022-43546 | Siemens POWER METER SICAM Q100 2.41 Web Interface EndTime input validation (ssa-570294 / WID-SEC-2023-1431)
CVE-2022-43545 | Siemens POWER METER SICAM Q100 2.41 Web Interface RecordType input validation (ssa-570294 / WID-SEC-2023-1431)
CVE-2022-43439 | Siemens POWER METER SICAM Q100 2.41 Web Interface Language input validation (ssa-570294 / WID-SEC-2023-1431)
CVE-2022-43398 | Siemens POWER METER SICAM Q100 2.41 Session Cookie session fixiation (ssa-570294 / WID-SEC-2023-1431)
Hackers abuse Triofox antivirus feature to deploy remote access tools
OnDemand | Analyst Insights: Building Cyber Resilience Through Proactive Recovery Strategies
Nacha Revises Fraud Monitoring Rules for FIs
Nacha's 2026 rule amendments pivot from "commercially reasonable" to "reasonably intended" fraud detection standards. Nacha's Devon Marsh explains what this shift means for RDFIs and ODFIs and how banks and financial institutions can define and demonstrate reasonable practices.
How Prompt Injection Is Breaking Digital Forensics Norms
Logs are where cybersecurity teams spot how and when the break in occurred. For a new type of attack, logs will be worthless - a condition that will especially challenge digital responders as artificial intelligence systems become more ubiquitous.
US Congress Moves to Revive CISA 2015 After Shutdown
A statute underpinning corporate cybersecurity information sharing may come back into effect along with funding to reopen the U.S. federal government after six weeks of being shutdown. The Cybersecurity Information Sharing Act of 2015 expired the same day Washington shut down on Oct. 1.
Cl0p Ransomware Lists NHS UK as Victim, Days After Washington Post Breach
Alleged Data Breach of International Kiteboarding Organization (IKO)
Beware of Security Alert-Themed Malicious Emails that Steal Your Email Logins
A new wave of security alert-themed phishing emails has recently surfaced, causing concern within both enterprise and personal email environments. These malicious emails cleverly impersonate official security notifications, often appearing to come from the victim’s own domain. Their main objective is to instill panic by warning users about “blocked messages” and prompt recipients to take […]
The post Beware of Security Alert-Themed Malicious Emails that Steal Your Email Logins appeared first on Cyber Security News.
Hitachi subsidiary GlobalLogic impacted by Clop’s attack spree on Oracle customers
The digital engineering services firm said human resources data on nearly 10,500 current and former employees was exposed.
The post Hitachi subsidiary GlobalLogic impacted by Clop’s attack spree on Oracle customers appeared first on CyberScoop.