Security Alerts & Patches

High-impact vulnerabilities, emergency patches, supply-chain incidents, and mitigations.

  • 9 Tracked terms
  • Last 30 days Feed window

What this topic collects on

An article joins this feed when it matches these terms. Each one is also a search of its own.

Latest in Security Alerts & Patches

Cyber Security News
cybersecuritynews.com > plesk-backup-manager-flaw > amp

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

4+ hour, 23+ min ago   (444+ words) A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations. The…...

CryptoTicker.io
cryptoticker.io > en > symbiosis-btc-bridge-exploit-check

Symbiosis Hack: Check Your Bridged Bitcoin Now

6+ hour, 8+ min ago   (1834+ words) An attacker minted billions of unbacked syBTC on the cross-chain bridge Symbiosis and pulled out roughly $336,000. We checked for ourselves on September 12 which routes are still running: the way into the bridge is suspended, the way out is open. Symbiosis…...

DEV Community
dev.to > anoymask > check-point-vpn-cve-2026-85102-and-cve-2026-85103-early-warning-for-pre-authentication-rce-2i4n

Check Point VPN CVE-2026-85102 and CVE-2026-85103: Early Warning for Pre-Authentication RCE

6+ hour, 44+ min ago   (1541+ words) 1. Basic Information Original Title: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Source: BleepingComputer, Dutch NCSC, Check Point Published Date: 2026-09-12 Severity: High Basis for Severity: Both CVSS 9.8 vulnerabilities allow unauthenticated remote code execution. Although the reference materials do…...

DEV Community
dev.to > goodpa > your-agent-just-attacked-a-package-manager-the-supply-chain-guardrail-checklist-for-cross-border-4chn

Your Agent Just Attacked a Package Manager: The Supply-Chain Guardrail Checklist for Cross-Border Sellers

8+ hour, 19+ min ago   (245+ words) Last week, an AI agent carried out an undisclosed attack on RubyGems, the package registry that nearly every Ruby project on the planet depends on. 247 points, 140 comments, and a quiet panic in the comments: the agent didn't break a rule…...

Medium
medium.com > @sanket.sahoo_82259 > day-8-llm03-supply-chain-guardrail-gazette-f812d56d98c9

Day 8 — LLM03: Supply Chain | Guardrail Gazette

7+ hour, 8+ min ago   (155+ words) You didn’t build the model, the dataset, or the plugin — but you inherited every risk that comes with them.Continue reading on Medium » Day 8 — LLM03: Supply Chain | Guardrail Gazette You didn’t build the model, the dataset, or the plugin — but you…...

Medium
medium.com > @bryant_74069 > the-foundation-the-open-source-stack-behind-a-home-soc-798f808e1e7c

The Foundation: The Open-Source Stack Behind a Home SOC

14+ hour, 55+ min ago   (1081+ words) Part 1 of a series on building an enterprise-grade Security Operations Center at home. Start with Part 0 if you haven’t. In Part 0 I made a claim: you can build a real, operating Security Operations Center on a home network, and the…...

4sysops
4sysops.com > archives > windows-11-patch-tuesday-breaks-usb-audio-with-code-10-and-dead-multichannel-sound

Windows 11 Patch Tuesday breaks USB audio with Code 10 and dead multichannel sound – 4sysops

19+ hour, 31+ min ago   (26+ words) Microsoft has confirmed a new Windows 11 Patch Tuesday problem that disables USB Audio Class 1.0 devices with Device Manager’s Code 10 error. The failure affect...

Forkast
forkast.news > the-papercut-pipeline-how-two-vulnerabilities-became-an-automated-rce-factory

The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory

23+ hour, 1+ min ago   (148+ words) Two PaperCut vulnerabilities are now chained into a fully automated attack pipeline with in-memory persistence—and 47% of installations can't patch. On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This…...

Windows Report
windowsreport.com > microsoft-investigates-rds-failures-after-september-windows-server-updates

Microsoft Investigates RDS Failures After September Windows Server Updates

2+ day, 1+ hour ago   (265+ words) Published on September 11, 2026 September 2026 Windows Server updates are causing Remote Desktop Services failures, with administrators reporting frozen RDS hosts, failed connections, and servers that sometimes require a hard reset. The issue does not always appear immediately. Some RDS servers reportedly…...

Forkast
forkast.news > stylesmuggler-turns-adobe-commerces-own-template-engine-into-an-unauthenticated-rce-chain

StyleSmuggler Turns Adobe Commerce’s Own Template Engine Into an Unauthenticated RCE Chain

2+ day, 6+ hour ago   (117+ words) CVE-2026-75650 lets attackers inject PHP through Magento's email template system, then triggers execution automatically. Multiple threat groups are already inside. The authentication gap has reached the payment layer. Simultaneously, a separate attacker group has been observed dropping a 485-byte PHP…...