Feed items are signals, not findings — a headline here is a lead to check, not a verified fact about your estate. Public official and reputable sources only; nothing behind a login or paywall.
| Published | Source | Item |
|---|---|---|
| 2026-09-30 02:00 | SANS Internet Storm Center | ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116, (Wed, Sep 30th) |
| 2026-09-29 13:29 | SANS Internet Storm Center |
Scans for Wordfence Protected Websites, (Tue, Sep 29th)
Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-w…
|
| 2026-09-29 02:00 | SANS Internet Storm Center | ISC Stormcast For Tuesday, September 29th, 2026 https://isc.sans.edu/podcastdetail/10114, (Tue, Sep 29th) |
| 2026-09-28 22:04 | SANS Internet Storm Center |
Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th)
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploite…
|
| 2026-09-28 19:36 | CERT/CC Vulnerability Notes |
VU#762428: Authlib library contains a signature‑verification bypass vulnerability
Overview Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts …
|
| 2026-09-28 12:00 | NCSC UK News |
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
|
| 2026-09-28 02:00 | SANS Internet Storm Center | ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112, (Mon, Sep 28th) |
| 2026-09-27 19:40 | CERT-EU Security Advisories |
2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Exe…
|
| 2026-09-27 15:04 | SANS Internet Storm Center |
Wireshark 4.6.9 Released, (Sun, Sep 27th)
Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.
|
| 2026-09-25 16:25 | CERT/CC Vulnerability Notes |
VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vul…
|
| 2026-09-25 06:45 | SANS Internet Storm Center |
A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
Introduction
|
| 2026-09-25 03:45 | SANS Internet Storm Center | ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th) |
| 2026-09-24 19:27 | CERT/CC Vulnerability Notes |
VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
Overview ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. Description ViewSonic ViewBoards are…
|
| 2026-09-24 15:44 | CERT/CC Vulnerability Notes |
VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability
Overview Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) devi…
|
| 2026-09-24 06:25 | SANS Internet Storm Center |
One URL, Three Different Tricks, (Thu, Sep 24th)
Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:
…
|
| 2026-09-24 03:50 | SANS Internet Storm Center | ISC Stormcast For Thursday, September 24th, 2026 https://isc.sans.edu/podcastdetail/10108, (Thu, Sep 24th) |
| 2026-09-23 18:22 | CERT/CC Vulnerability Notes |
VU#273940: Enterprise Access Management EAM does not rotate RSA keys
Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides n…
|
| 2026-09-23 17:41 | CERT/CC Vulnerability Notes |
VU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite anothe…
|
Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-w…
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploite…
Overview Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts …
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Exe…
Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.
Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vul…
Introduction
Overview ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. Description ViewSonic ViewBoards are…
Overview Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) devi…
Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:
…
Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides n…
Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite anothe…
Sources
| Name | Last poll | Status | Trust |
|---|---|---|---|
| CERT-EU Security Advisories | 2026-09-30 13:35 | ok | 0.90 |
| CERT/CC Vulnerability Notes | 2026-09-30 13:35 | ok | 0.90 |
| CISA Alerts muted | 2026-08-19 01:32 | error | 0.95 |
| CISA Cybersecurity Advisories muted | 2026-08-19 01:32 | error | 0.95 |
| JPCERT/CC Alerts | 2026-09-30 13:35 | ok | 0.85 |
| NCSC UK News | 2026-09-30 13:35 | ok | 0.90 |
| SANS Internet Storm Center | 2026-09-30 13:35 | ok | 0.80 |