A Wiki Add-On Was Fixed Quietly. Attacks Began a Day After the Flaw Was Made Public.
CVE-2026-100382 in MediaWiki's External Data extension lets anyone run commands on a wiki's server. Bots planted web she...
ASEAN edition · Fri, 2 Oct 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
CVE-2026-100382 in MediaWiki's External Data extension lets anyone run commands on a wiki's server. Bots planted web she...
CVE-2026-76504 lets an attacker with no password use Catalyst SD-WAN Manager's API as the administrator. It was exploite...
Keio confirmed the attack on 26 September and cut off parts of its network. Business systems, including at a group hotel...
The CoreGraphics bug was used against targeted people on versions before iOS 27. Nearly 80% of iPhones were still on iOS...
Acting on a federal warning, the file-sharing company ordered a precautionary shutdown on 25 September. No breach has be...
Fixes for eight flaws shipped on 27 September. US federal agencies have until 30 September and are told to look for intr...
Microsoft reclassified CVE-2026-65660 as remote code execution in August and confirmed attacks on 25 September. US feder...
A critical bug in WordPress's core software affects every release from 4.7 to 7.1.1. Code execution needs a particular t...
Security appliances from Arista, F5 and Check Point are being attacked, and United States agencies must patch them by to...
SparroWocky replaced SparrowDoor from August 2025. ESET puts about nine in ten of the group's recent victims in one regi...
A stolen Cloudflare key let attackers rewrite three JavaScript files at the edge and strip the policy headers that would...
Three Linux kernel flaws joined the exploited catalogue on 18 September. No attacker, no victim and no technique has bee...
The advisory names no victim and no campaign, and the vector says adjacent network rather than the open internet.
The fix shipped three months ago and a public exploit followed in August. Fortinet says daily attempts against unpatched...
Local privilege escalation rarely alarms anyone. On shared hosting, where every customer already has a low-privileged ac...
An authentication bypass on the appliance that decides who gets onto the network, scored 10.0, already being exploited w...
A token signed with an algorithm the gateway does not support is accepted anyway. WSO2 scored it 10.0 and shipped the fi...
A mail gateway reads every message a company receives. Cisco's can be taken over by one of them, and the flaw was alread...
CVE-2026-68488 needs only a customer's own panel login and FTP access. On shared hosting, that turns one account into ev...
CVE-2026-0310 is reachable through a dataplane interface, not only the management plane, and Palo Alto lists no mitigati...
Check Point found ChatGPT's isolated sandboxes could pass data through an internal package service — the same one OpenAI...
Microsoft shipped 974 fixes in September, a monthly record. The year is the number that matters: 2,760 so far against a...
Two pre-authentication flaws in Check Point VPN were patched on 9 September. Three days later the Dutch NCSC said attemp...
Microsoft describes sign-ins followed by attackers registering their own authentication method. It survives every passwo...