search

Sections

Cyber Security

2432 articles

Claude Chrome extension flaw lets malicious extensions trigger AI actions
cybersecurity

Claude Chrome extension flaw lets malicious extensions trigger AI actions

A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.

BleepingComputer ·
Begun, the Patch Wars have
cybersecurity

Begun, the Patch Wars have

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.

Cisco Talos Blog ·
AI Agents Broke the Security Playbook. Here's What Replaces It.
cybersecurity

AI Agents Broke the Security Playbook. Here's What Replaces It.

Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments.

BleepingComputer ·
AutomationDirect Productivity Suite
cybersecurity

AutomationDirect Productivity Suite

AutomationDirect’s Productivity Suite versions up to 4.6.2.2 are vulnerable to several critical issues that could allow local attackers to cause memory corruption, system instability, or denial-of-service conditions. Key vulnerabilities include out-of-bounds reads/writes, and a divide-by-zero error. Users are advised to update to version 4.7.0.47 or later. If immediate updates aren’t possible, AutomationDirect recommends various compensating measures, such as network isolation, access restrictions, and stringent monitoring practices to mitigate risks. CISA encourages organizations to maintain robust cybersecurity practices and to report any anomalies.

All CISA Advisories ·
CISA Adds Three Known Exploited Vulnerabilities to Catalog
cybersecurity

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, reflecting active exploitation: two CVEs related to Fortinet FortiSandbox OS Command Injection and one from Microsoft SharePoint concerning Deserialization of Untrusted Data. These vulnerabilities are significant risks for federal agencies, driving the need for prompt remediation as outlined in Binding Operational Directive 26-04. While this directive specifically affects Federal Civilian Executive Branch agencies, CISA advises all organizations to adopt similar risk-based vulnerability management practices. CISA welcomes submissions for new vulnerabilities to the KEV Catalog through its nomination process.

All CISA Advisories ·
NASA Core Flight System (cFS) Health & Safety (HS) Application
cybersecurity

NASA Core Flight System (cFS) Health & Safety (HS) Application

A vulnerability in NASA’s Core Flight System (cFS) Health & Safety (HS) Application could lead to denial-of-service conditions. The issue stems from a null pointer dereference, causing a segmentation fault when handling a Housekeeping Telemetry request. This flaw affects the cFS Health & Safety application, with critical implications for transportation systems globally. The vendor, NASA, provides a CVSS score of 7.5 for this vulnerability, indicating its severity.

All CISA Advisories ·
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
cybersecurity

Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT

A denial-of-service vulnerability (CVE-2026-9653) has been identified in Rockwell Automation’s 1756-EN2, 1756-EN3, and 1756-ENBT communication modules due to improper validation of connection packets. The affected versions can allow attackers on the network to disrupt device connections, although these connections will resume immediately after. Users are advised to upgrade the affected devices to version 12.002, as the 1756-ENBT is discontinued and has no available fix. CISA recommends enhancing network security, including using firewalls and VPNs, to mitigate risks.

All CISA Advisories ·
Rockwell Automation Arena
cybersecurity

Rockwell Automation Arena

Rockwell Automation’s Arena software versions up to V17.00.00 are vulnerable to multiple memory corruption issues, identified as CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314. Attackers could exploit these vulnerabilities to execute arbitrary code by convincing users to open malicious files. Users are urged to update to V17.00.01 to mitigate these risks. CISA recommends enhancing network security and implementing cybersecurity best practices to protect against such threats.

All CISA Advisories ·