search

Sections

Cyber Security

2432 articles

Rockwell Automation 1715-AENTR EtherNet/IP Adapter
cybersecurity

Rockwell Automation 1715-AENTR EtherNet/IP Adapter

A critical vulnerability has been identified in the Rockwell Automation 1715-AENTR EtherNet/IP Adapter, affecting versions 3.003 and below. This flaw exposes a debug port that allows unauthenticated remote access, enabling attackers to read or delete files, stop tasks, and modify device states, potentially compromising confidentiality and availability. Users are urged to upgrade to version 3.011 or later or adopt security best practices to mitigate risks. The Cybersecurity and Infrastructure Security Agency (CISA) recommends defensive measures to reduce exploitation risks and emphasizes the importance of network isolation and secure remote access methods.

All CISA Advisories ·
[Video] Where protection starts: Cisco Talos Intelligence Integrations
cybersecurity

[Video] Where protection starts: Cisco Talos Intelligence Integrations

Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.

Cisco Talos Blog ·
The serpent’s tongue: Luring the Python out of its den
cybersecurity

The serpent’s tongue: Luring the Python out of its den

This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.

Cisco Talos Blog ·
AI Security Report 2026
cybersecurity

AI Security Report 2026

The Annual AI Security Report 2026 from Check Point Research reveals a significant shift in the role of AI within cyber security. Previously viewed as a tool that enhanced existing attack methods, AI has now evolved into an active operator in cyber attacks. This change marks a transition where AI not only assists attackers in preparation but takes on a more central role in executing malicious activities. This development emphasizes the growing sophistication and impact of AI in cyber threats.

Check Point Research ·
Introducing Third-Party Applications for Organizations
cybersecurity

Introducing Third-Party Applications for Organizations

Securely extend your multi-tenant APIs and MCP servers to AI agents, partner marketplaces and developer ecosystems using native, organization-scoped access control with Auth0 Third-Party Applications for Organizations

Auth0 Blog ·
Request for Comments: CARE and Maven Central
cybersecurity

Request for Comments: CARE and Maven Central

For most of Maven Central’s history, publishing has followed a simple model: maintainers publish releases, users consume them, and when something goes wrong, the fix comes through the same channel.

2024 Sonatype Blog ·
New compliance guidance available: HITRUST i1 on AWS
cybersecurity

New compliance guidance available: HITRUST i1 on AWS

Amazon Web Services (AWS) has released new compliance guidance for healthcare organizations pursuing HITRUST i1 certification. The document, titled “HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform,” provides a framework that encompasses 182 curated controls necessary for compliance. The guidance aims to assist these organizations in effectively utilizing AWS as their cloud infrastructure while meeting HITRUST standards.

AWS Security Blog ·
13th July – Threat Intelligence Report
cybersecurity

13th July – Threat Intelligence Report

In the Threat Intelligence Bulletin for the week of July 13th, significant cyber research findings are shared, including a major data breach by U.S. auto insurer AssuranceAmerica. Approximately 7 million individuals were affected when attackers accessed company systems using compromised employee credentials, leading to the theft of personal information, such as names, contact details, and driver’s licenses. This incident highlights ongoing vulnerabilities in the sector.

Check Point Research ·
CISA Adds One Known Exploited Vulnerability to Catalog
cybersecurity

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2008-4128, related to Cisco IOS, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation concerns. This vulnerability is a common target for cyber attackers and poses significant risks to federal entities. Under Binding Operational Directive 26-04, federal agencies are required to prioritize the rapid remediation of high-risk vulnerabilities from the KEV Catalog while allowing for deferral of lower-risk ones. CISA urges all organizations to adopt similar risk-based vulnerability management practices. Organizations can submit information on exploited vulnerabilities for potential KEV catalog inclusion through CISA’s nomination process.

All CISA Advisories ·
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
cybersecurity

Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

The Russian Federal Security Service (FSB) continues to exploit poorly configured networking devices globally, impacting various critical infrastructure sectors, including communications, energy, and healthcare. A recent Cybersecurity Advisory (CSA) from multiple agencies, including the NSA, CISA, and FBI, details tactics, techniques, and recommended mitigations to combat threats posed by FSB cyber actors. Key actions include disabling insecure protocols like SNMPv1/v2, using SNMPv3, and implementing strong password policies. Network defenders are urged to enhance configurations and monitor for unusual activities to better protect their systems.

All CISA Advisories ·